Comp AI
by Comp AI (Bubba AI Inc.)
Open-source, agentic compliance automation for SOC 2, ISO 27001, HIPAA and GDPR: an AGPL alternative to Vanta and Drata
Comp AI is an open-core compliance automation platform that uses AI agents to draft policies, collect audit evidence, monitor employee devices and run penetration tests for SOC 2, ISO 27001, HIPAA, GDPR and other frameworks. It is aimed at startups and growing software companies that need audit readiness fast and want inspectable, self-hostable code instead of a closed SaaS.
Comp AI is a compliance automation platform built by Bubba AI Inc., a company started in January 2025 by Lewis Carhart (CEO), Claudio Fuentes (COO) and Mariano Fuentes (CTO), which runs out of Miami with an office in New York. It positions itself as an open-source alternative to Vanta and Drata: roughly 99% of the codebase is published on GitHub under AGPLv3, with enterprise features in an /ee directory under a commercial licence, and the main repository has about 2,000 stars and more than 8,000 commits. The product generates a company's security policies from onboarding context and lets users edit them in plain language through a diff view; turns a prompt describing a control into a recurring automation that collects and stores evidence; runs an open-source Device Agent on macOS, Windows and Ubuntu that checks disk encryption, antivirus, password policy and screen-lock settings every hour; and adds agent-driven penetration testing of code, APIs and infrastructure, vendor risk scoring and a live-monitored Trust Portal. It connects to more than 580 tools including AWS, GCP and Azure, and its pricing page scopes quotes across frameworks from SOC 2, ISO 27001, HIPAA and GDPR to PCI DSS, ISO 42001, NIST and FedRAMP. Comp AI does not itself issue the SOC 2 opinion; that still requires an independent CPA firm. On September 17, 2026 it raised a $34 million Series A led by Roo Capital and Grand Ventures, bringing total funding to $36.6 million, and said more than 1,000 companies use it, including Dub and OpenCode, with annual recurring revenue up 15x over the past year.
Founders, CTOs or first security hires at startups and scale-ups that need SOC 2 or ISO 27001 readiness quickly to close enterprise deals, and prefer inspectable open-source tooling.
Audit readiness in days rather than months, with policies, evidence collection and device checks generated and monitored by agents.
At a Glance
- Category
- Governance & Security
- Pricing
- Contact for pricing, Subscription
- Target Market
- CTOs, CISOs, Founders, Security & Compliance Teams
- Deployment
- Cloud-first, Open-source
- Founded
- 2025
- Headquarters
- Miami, United States
- Customers
- 1,000+ companies
Key Features
- ✓AI policy generation and editor
Generates every policy from onboarding context and proposes plain-language edits in a diff view before anything is accepted.
- ✓Automated evidence agents
Turn a prompt describing a control into a recurring automation that collects and stores audit evidence on a schedule.
- ✓Open-source Device Agent
Checks disk encryption, antivirus, password policy and screen lock hourly on macOS, Windows and Ubuntu without collecting personal data.
- ✓Agentic penetration testing
Agents probe code, APIs and infrastructure and produce audit-ready reports, extending the product from compliance tracking into security testing.
- ✓Trust Portal and vendor risk
Publishes only verified controls and approved policies to customers, and scores vendors with alerts before issues become audit findings.
- ✓580+ integrations and API
Connects to AWS, GCP, Azure and hundreds of SaaS tools for daily checks, with an API for building internal evidence tooling.
Capabilities
Use Cases
- •First SOC 2 for enterprise sales
A seed-stage SaaS company generates its policies, connects its cloud accounts and reaches audit readiness before engaging an independent CPA auditor.
- •Multi-framework compliance
A health-tech startup manages SOC 2 and HIPAA controls in a single workspace instead of running two parallel compliance programmes.
- •Endpoint compliance evidence
IT deploys the Device Agent to every laptop so encryption and screen-lock evidence is collected hourly instead of through manual screenshots.
- •Customer security reviews
Sales teams point prospects to a live Trust Portal showing verified controls and published policies, shortening security questionnaires and vendor reviews.
Ideal For
Best For
- ✓Startups needing a first SOC 2 report to unblock enterprise sales
- ✓Engineering-led teams that want to inspect or self-host their compliance tooling under AGPLv3
- ✓Companies running several frameworks (SOC 2 plus HIPAA, ISO 27001 or ISO 42001) in one workspace
- ✓Small teams that want hands-on help through a shared Slack channel with compliance experts
- ✓Organisations on mainstream cloud stacks (AWS, GCP, Azure) where connectors automate most evidence
Not Ideal For
- ✗Buyers who need transparent list pricing: Comp AI quotes only after a 20-minute call, and an independent review reports 12-month terms with automatic renewal.
- ✗Companies on nonstandard or unsupported cloud and SaaS stacks, where users report connectors automate less than expected and manual evidence uploads remain.
- ✗Organisations of roughly 100+ people that depend on SCIM-driven identity lifecycle, which reviewers could not confirm is supported natively.
Deployment
Market & Ratings
1,000+ companies
Market Analysis
Pros
- ✓Inspectable, self-hostable open-core code
- ✓Fast path to audit readiness for small teams; 24 of 25 users interviewed by an independent reviewer scored it 4-5
- ✓Broad framework coverage including ISO 42001 and FedRAMP
- ✓Rapid growth (15x ARR in a year) and fresh Series A funding
Cons
- ✗No published pricing, and 12-month contracts that renew automatically
- ✗Automation is stack-dependent: users still upload evidence manually for access reviews, vendor reviews and unusual controls
- ✗Native SCIM support is unconfirmed, a concern for identity lifecycle at around 100 employees
- ✗Young company (founded 2025) with far fewer reviews and integrations track record than Vanta
Pricing
Open-source core (self-hosted)
$0
- ✓AGPLv3 core (~99% of codebase)
- ✓Enterprise /ee features require a commercial licence
Managed platform
Contact for pricing
- ✓Quote scoped by frameworks, headcount, timeline and audit/pentest/trust-center needs
- ✓Shared Slack channel with compliance experts
Comp AI publishes no prices: quotes are scoped on a 20-minute call by frameworks in scope, headcount, timeline and whether audit, penetration testing or a trust center is needed. An independent September 2026 review reports 12-month minimum terms with automatic renewal and warns that older figures still circulating online ($199/month, $3,000) are retired. The AGPL core can be self-hosted at no licence cost.
Security & Compliance
Connect
Sources
This page was written from 7 sources, 5 on domains other than trycomp.ai.
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
Apollo Research Watcher
Runtime monitoring and blocking for Claude Code and Codex: catch dangerous coding-agent actions before they run
Mate Security
Open agentic SOC platform powered by a security context graph built for each organisation
Cymphony
Workforce security graph that maps what employees and AI agents can reach, then remediates the exposure
MintMCP
Enterprise MCP gateway that gives every AI agent its own identity, scoped tools and audit trail