LaunchedEditorial Listing

Comp AI

Comp AI · Comp AI: Open-Source AI Compliance Platform for SOC 2, ISO 27001 and HIPAA

Open Comp AI

Comp AI is an open-core compliance platform (AGPL-3.0) that uses AI agents to collect audit evidence, capture screenshots from vendor apps, draft policies, monitor cloud and device settings and run AI penetration tests for frameworks such as SOC 2, ISO 27001, HIPAA and GDPR. It suits startups and mid-market companies preparing for audits, especially teams that want to inspect or self-host the platform.

PricingCustom
Setupmedium
Runs onWeb · API · Browser extension · Self-hosted
APIYes
Open sourceYes
DocsYes
CategorySecurity
ComplianceSOC 2ISO 27001HIPAAGRCAudit EvidenceOpen SourceMCP

Best for

Startups and mid-market companies working toward SOC 2, ISO 27001, HIPAA or GDPR who want evidence collection and policy work automated, and engineering-led teams that value an open-source, self-hostable compliance platform

Not ideal for

Buyers who need transparent list pricing before talking to sales, organizations that want a fully managed compliance service with no internal owner, and teams that need a dedicated pentesting tool with broad asset coverage

Who it's for

Startups, mid-market companies and security or engineering leads preparing for compliance audits

Capabilities

  • Evidence agent that turns a plain-language request into an automation, lets you test the output, then re-runs it on a schedule to keep the task's evidence current
  • Browser Automations that sign into vendor web apps without APIs, capture timestamped screenshots with optional pass or fail checks, and handle two-factor sign-in
  • Collects evidence from 580+ integrations, and new integrations and checks can be written and contributed through the open-source repo
  • Generates policies from onboarding context about your stack, processes and risk tolerance, edited in an AI policy editor
  • Cloud Tests for AWS, Azure and GCP that run read-only by default and map misconfigurations to SOC 2, ISO 27001, CIS, PCI DSS and HIPAA controls, with opt-in auto-remediation on AWS
  • Open-source device agent for macOS 14+, Windows 10+ and Ubuntu 20.04+ that checks disk encryption, antivirus, password policy and screen lock every hour and offers fixes for failing checks
  • Penetration testing agent that runs one-time external assessments against a target URL, optionally with repository context, with finding triage and Markdown or customer-shareable PDF reports
  • Security questionnaire answering from your policies and knowledge base, plus a Chrome extension that drafts answers on the vendor's own page
  • Trust portal that manages external access requests, NDA signing and time-limited access to your security documents
  • Compliance API plus MCP access, either a hosted connector with OAuth sign-in or the self-run @trycompai/mcp-server package, for Claude Desktop, Claude Code, Cursor, VS Code, Codex, Windsurf, Gemini and ChatGPT, limited to your role's permissions
  • Self-hosting with Docker from the public AGPL-3.0 repository

Limitations

  • No public pricing. Quotes depend on frameworks, company size, timeline and whether audits or pentests are included, and require a sales call
  • The core is AGPL-3.0, but a small enterprise edition is under a commercial license, so not every feature is open source
  • Self-hosting requires external services, including an external PostgreSQL 14+ database, hosted Trigger.dev for background jobs and Resend for email, plus several per-service env files to configure
  • Browser Automations and Penetration Tests are listed as features your organization must have enabled, and each pentest run goes through a checkout step
  • Browser Automations pause and need a human when they hit CAPTCHAs, device approvals or passkeys
  • Cloud auto-remediation is documented only for AWS
  • The pentest docs describe one-time external tests of a target URL and do not spell out coverage for other asset types
  • AI-drafted policies and evidence still need human review, as the company itself stresses

Use cases

  • Getting a startup ready for a first SOC 2 Type I audit, with generated policies and evidence collected from GitHub, cloud accounts and HR tools
  • Creating an automation that checks Dependabot or branch protection on every repository and refreshes the evidence each month
  • Capturing monthly screenshots of admin security settings in a SaaS tool that has no API
  • Rolling out the device agent to employee laptops to prove disk encryption and screen-lock policies
  • Running an AI pentest on a web app and sharing the PDF report with a customer's security team
  • Answering a customer security questionnaire from existing policies

Our take

Comp AI competes with Vanta and Drata on the usual compliance workflow but differs in two ways that matter to technical teams: the code is public, so you can read exactly what each check does or run it yourself, and evidence collection is extended by prompt-built automations and browser screenshots rather than waiting for a vendor to add an integration. The agent features reduce the grind of evidence and policy work, but they do not replace an owner who reviews policies and answers auditors. Quote-only pricing makes budgeting harder, so request pricing for your exact frameworks and ask whether the audit and pentest are included.

Who should use it

Startups facing their first SOC 2 or ISO 27001 audit, engineering-led companies that want to inspect or self-host their compliance tooling, and teams with vendor tools that lack APIs and need screenshot evidence collected automatically.

Who should skip it

Companies that want published pricing up front, organizations looking for a fully managed service with no internal compliance owner, and security teams whose main need is deep, standalone penetration testing.

