Logo Menu

Comp AI SOC 2 compliance software

Open-core, self-hostable SOC 2 / multi-framework compliance automation platform Last updated

Comp AI uses an open-core model: its repository says roughly 99% is AGPLv3 and the enterprise-edition directory is commercially licensed. The current pricing page is quote-only and scopes the price by frameworks, headcount, timeline, audit, penetration testing, and trust-center needs.

By , Lead Editor · independently researched · Methodology

Pricing
Quote-based
Source-checked frameworks
11
Integrations
590+
G2 (2026-08-11)
4.7 · 68 reviews
What the evidence says

A separate vendor timeline article still publishes a $5,000-$10,000 SOC 2 range, so we do not treat that figure as a current standard rate card. Standard terms state a 12-month minimum commitment and automatic one-year renewals unless either party gives 30 days' written notice; the signed Order Form controls the actual term and fee. G2 showed 4.7/5 across 68 reviews on 2026-08-11; one reviewer reported intermittent automation failures and wanted stronger GDPR support.

Company context

Comp AI (legal entity Bubba AI, Inc.) announced a $2.6M pre-seed round on July 28, 2025, co-led by OSS Capital and Grand Ventures, with participation from David Cramer and Ben Tossell.

Capabilities

What Comp AI does.

Seven capabilities, graded the same way for every platform in the directory. "Not established" means we looked and could not confirm it, not that the feature is missing.

CapabilityStatusEvidence
Automated evidence collection Yes Independent write-up confirms an 'Automated Evidence' feature that builds recurring evidence-collection automations from a plain-language prompt. Source
Auditor workspace Partial Current API docs expose a built-in auditor role, an auditor-only bulk evidence export, audit findings, revision notes, and remediation status transitions. That establishes an in-product auditor workflow, but we did not independently test the browser UI or confirm the exact organization-level scope presented to an invited auditor. Source
Trust center Yes Live public trust center exists and is linked from the vendor homepage; vendor claims only published policies and verified controls surface (unverified independently). Source
Security questionnaire answering Yes A Security Questionnaire feature appears in the product docs; Help Net Security confirms published policies feed answers automatically. Source
Enterprise admin (SSO, SCIM, RBAC) Partial Vendor security page and API docs confirm custom roles and fine-grained RBAC. The current product docs do not establish SSO or SCIM; treat them as unconfirmed rather than absent. Source
SCIM 2.0 provisioning Not established Comp AI's current product documentation index, security page, pricing page, and self-hosting authentication reference do not document SCIM. Absence is not proof that the feature is unavailable, so the result remains unknown.
Continuous control testing Yes Device Agent runs hourly checks on four controls (disk encryption, AV, password policy, screen lock); homepage separately claims daily cloud-infrastructure scans. Source
Native multi-framework support Partial Pricing page states 'controls map across frameworks,' and adding ISO 27001 to an existing SOC 2 program 'starts about two-thirds done' - implying SOC 2 is the base control set with other frameworks crosswalk-mapped from it, not independently confirmed per-framework. Source
Source-checked frameworks

11 frameworks checked individually, and how well each is established.

A framework on a marketing page is a vendor claim, not a confirmed capability. We grade the difference rather than repeating the list.

FrameworkEvidenceNote
SOC 2 Vendor-claimed Primary framework in all vendor and press material; independently corroborated by Help Net Security (Apr 2026). Source
ISO 27001 Vendor-claimed Source
HIPAA Vendor-claimed Source
GDPR Vendor-claimed A G2 reviewer noted a wish for stronger GDPR-specific support, see openQuestions. Source
PCI DSS Vendor-claimed Listed under "Frameworks we quote" on the pricing page. Source
SOC 1 Vendor-claimed Source
FedRAMP Vendor-claimed Also referenced on the homepage as available for enterprise-stage customers. Source
ISO 42001 Vendor-claimed Source
ISO 9001 Vendor-claimed Listed under frameworks Comp AI quotes; this establishes vendor-claimed availability, not certification or independently validated control depth. Source
CCPA Vendor-claimed Listed under frameworks Comp AI quotes. Source
NEN 7510 Vendor-claimed Listed under frameworks Comp AI quotes. The same page says only 'NIST' without naming CSF, 800-53, or 800-171, so no specific NIST framework is recorded. Source
Pricing

Comp AI uses quote-based pricing.

Getting a direct number requires a sales conversation. Anything below comes from reported quotes or marketplace listings, and is labeled as such.

Disclosure model
Quote-based
Sourced annual price
None found
Basis
Estimate, 2026-08-11

Software pricing alone does not establish the audit fee. A licensed CPA firm issues the SOC 2 report. A commercial offer may package coordination or the fee, so get the legal provider, deliverable, and amount in writing. See the SOC 2 audit cost guide for scope and budget context.

