The Comp AI Series A, a $34 million round led by Roo Capital and Grand Ventures, is the latest bet that security and compliance work is ripe for automation, and that the agentic era has made that bet more urgent.
The Miami-based cybersecurity startup announced the raise on Thursday. OSS Capital also participated in the round, according to the company’s press release. Comp AI has now raised $37.5 million in total funding since its founding in January 2025.
The growth backing the round is hard to ignore. Comp AI says it has achieved 15x year-over-year ARR growth and now serves more than 1,000 customers, a trajectory that has unfolded in under eighteen months.
From a Shut-Down Startup to a SOC 2 Frustration
The company was founded by Lewis Carhart (CEO), Claudio Fuentes (COO), and Mariano Fuentes (CTO), who is Claudio’s brother. Claudio and Mariano had been building companies together for nearly a decade before the three converged.
Claudio’s career included co-founding Noonshot (which was acquired) and AskNed (used by Lionsgate and NBC Universal), as well as a stint as senior product manager at Pypestream, where he built enterprise AI products for clients including Shell, JPMorgan Chase, and Royal Caribbean. He and Mariano then built LeapAI, a workflow platform that raised $1.4 million from Founders Inc., David Cramer of Sentry, and Paul Copplestone of Supabase, and attracted customers including Heineken, Inflection, and Live Nation.
LeapAI ran for roughly two years and grew to more than a million users. The trio eventually shut it down after concluding they had not found a ‘sticky enough use case to warrant continued investment.’ The lesson that stuck, beyond how to build with large language models, was mundane: SOC 2 compliance was painful.
‘It’s a very obscure process,’ Claudio said. ‘It took us a couple of months of doing things by hand, and the whole time it meant taking our eyes off building the product.’
That frustration became the product. This time, Carhart took the lead as CEO (it was his idea, the founders have said) and the company was built around automating the compliance burden that had slowed them down at LeapAI.
What the Comp AI Series A Will Fund
Comp AI’s platform uses AI agents to handle the work that compliance teams have historically done by hand: drafting security policies, collecting audit evidence, and continuously monitoring whether a company is meeting its control requirements. The software also includes AI-powered penetration testing that, as Carhart described it, ‘proactively tests codebases and infrastructures for vulnerabilities.’
It does not replace the independent auditor, and the founders are deliberate about the human element inside their own system. ‘An agent might draft a policy, for example, but a person still reviews and approves it,’ Carhart said. ‘As agents take on more consequential actions over time, we believe the level of safeguards and human approval should increase accordingly.’
The round will accelerate expansion beyond compliance automation into continuous cybersecurity: real-time monitoring, control validation, and security testing across applications and infrastructure. Hiring is planned across product, engineering, operations, sales, customer success, and marketing, split between the company’s Miami headquarters and its New York office, according to CityBiz.
The scale of the ambition is a long way from the company’s early days. Grand Ventures General Partner Nathan Owen has said Comp AI had four employees working from a single room when he first visited the New York office.
Roo Capital, which PitchBook identifies as a Miami-based firm founded in 2021 that focuses on early-stage SaaS, healthcare software, and cybersecurity companies, led the round alongside Grand Ventures. The firm has made 31 investments to date.
Comp AI enters the market alongside an expanding field of compliance-adjacent platforms. Carhart frames the opportunity around a structural gap in how compliance has traditionally worked. ‘Imagine a company completes its SOC 2 audit and two weeks later deploys a new AI agent that can access customer data, change permissions across an internal system, or introduce a new vulnerability through code deployment,’ he said. ‘The audit didn’t become invalid; it simply wasn’t designed to tell you in real time what changed afterward.’
For Mariano, the answer begins with permissions and accountability. As companies adopt more AI, he has said, they need to demonstrate what an agent accessed, what it tried to do, and whether it stayed within its assigned boundaries. ‘We’re building toward a security layer that can monitor and validate those kinds of risk more continuously as these systems evolve,’ he said.
PitchBook lists Comp AI as a revenue-generating private company with 33 employees. The company has set a clear direction of travel: moving upmarket toward enterprise clients, the same segment whose demands first revealed the SOC 2 problem at LeapAI. Whether those clients will stay once the next audit cycle begins is the test the $34 million is meant to answer.
