Analysis
Comp AI, the Miami-based AI-native compliance and security platform, closed a $34 million Series A led by Roo Capital and Grand Ventures, according to Yahoo Finance and TechCrunch. The company has grown ARR 15x year-over-year since its January 2025 founding by Lewis Carhart, Claudio Fuentes and Mariano Fuentes, and now serves more than 1,000 customers. Lead investor Roo Capital is itself based in Coconut Grove, adding another local round to the run of raises in our South Florida funding tracker.
From Compliance Automation To Continuous Security
Comp AI's platform originally focused on automating compliance workflows -- bringing risk management, vendor security and audit preparation into a single system using agentic AI to reduce manual work. The new capital funds an expansion into continuous cybersecurity: real-time monitoring, control validation and security testing across applications and infrastructure, extending the company from a periodic-audit tool into always-on oversight.
“- Vanta -- $4.15B valuation on a $150M Series D led by Wellington (July 2025): started in SOC 2 automation, now spans GRC, vendor risk and AI risk management.”
Why Agent Permissions Are The Actual Product
The company's stated focus -- tracking exactly what an AI agent accessed, what it attempted to do, and whether it stayed within the boundaries it was granted -- addresses a gap that has become urgent as enterprises deploy agentic AI faster than security teams can build native monitoring for it. This is the same category of problem Pulse has tracked elsewhere this week: OpenAI's own agents were found probing infrastructure outside their intended scope, and a cross-vendor code-execution flaw hit Claude Code, Codex, Gemini CLI and GitHub Copilot simultaneously. Comp AI's bet is that permissions-and-accountability tooling becomes as standard for agentic AI deployments as endpoint security became for traditional IT.
The Numbers In Context
$34 million is a modest check next to this week's multibillion-dollar AI-infrastructure raises, but the 15x ARR growth and 1,000-plus customer count in under two years is a genuinely strong efficiency signal for a compliance-category startup, a space VCs have historically treated as slow-moving relative to consumer or infrastructure AI.
The incumbents it has to displace are much further along.
- Vanta -- $4.15B valuation on a $150M Series D led by Wellington (July 2025): started in SOC 2 automation, now spans GRC, vendor risk and AI risk management. Sacra estimates $300M ARR across roughly 16,000 customers as of April 2026.
- Drata -- roughly $98M ARR entering 2025: bought trust-portal vendor SafeBase for $250M in February 2025 to widen the same surface, and leads enterprise compliance spend.
- Comp AI -- 1,000+ customers 20 months in: about 6% of Vanta's count, fast for this category and still an order of magnitude short of parity.
Where The Category Could Fragment
The risk is competitive crowding: agentic-AI security and compliance is attracting well-funded entrants from multiple angles -- some starting from compliance like Comp AI, others starting from pure security tooling -- and the category could fragment before any single platform becomes the default. Comp AI's 1,000-customer base is a real moat today, but retention and expansion revenue as the product shifts from periodic compliance checks to continuous monitoring will determine whether that base grows with the company or churns to a security-native competitor.