Read the Comp AI pricing guide for the current source table and quote checklist.

Auditor handoff

Who actually issues the report.

Comp AI does not issue the SOC 2 report. Its FAQ says customers may bring any accredited auditor, while current API docs document a built-in auditor role, auditor-only bulk evidence export, and finding/revision workflows. Comp AI also markets access to pre-vetted auditors, but no specific audit firm is named in the current product or pricing materials; confirm the legal CPA firm and fee in the quote.

Software prepares you for the audit; a licensed CPA firm performs it and issues the report. If you have not picked a firm yet, we list independent SOC 2 auditors separately, and we are not one of them.

Fit

Who Comp AI is for, and who it is not.

Good fit

An engineering-led company that values an inspectable, self-hostable compliance platform and wants one vendor scope that can include guided implementation, a trust center, penetration testing, and audit coordination when quoted.

Poor fit

A buyer who needs a published rate card before speaking with sales, requires confirmed SCIM-based provisioning, or expects every managed-cloud enterprise control to follow automatically from the public open-core codebase.

Typical buyer: Engineering-led startups and growing software companies pursuing SOC 2 or adjacent frameworks, especially teams that value inspectable evidence-collection code or want the option to self-host.

Related profiles

Compare Comp AI with three alternatives.

  • The team can own audit preparation internally and prioritizes broad connector coverage.

  • A founder or CTO needs a dedicated consultant alongside the software for a first audit.

  • Continuous monitoring and a mature managed evidence workflow matter.

Source ledger

Where every figure on this page came from.

11 sources, each with what it establishes and when we read it. If a claim here is out of date, this is the list that tells you which one to re-check.

  • Product positioning, 580+ integrations and 1,000+ companies claims, core feature list, daily cloud scans, guided Slack support, and FAQ statements that Comp AI is auditor-agnostic and does not issue the report. Vendor site · vendor-doc · 2026-08-11 · https://www.trycomp.ai/
  • Current pricing is quote-only with no public rate card; price varies by framework, headcount, timeline, and included audit, penetration-test, and trust-center scope; frameworks quoted include ISO 42001, ISO 9001, CCPA, and NEN 7510. Vendor site · vendor-doc · 2026-08-11 · https://www.trycomp.ai/pricing
  • RBAC / role-based permissions, encryption, multi-tenant isolation claims. Vendor site · vendor-doc · 2026-08-11 · https://www.trycomp.ai/security
  • Documentation index and API references for automated evidence, device compliance, questionnaires, penetration tests, Trust Access, cloud checks, custom roles, an auditor role, auditor-only evidence export, and audit-finding workflows. Vendor docs (Mintlify) · vendor-doc · 2026-08-11 · https://www.trycomp.ai/docs/llms.txt
  • Open-core license split (repository states 99% AGPLv3 and 1% commercial enterprise edition), self-hosting instructions, 1.9k stars, 376 forks, and 10 watchers as of retrieval date. GitHub · vendor-doc · 2026-08-11 · https://github.com/trycompai/comp
  • Independent description of the open-core license split, Device Agent behavior (hourly checks, supported OS versions, no PII collected), Security Questionnaire and API existence, cloud integrations (AWS/GCP/Azure). Help Net Security · press · 2026-08-11 · https://www.helpnetsecurity.com/2026/04/07/comp-ai-open-source-compliance-platform/
  • Company announcement dated July 28, 2025: $2.6M pre-seed co-led by OSS Capital and Grand Ventures with participation from David Cramer and Ben Tossell; founders named as Mariano Fuentes, Lewis Carhart, and Claudio Fuentes. Comp AI · vendor-doc · 2026-08-11 · https://www.trycomp.ai/hub/comp-ai-pre-seed-round
  • Standard terms identify Bubba AI, Inc. d/b/a Comp AI, require a minimum 12-month commitment, and auto-renew subscriptions for successive one-year periods unless either party gives at least 30 days' written notice. Comp AI · vendor-doc · 2026-08-11 · https://www.trycomp.ai/legal/terms-of-service
  • 4.7-star rating from 68 reviews. G2 · review-platform · 2026-08-11 · https://www.g2.com/sellers/comp-ai
  • Reviewer-reported limitation: some automations fail randomly; desire for stronger GDPR support. G2 · review-platform · 2026-08-11 · https://www.g2.com/products/comp-ai/reviews
  • Company profile confirming product description and funding record exist in Crunchbase's database. Crunchbase · press · 2026-07-24 · https://www.crunchbase.com/organization/comp-ai

← All SOC 2 compliance software · Comp AI review · How we verify