C

Comp AI

by Comp AI (Bubba AI Inc.)

Governance & SecurityAutomation & Workflows

Open-source, agentic compliance automation for SOC 2, ISO 27001, HIPAA and GDPR: an AGPL alternative to Vanta and Drata

Contact for pricing · Subscription·Added Sep 18, 2026·Updated Sep 18, 2026
Share:
THE DAILY BRIEF
Comp AI

by Comp AI (Bubba AI Inc.)

Governance & SecurityAutomation & Workflows

Open-source, agentic compliance automation for SOC 2, ISO 27001, HIPAA and GDPR: an AGPL alternative to Vanta and Drata

Contact for pricing · Subscription

Comp AI is an open-core compliance automation platform that uses AI agents to draft policies, collect audit evidence, monitor employee devices and run penetration tests for SOC 2, ISO 27001, HIPAA, GDPR and other frameworks. It is aimed at startups and growing software companies that need audit readiness fast and want inspectable, self-hostable code instead of a closed SaaS.

At a Glance

Category
Governance & Security
Pricing
Contact for pricing, Subscription
Target Market
CTOs, CISOs, Founders, Security & Compliance Teams
Deployment
Cloud-first, Open-source
Founded
2025
Headquarters
Miami, United States
Customers
1,000+ companies

Key Features

  • AI policy generation and editor
  • Automated evidence agents
  • Open-source Device Agent
  • Agentic penetration testing
  • Trust Portal and vendor risk
  • 580+ integrations and API

Capabilities

text generation
image generation
video generation
code generation
workflow automation
api access
audio generation
fine tuning
agent orchestration

Use Cases

  • First SOC 2 for enterprise sales
  • Multi-framework compliance
  • Endpoint compliance evidence
  • Customer security reviews

Ideal For

Best For

  • Startups needing a first SOC 2 report to unblock enterprise sales
  • Engineering-led teams that want to inspect or self-host their compliance tooling under AGPLv3
  • Companies running several frameworks (SOC 2 plus HIPAA, ISO 27001 or ISO 42001) in one workspace
  • Small teams that want hands-on help through a shared Slack channel with compliance experts
  • Organisations on mainstream cloud stacks (AWS, GCP, Azure) where connectors automate most evidence

Not Ideal For

  • Buyers who need transparent list pricing: Comp AI quotes only after a 20-minute call, and an independent review reports 12-month terms with automatic renewal.
  • Companies on nonstandard or unsupported cloud and SaaS stacks, where users report connectors automate less than expected and manual evidence uploads remain.
  • Organisations of roughly 100+ people that depend on SCIM-driven identity lifecycle, which reviewers could not confirm is supported natively.

Market Analysis

Open-sourceStartup and mid-marketVanta/Drata alternative

Pros

  • Inspectable, self-hostable open-core code
  • Fast path to audit readiness for small teams; 24 of 25 users interviewed by an independent reviewer scored it 4-5
  • Broad framework coverage including ISO 42001 and FedRAMP
  • Rapid growth (15x ARR in a year) and fresh Series A funding

Cons

  • No published pricing, and 12-month contracts that renew automatically
  • Automation is stack-dependent: users still upload evidence manually for access reviews, vendor reviews and unusual controls
  • Native SCIM support is unconfirmed, a concern for identity lifecycle at around 100 employees
  • Young company (founded 2025) with far fewer reviews and integrations track record than Vanta

Pricing

Open-source core (self-hosted)

$0

  • AGPLv3 core (~99% of codebase)
  • Enterprise /ee features require a commercial licence

Managed platform

Contact for pricing

  • Quote scoped by frameworks, headcount, timeline and audit/pentest/trust-center needs
  • Shared Slack channel with compliance experts

Comp AI publishes no prices: quotes are scoped on a 20-minute call by frameworks in scope, headcount, timeline and whether audit, penetration testing or a trust center is needed. An independent September 2026 review reports 12-month minimum terms with automatic renewal and warns that older figures still circulating online ($199/month, $3,000) are retired. The AGPL core can be self-hosted at no licence cost.

Security & Compliance

soc2
gdpr
hipaa
iso27001
sso
data residency

THE DAILY BRIEF

Enterprise AI insights for technology and business leaders, twice weekly.

beri.net

Subscribe at beri.net/subscribe for twice-weekly AI insights delivered to your inbox.

LinkedIn: linkedin.com/in/rberi  |  X: x.com/rajeshberi

© 2026 Rajesh Beri. All rights reserved.

Comp AI is an open-core compliance automation platform that uses AI agents to draft policies, collect audit evidence, monitor employee devices and run penetration tests for SOC 2, ISO 27001, HIPAA, GDPR and other frameworks. It is aimed at startups and growing software companies that need audit readiness fast and want inspectable, self-hostable code instead of a closed SaaS.

Comp AI is a compliance automation platform built by Bubba AI Inc., a company started in January 2025 by Lewis Carhart (CEO), Claudio Fuentes (COO) and Mariano Fuentes (CTO), which runs out of Miami with an office in New York. It positions itself as an open-source alternative to Vanta and Drata: roughly 99% of the codebase is published on GitHub under AGPLv3, with enterprise features in an /ee directory under a commercial licence, and the main repository has about 2,000 stars and more than 8,000 commits. The product generates a company's security policies from onboarding context and lets users edit them in plain language through a diff view; turns a prompt describing a control into a recurring automation that collects and stores evidence; runs an open-source Device Agent on macOS, Windows and Ubuntu that checks disk encryption, antivirus, password policy and screen-lock settings every hour; and adds agent-driven penetration testing of code, APIs and infrastructure, vendor risk scoring and a live-monitored Trust Portal. It connects to more than 580 tools including AWS, GCP and Azure, and its pricing page scopes quotes across frameworks from SOC 2, ISO 27001, HIPAA and GDPR to PCI DSS, ISO 42001, NIST and FedRAMP. Comp AI does not itself issue the SOC 2 opinion; that still requires an independent CPA firm. On September 17, 2026 it raised a $34 million Series A led by Roo Capital and Grand Ventures, bringing total funding to $36.6 million, and said more than 1,000 companies use it, including Dub and OpenCode, with annual recurring revenue up 15x over the past year.

