This Startup Just Raised $34 Million to Let AI Handle Security Checks

Comp AI has raised $34 million in a Series A round led by Roo Capital and Grand Ventures. TechCrunch
The financing was announced on Sept. 17, 2026. It brings total funding to $37.5 million. The company was started by Lewis Carhart, Claudio Fuentes and Mariano Fuentes, who serve as chief executive, chief operating officer and chief technology officer.
Comp AI makes AI helpers for computer security and rule-following. The helpers write security rules and gather the proof needed to pass security audits. That work often pulls engineers away from product work and leaves risk and compliance teams with hours of manual follow-up.
The system also watches all the time to check if a company still follows its security rules. It also runs simulated attacks to test software and company systems for weak spots.
The broader context here is a shift from a yearly inspection to constant monitoring. Think of it like a car inspection that never stops. Older tools stored documents in one place, assigned an owner to each rule and pulled in data as proof. The new approach tries to do the whole loop on its own, writing drafts, fetching proof and starting checks without a person filing a request.
In my view, writing the rules is not the hard part. That part is cheap. Keeping them up to date is hard. Systems change, suppliers change and access habits change. Proof gets old between checks. Watching continuously addresses the right problem, if the checks show what is really happening and not only what looks good on a screen.
In practical terms for the people who do this work, the impact splits two ways. For engineers, automatic proof collection could turn audit season from a quarterly scramble into background work. For security chiefs, auditors and customers, computer-written records still need version history, approval records and clear sign-off. Responsibility does not go away. It moves to review and control of changes.
One part worth flagging is the simulated attacks. Normal tests are limited in time and led by people, with clear rules about what can be touched. AI helpers can cover more ground and test sooner after a change. The bar will be clean results. Teams will trust the findings only if duplicates are removed, real risk is confirmed and runs are safe near live systems. Without that care, more results mean more cleanup work.
Looking further out, the goal is rule-following built into daily engineering work instead of added just before an audit. People would set the intent and review exceptions. That future is plausible and hopeful, because it could free small teams from repetitive work for design and response. It will depend on transparency. Customers and auditors need to see what was checked and repeat the check.


