
Comp AI has raised a $15.7 million Series A round led by Salesforce Ventures, with participation fro...
The AMW Read
Company automates security/compliance tasks including policy drafting and evidence collection, positioning it as an AI agent builder; the rise of AI agents creating new compliance obligations and the need to track agent behavior grounds this in 02.§1 (agent definition/boundary) and cross.§F (data/IP
Comp AI has raised a $15.7 million Series A round led by Salesforce Ventures, with participation from Y Combinator, to expand its AI-powered security and compliance automation platform. The startup, founded by the team behind the shuttered open-source privacy tool OneRep, helps companies automate SOC 2 audits, security policy writing, and evidence collection, with plans to extend into fully autonomous compliance workflows. Co-founder and CEO Navin Carhart said the funding will accelerate product expansion as enterprises grapple with continuous security requirements in the agentic era.
The funding signals a shift in how security and compliance platforms are positioning themselves for an AI-driven software landscape, where agents increasingly handle tasks that touch customer data and internal systems. Rather than treating security and compliance as a one-time box-checking exercise, Comp AI is targeting continuous, semi-autonomous compliance—a model that becomes more defensible as every new model deployment or agent integration introduces fresh risk surfaces. This aligns with a broader market trend where compliance tech is evolving from static audit preparation into dynamic, always-on governance infrastructure, creating opportunities for startups that can differentiate on automation depth in an increasingly crowded space.
For builders, the clear takeaway is that security and compliance are no longer just back-office burdens but are becoming direct enablers of AI adoption. As companies push agents into production, the ability to demonstrate auditable, bounded behavior will become a competitive differentiator. Investors backing Comp AI are betting that the next wave of security incumbents will be those that bake continuous compliance into the AI lifecycle itself—from policy generation to evidence collection—rather than bolting it on after the fact.