Ideal Buyer

Founders, CTOs or first security hires at startups and scale-ups that need SOC 2 or ISO 27001 readiness quickly to close enterprise deals, and prefer inspectable open-source tooling.

Key Benefit

Audit readiness in days rather than months, with policies, evidence collection and device checks generated and monitored by agents.

At a Glance

Category
Governance & Security
Pricing
Contact for pricing, Subscription
Target Market
CTOs, CISOs, Founders, Security & Compliance Teams
Deployment
Cloud-first, Open-source
Founded
2025
Headquarters
Miami, United States
Customers
1,000+ companies

Key Features

  • AI policy generation and editor

    Generates every policy from onboarding context and proposes plain-language edits in a diff view before anything is accepted.

  • Automated evidence agents

    Turn a prompt describing a control into a recurring automation that collects and stores audit evidence on a schedule.

  • Open-source Device Agent

    Checks disk encryption, antivirus, password policy and screen lock hourly on macOS, Windows and Ubuntu without collecting personal data.

  • Agentic penetration testing

    Agents probe code, APIs and infrastructure and produce audit-ready reports, extending the product from compliance tracking into security testing.

  • Trust Portal and vendor risk

    Publishes only verified controls and approved policies to customers, and scores vendors with alerts before issues become audit findings.

  • 580+ integrations and API

    Connects to AWS, GCP, Azure and hundreds of SaaS tools for daily checks, with an API for building internal evidence tooling.

Capabilities

text generation
image generation
video generation
code generation
workflow automation
api access
audio generation
fine tuning
agent orchestration

Use Cases

  • First SOC 2 for enterprise sales

    A seed-stage SaaS company generates its policies, connects its cloud accounts and reaches audit readiness before engaging an independent CPA auditor.

  • Multi-framework compliance

    A health-tech startup manages SOC 2 and HIPAA controls in a single workspace instead of running two parallel compliance programmes.

  • Endpoint compliance evidence

    IT deploys the Device Agent to every laptop so encryption and screen-lock evidence is collected hourly instead of through manual screenshots.

  • Customer security reviews

    Sales teams point prospects to a live Trust Portal showing verified controls and published policies, shortening security questionnaires and vendor reviews.

Ideal For

Best For

  • Startups needing a first SOC 2 report to unblock enterprise sales
  • Engineering-led teams that want to inspect or self-host their compliance tooling under AGPLv3
  • Companies running several frameworks (SOC 2 plus HIPAA, ISO 27001 or ISO 42001) in one workspace
  • Small teams that want hands-on help through a shared Slack channel with compliance experts
  • Organisations on mainstream cloud stacks (AWS, GCP, Azure) where connectors automate most evidence

Not Ideal For

  • Buyers who need transparent list pricing: Comp AI quotes only after a 20-minute call, and an independent review reports 12-month terms with automatic renewal.
  • Companies on nonstandard or unsupported cloud and SaaS stacks, where users report connectors automate less than expected and manual evidence uploads remain.
  • Organisations of roughly 100+ people that depend on SCIM-driven identity lifecycle, which reviewers could not confirm is supported natively.

Deployment

On-Premise

Market & Ratings

Estimated Customers

1,000+ companies

Market Analysis

Open-sourceStartup and mid-marketVanta/Drata alternative

Pros

  • Inspectable, self-hostable open-core code
  • Fast path to audit readiness for small teams; 24 of 25 users interviewed by an independent reviewer scored it 4-5
  • Broad framework coverage including ISO 42001 and FedRAMP
  • Rapid growth (15x ARR in a year) and fresh Series A funding

Cons

  • No published pricing, and 12-month contracts that renew automatically
  • Automation is stack-dependent: users still upload evidence manually for access reviews, vendor reviews and unusual controls
  • Native SCIM support is unconfirmed, a concern for identity lifecycle at around 100 employees
  • Young company (founded 2025) with far fewer reviews and integrations track record than Vanta

Pricing

Open-source core (self-hosted)

$0

  • AGPLv3 core (~99% of codebase)
  • Enterprise /ee features require a commercial licence

Managed platform

Contact for pricing

  • Quote scoped by frameworks, headcount, timeline and audit/pentest/trust-center needs
  • Shared Slack channel with compliance experts

Comp AI publishes no prices: quotes are scoped on a 20-minute call by frameworks in scope, headcount, timeline and whether audit, penetration testing or a trust center is needed. An independent September 2026 review reports 12-month minimum terms with automatic renewal and warns that older figures still circulating online ($199/month, $3,000) are retired. The AGPL core can be self-hosted at no licence cost.

Security & Compliance

soc2
gdpr
hipaa
iso27001
sso
data residency

Connect

Sources

This page was written from 7 sources, 5 on domains other than trycomp.ai.

  1. 1.trycomp.aitrycomp.aivendor
  2. 2.trycomp.aipricingvendor
  3. 3.github.comcomp
  4. 4.siliconangle.comcompliance automation startup comp ai raises 34m to push int
  5. 5.helpnetsecurity.comcomp ai open source compliance platform
  6. 6.soc2auditors.orgcomp ai review
  7. 7.hn.algolia.comsearch
Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe