Comp AI SOC 2 compliance software
Comp AI uses an open-core model: its repository says roughly 99% is AGPLv3 and the enterprise-edition directory is commercially licensed. The current pricing page is quote-only and scopes the price by frameworks, headcount, timeline, audit, penetration testing, and trust-center needs.
By Peter Korpak, Lead Editor · independently researched · Methodology
- Pricing
- Quote-based
- Source-checked frameworks
- 11
- Integrations
- 590+
- G2 (2026-08-11)
- 4.7 · 68 reviews
A separate vendor timeline article still publishes a $5,000-$10,000 SOC 2 range, so we do not treat that figure as a current standard rate card. Standard terms state a 12-month minimum commitment and automatic one-year renewals unless either party gives 30 days' written notice; the signed Order Form controls the actual term and fee. G2 showed 4.7/5 across 68 reviews on 2026-08-11; one reviewer reported intermittent automation failures and wanted stronger GDPR support.
Comp AI (legal entity Bubba AI, Inc.) announced a $2.6M pre-seed round on July 28, 2025, co-led by OSS Capital and Grand Ventures, with participation from David Cramer and Ben Tossell.
What Comp AI does.
Seven capabilities, graded the same way for every platform in the directory. "Not established" means we looked and could not confirm it, not that the feature is missing.
| Capability | Status | Evidence |
|---|---|---|
| Automated evidence collection | Yes | Independent write-up confirms an 'Automated Evidence' feature that builds recurring evidence-collection automations from a plain-language prompt. Source |
| Auditor workspace | Partial | Current API docs expose a built-in auditor role, an auditor-only bulk evidence export, audit findings, revision notes, and remediation status transitions. That establishes an in-product auditor workflow, but we did not independently test the browser UI or confirm the exact organization-level scope presented to an invited auditor. Source |
| Trust center | Yes | Live public trust center exists and is linked from the vendor homepage; vendor claims only published policies and verified controls surface (unverified independently). Source |
| Security questionnaire answering | Yes | A Security Questionnaire feature appears in the product docs; Help Net Security confirms published policies feed answers automatically. Source |
| Enterprise admin (SSO, SCIM, RBAC) | Partial | Vendor security page and API docs confirm custom roles and fine-grained RBAC. The current product docs do not establish SSO or SCIM; treat them as unconfirmed rather than absent. Source |
| SCIM 2.0 provisioning | Not established | Comp AI's current product documentation index, security page, pricing page, and self-hosting authentication reference do not document SCIM. Absence is not proof that the feature is unavailable, so the result remains unknown. |
| Continuous control testing | Yes | Device Agent runs hourly checks on four controls (disk encryption, AV, password policy, screen lock); homepage separately claims daily cloud-infrastructure scans. Source |
| Native multi-framework support | Partial | Pricing page states 'controls map across frameworks,' and adding ISO 27001 to an existing SOC 2 program 'starts about two-thirds done' - implying SOC 2 is the base control set with other frameworks crosswalk-mapped from it, not independently confirmed per-framework. Source |
11 frameworks checked individually, and how well each is established.
A framework on a marketing page is a vendor claim, not a confirmed capability. We grade the difference rather than repeating the list.
| Framework | Evidence | Note |
|---|---|---|
| SOC 2 | Vendor-claimed | Primary framework in all vendor and press material; independently corroborated by Help Net Security (Apr 2026). Source |
| ISO 27001 | Vendor-claimed | Source |
| HIPAA | Vendor-claimed | Source |
| GDPR | Vendor-claimed | A G2 reviewer noted a wish for stronger GDPR-specific support, see openQuestions. Source |
| PCI DSS | Vendor-claimed | Listed under "Frameworks we quote" on the pricing page. Source |
| SOC 1 | Vendor-claimed | Source |
| FedRAMP | Vendor-claimed | Also referenced on the homepage as available for enterprise-stage customers. Source |
| ISO 42001 | Vendor-claimed | Source |
| ISO 9001 | Vendor-claimed | Listed under frameworks Comp AI quotes; this establishes vendor-claimed availability, not certification or independently validated control depth. Source |
| CCPA | Vendor-claimed | Listed under frameworks Comp AI quotes. Source |
| NEN 7510 | Vendor-claimed | Listed under frameworks Comp AI quotes. The same page says only 'NIST' without naming CSF, 800-53, or 800-171, so no specific NIST framework is recorded. Source |
Comp AI uses quote-based pricing.
