
Comp AI · Comp AI: Open-Source AI Compliance Platform for SOC 2, ISO 27001 and HIPAA
Comp AI is an open-core compliance platform (AGPL-3.0) that uses AI agents to collect audit evidence, capture screenshots from vendor apps, draft policies, monitor cloud and device settings and run AI penetration tests for frameworks such as SOC 2, ISO 27001, HIPAA and GDPR. It suits startups and mid-market companies preparing for audits, especially teams that want to inspect or self-host the platform.
Best for
Startups and mid-market companies working toward SOC 2, ISO 27001, HIPAA or GDPR who want evidence collection and policy work automated, and engineering-led teams that value an open-source, self-hostable compliance platform
Not ideal for
Buyers who need transparent list pricing before talking to sales, organizations that want a fully managed compliance service with no internal owner, and teams that need a dedicated pentesting tool with broad asset coverage
Who it's for
Startups, mid-market companies and security or engineering leads preparing for compliance audits
Comp AI competes with Vanta and Drata on the usual compliance workflow but differs in two ways that matter to technical teams: the code is public, so you can read exactly what each check does or run it yourself, and evidence collection is extended by prompt-built automations and browser screenshots rather than waiting for a vendor to add an integration. The agent features reduce the grind of evidence and policy work, but they do not replace an owner who reviews policies and answers auditors. Quote-only pricing makes budgeting harder, so request pricing for your exact frameworks and ask whether the audit and pentest are included.
Who should use it
Startups facing their first SOC 2 or ISO 27001 audit, engineering-led companies that want to inspect or self-host their compliance tooling, and teams with vendor tools that lack APIs and need screenshot evidence collected automatically.
Who should skip it
Companies that want published pricing up front, organizations looking for a fully managed service with no internal compliance owner, and security teams whose main need is deep, standalone penetration testing.
First SOC 2 audit at a startup
Generated policies, integration-based evidence and scheduled automations remove much of the manual collection that usually delays an initial audit.
Evidence from tools without APIs
Browser Automations sign in like a person, take timestamped screenshots with pass or fail checks and repeat them on a schedule, instead of someone collecting screenshots before each audit.
Self-hosted compliance tooling
Teams with strict data-handling rules can run the AGPL-3.0 platform themselves with Docker rather than sending compliance data to a closed SaaS vendor.
Comp AI vs. Strix
Strix is an open-source AI pentesting tool for the CLI and CI that reports only validated findings. Comp AI includes a pentesting agent as one part of a broader compliance platform covering evidence, policies, cloud and device checks.
Comp AI vs. Shannon
Shannon is an open-source AI pentester that combines source-code analysis with testing of a running web app. Comp AI's pentest runs against a target URL with optional repository context and keeps findings, dispute justifications and PDF reports inside the compliance platform, where auditors get read-only access.
What is Comp AI?
Comp AI is a compliance automation platform that uses AI agents to collect audit evidence, generate policies, monitor cloud and device security settings, answer security questionnaires and run AI penetration tests, for frameworks such as SOC 2, ISO 27001, HIPAA and GDPR.
Is Comp AI open source?
Mostly. The repository at github.com/trycompai/comp is licensed AGPL-3.0 for the core, which the project describes as 99% of the code, and an enterprise edition directory is under a commercial license. The device agent is also open source.
Can Comp AI be self-hosted?
Yes. The docs include a Docker Compose self-hosting guide. It needs an external PostgreSQL 14+ database with SSL plus accounts with Trigger.dev (hosted) for background jobs and Resend for email, and each service has its own env file.
How much does Comp AI cost?
Comp AI does not publish prices. Its pricing page says quotes depend on the frameworks in scope, company size, timeline and whether audits or penetration testing are included, and you book a 20-minute call to get one.
Which frameworks does Comp AI support?
The pricing page lists SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, SOC 1, NIST, ISO 42001, ISO 9001, CCPA, EN 7510 and FedRAMP.
Does Comp AI work with Claude Code or Cursor?
Yes. The recommended option is Comp AI's hosted MCP Connector, which you add with one URL and an OAuth sign-in. There is also a self-run npm package, @trycompai/mcp-server, that uses a Comp AI API key and has setup steps for Claude Desktop, Claude Code, Cursor, VS Code, Codex, Gemini CLI and Windsurf. Either way, the assistant can only do what your role allows in the dashboard.

Strix (OmniSecure, Inc.)
Engineering and AppSec teams that want open-source, AI-driven pentesting of their own apps and APIs in the CLI or CI, with an option to move to a managed platform
FreemiumKeygraph
Engineering teams with access to both the source code and a staging copy of their web app or API who want open-source, evidence-backed security testing in CI
FreemiumComp AI is an alternative to Vanta and Drata whose core code is public on GitHub under AGPL-3.0, with a small enterprise edition under a commercial license. After onboarding, where you describe your stack, processes and risk tolerance, it generates policies for you to review and maps controls to the frameworks in scope, which include SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, ISO 42001 and FedRAMP. The agentic parts sit on top of that. Automated Evidence lets you describe what proof a task needs in plain language, for example checking that Dependabot is enabled on a GitHub repository. The agent builds the automation, you test and publish it, and it re-runs on the task's schedule. Browser Automations sign into vendor web apps without an API, take timestamped screenshots with optional pass or fail checks, and re-authenticate on their own, pausing for a human when a CAPTCHA or passkey appears. Cloud Tests scan AWS, Azure and GCP read-only, with opt-in auto-remediation on AWS, and an open-source device agent checks disk encryption, antivirus, password policy and screen lock on macOS, Windows and Linux. A penetration testing agent runs one-time external assessments against a target URL, optionally with repository context, and produces customer-shareable PDF reports, and your written reasons for disputing findings are passed to the agent on retests of the same target. Security questionnaires are answered from your policies, and a trust portal handles external access requests. There is an API, plus MCP access through a hosted connector with OAuth sign-in or a self-run npm server, so Claude Code, Cursor, ChatGPT and other clients can act on the program under your role's permissions. The company says a person still reviews and approves what agents draft. The tradeoffs: pricing is quote-only, audits and pentests are scoped into the price rather than listed, some agent features must be enabled for your organization, and self-hosting needs external services such as Trigger.dev and Resend.
Comp AI raised a $34 million Series A led by Roo Capital and Grand Ventures, bringing total funding to $37.5 million, to build an agentic security and compliance platform with human approval of agent work.
Are you the founder? Claim this listing →