Strengths

  • Core platform and device agent are public on GitHub under AGPL-3.0 and can be self-hosted
  • Evidence automations built from plain-language prompts keep evidence current on a schedule
  • Browser Automations reach vendor apps that have no API
  • Covers compliance, cloud posture, device checks and pentesting in one platform
  • API and MCP server let teams run compliance tasks from coding assistants under existing permissions

Weaknesses

  • Quote-only pricing with a sales call required
  • A small enterprise edition is under a commercial license
  • Self-hosting depends on external services and careful configuration
  • Browser Automations stop at CAPTCHAs and passkeys

Technical specs

Where Comp AI excels

First SOC 2 audit at a startup

Generated policies, integration-based evidence and scheduled automations remove much of the manual collection that usually delays an initial audit.

Evidence from tools without APIs

Browser Automations sign in like a person, take timestamped screenshots with pass or fail checks and repeat them on a schedule, instead of someone collecting screenshots before each audit.

Self-hosted compliance tooling

Teams with strict data-handling rules can run the AGPL-3.0 platform themselves with Docker rather than sending compliance data to a closed SaaS vendor.

Comp AI vs. competitors

Comp AI vs. Strix

Strix is an open-source AI pentesting tool for the CLI and CI that reports only validated findings. Comp AI includes a pentesting agent as one part of a broader compliance platform covering evidence, policies, cloud and device checks.

Comp AI vs. Shannon

Shannon is an open-source AI pentester that combines source-code analysis with testing of a running web app. Comp AI's pentest runs against a target URL with optional repository context and keeps findings, dispute justifications and PDF reports inside the compliance platform, where auditors get read-only access.

Frequently asked questions

What is Comp AI?

Comp AI is a compliance automation platform that uses AI agents to collect audit evidence, generate policies, monitor cloud and device security settings, answer security questionnaires and run AI penetration tests, for frameworks such as SOC 2, ISO 27001, HIPAA and GDPR.

Is Comp AI open source?

Mostly. The repository at github.com/trycompai/comp is licensed AGPL-3.0 for the core, which the project describes as 99% of the code, and an enterprise edition directory is under a commercial license. The device agent is also open source.

Can Comp AI be self-hosted?

Yes. The docs include a Docker Compose self-hosting guide. It needs an external PostgreSQL 14+ database with SSL plus accounts with Trigger.dev (hosted) for background jobs and Resend for email, and each service has its own env file.

How much does Comp AI cost?

Comp AI does not publish prices. Its pricing page says quotes depend on the frameworks in scope, company size, timeline and whether audits or penetration testing are included, and you book a 20-minute call to get one.

Which frameworks does Comp AI support?

The pricing page lists SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, SOC 1, NIST, ISO 42001, ISO 9001, CCPA, EN 7510 and FedRAMP.

Does Comp AI work with Claude Code or Cursor?

Yes. The recommended option is Comp AI's hosted MCP Connector, which you add with one URL and an OAuth sign-in. There is also a self-run npm package, @trycompai/mcp-server, that uses a Comp AI API key and has setup steps for Claude Desktop, Claude Code, Cursor, VS Code, Codex, Gemini CLI and Windsurf. Either way, the assistant can only do what your role allows in the dashboard.

Integrations & fit

580+ integrationsGitHubAWSMicrosoft AzureGoogle CloudAikido SecurityMCP (Claude Code, Cursor, ChatGPT, Codex)API
Good fit forStartup / small team, Enterprise
Pricing modelCustom· Contact for pricing
See pricing on Comp AI →

Alternatives to consider

About Comp AI

Comp AI is an alternative to Vanta and Drata whose core code is public on GitHub under AGPL-3.0, with a small enterprise edition under a commercial license. After onboarding, where you describe your stack, processes and risk tolerance, it generates policies for you to review and maps controls to the frameworks in scope, which include SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, ISO 42001 and FedRAMP. The agentic parts sit on top of that. Automated Evidence lets you describe what proof a task needs in plain language, for example checking that Dependabot is enabled on a GitHub repository. The agent builds the automation, you test and publish it, and it re-runs on the task's schedule. Browser Automations sign into vendor web apps without an API, take timestamped screenshots with optional pass or fail checks, and re-authenticate on their own, pausing for a human when a CAPTCHA or passkey appears. Cloud Tests scan AWS, Azure and GCP read-only, with opt-in auto-remediation on AWS, and an open-source device agent checks disk encryption, antivirus, password policy and screen lock on macOS, Windows and Linux. A penetration testing agent runs one-time external assessments against a target URL, optionally with repository context, and produces customer-shareable PDF reports, and your written reasons for disputing findings are passed to the agent on retests of the same target. Security questionnaires are answered from your policies, and a trust portal handles external access requests. There is an API, plus MCP access through a hosted connector with OAuth sign-in or a self-run npm server, so Claude Code, Cursor, ChatGPT and other clients can act on the program under your role's permissions. The company says a person still reviews and approves what agents draft. The tradeoffs: pricing is quote-only, audits and pentests are scoped into the price rather than listed, some agent features must be enabled for your organization, and self-hosting needs external services such as Trigger.dev and Resend.

Updates from Comp AI

MilestoneComp AI raises $34M Series A

Comp AI raised a $34 million Series A led by Roo Capital and Grand Ventures, bringing total funding to $37.5 million, to build an agentic security and compliance platform with human approval of agent work.

Are you the founder? Claim this listing →