Getting a direct number requires a sales conversation. Anything below comes from reported quotes or marketplace listings, and is labeled as such.
- Disclosure model
- Quote-based
- Sourced annual price
- None found
- Basis
- Estimate, 2026-08-11
Software pricing alone does not establish the audit fee. A licensed CPA firm issues the SOC 2 report. A commercial offer may package coordination or the fee, so get the legal provider, deliverable, and amount in writing. See the SOC 2 audit cost guide for scope and budget context.
Read the Comp AI pricing guide for the current source table and quote checklist.
Who actually issues the report.
Comp AI does not issue the SOC 2 report. Its FAQ says customers may bring any accredited auditor, while current API docs document a built-in auditor role, auditor-only bulk evidence export, and finding/revision workflows. Comp AI also markets access to pre-vetted auditors, but no specific audit firm is named in the current product or pricing materials; confirm the legal CPA firm and fee in the quote.
Software prepares you for the audit; a licensed CPA firm performs it and issues the report. If you have not picked a firm yet, we list independent SOC 2 auditors separately, and we are not one of them.
Who Comp AI is for, and who it is not.
Good fit
An engineering-led company that values an inspectable, self-hostable compliance platform and wants one vendor scope that can include guided implementation, a trust center, penetration testing, and audit coordination when quoted.
Poor fit
A buyer who needs a published rate card before speaking with sales, requires confirmed SCIM-based provisioning, or expects every managed-cloud enterprise control to follow automatically from the public open-core codebase.
Typical buyer: Engineering-led startups and growing software companies pursuing SOC 2 or adjacent frameworks, especially teams that value inspectable evidence-collection code or want the option to self-host.
Compare Comp AI with three alternatives.
-
The team can own audit preparation internally and prioritizes broad connector coverage.
-
A founder or CTO needs a dedicated consultant alongside the software for a first audit.
-
Continuous monitoring and a mature managed evidence workflow matter.
Where every figure on this page came from.
11 sources, each with what it establishes and when we read it. If a claim here is out of date, this is the list that tells you which one to re-check.
- Product positioning, 580+ integrations and 1,000+ companies claims, core feature list, daily cloud scans, guided Slack support, and FAQ statements that Comp AI is auditor-agnostic and does not issue the report. https://www.trycomp.ai/
- Current pricing is quote-only with no public rate card; price varies by framework, headcount, timeline, and included audit, penetration-test, and trust-center scope; frameworks quoted include ISO 42001, ISO 9001, CCPA, and NEN 7510. https://www.trycomp.ai/pricing
- RBAC / role-based permissions, encryption, multi-tenant isolation claims. https://www.trycomp.ai/security
- Documentation index and API references for automated evidence, device compliance, questionnaires, penetration tests, Trust Access, cloud checks, custom roles, an auditor role, auditor-only evidence export, and audit-finding workflows. https://www.trycomp.ai/docs/llms.txt
- Open-core license split (repository states 99% AGPLv3 and 1% commercial enterprise edition), self-hosting instructions, 1.9k stars, 376 forks, and 10 watchers as of retrieval date. https://github.com/trycompai/comp
- Independent description of the open-core license split, Device Agent behavior (hourly checks, supported OS versions, no PII collected), Security Questionnaire and API existence, cloud integrations (AWS/GCP/Azure). https://www.helpnetsecurity.com/2026/04/07/comp-ai-open-source-compliance-platform/
- Company announcement dated July 28, 2025: $2.6M pre-seed co-led by OSS Capital and Grand Ventures with participation from David Cramer and Ben Tossell; founders named as Mariano Fuentes, Lewis Carhart, and Claudio Fuentes. https://www.trycomp.ai/hub/comp-ai-pre-seed-round
- Standard terms identify Bubba AI, Inc. d/b/a Comp AI, require a minimum 12-month commitment, and auto-renew subscriptions for successive one-year periods unless either party gives at least 30 days' written notice. https://www.trycomp.ai/legal/terms-of-service
- 4.7-star rating from 68 reviews. https://www.g2.com/sellers/comp-ai
- Reviewer-reported limitation: some automations fail randomly; desire for stronger GDPR support. https://www.g2.com/products/comp-ai/reviews
- Company profile confirming product description and funding record exist in Crunchbase's database. https://www.crunchbase.com/organization/comp-ai
← All SOC 2 compliance software · Comp AI review · How we verify