| |

We Backed Comp AI at Pre-Seed. 15 Months Later, We Doubled Down.

Getting back the quarter every software company traditionally loses becoming compliant

By: Nathan Owen

Every high-growth software company I’ve been part of or around eventually hits this: A big prospect’s security team sends over the questionnaire, the deal stalls, there is a crazed scramble, and suddenly somebody on the engineering team, usually one of the most senior people on the team, is spending the next quarter screenshotting AWS consoles, writing policies, and pasting evidence into spreadsheets. SOC 2, ISO 27001, HIPAA, GDPR, etc.

That all sounds fine except this: for high-growth startups, compliance isn’t really about checking a box. It’s about revenue. If you can’t get through a security review, you’re never going to close your first enterprise customer(s).

We backed Comp AI at pre-seed because Lewis Carhart, Claudio Fuentes, and Mariano Fuentes were building a better way to solve that problem. Fifteen months after our first check, we’re back in with a bigger one.

Grand Ventures co-led Comp AI’s $34 million Series A alongside Roo Capital, which brings total funding to $37.5 million. Since our first check, Comp AI has grown past 1,000 customers and increased ARR 15x year over year.

Those are strong numbers, but it’s not really why we doubled down. Over the last 15 months, we had the opportunity to watch Lewis, Claudio, and Mariano execute, saw the product work across our own portfolio, watched customers recommend it to one another, and became convinced the opportunity was expanding well beyond just compliance automation.

The founding team built what they said they would build

When we first met Lewis, Claudio, and Mariano, they weren’t theorizing about compliance. They had lived it. At Leap AI, they watched engineers burn months getting through SOC 2 and other frameworks by hand. Claudio put it plainly: “It’s a very obscure process. It took us a couple of months of doing things by hand.”

They did what great founders do and built the product they wished they’d had. When I visited their first New York office, the entire team could fit in one room. They were operating with the speed and output of a company many times their size, and that capital efficiency became another important signal for us. The pre-seed pitch was simple: an open-source compliance platform with AI at the core, not bolted onto a legacy workflow, and that’s what Comp AI launched shortly after we first invested.

Comp AI Founders: Mariano Fuentes, Lewis Carhart, and Claudio Fuentes in 2025 in the apartment they lived in / launched Comp AI from

Comp AI connects to a company’s infrastructure, figures out what’s running, maps it against the framework you need, drafts the policies, collects the evidence, and gets you ready for what an auditor will ask for. AI does most of the tedious work, but the product doesn’t pretend humans disappear. An agent drafts the policy, and a person still reviews and approves it. Auditors require that, and Comp AI’s platform provides exactly that.

We had an opportunity to watch it work inside our own portfolio

Several Grand Ventures portfolio companies have now used Comp AI to get audit-ready. A number of them had nobody on staff who had ever touched compliance. Founders and three-person engineering teams got through a work effort that used to eat the better part of a quarter, then used the certification to unblock enterprise deals. A number of them had previously started with some of the incumbent platforms like Vanta and Drata and six months were still stuck somewhere in the middle of the process.

We started seeing one of the strongest product signals you possibly see within a VC portfolio: our founders were recommending Comp AI to each other without us asking. When a group of founders who are already overloaded go out of their way to tell other founders, “you need to use this,” it catches your attention…

The open-source flywheel is real

Comp AI also fits a thesis we’ve been building at Grand for years around Commercial Open Source Software. We’ve seen versions of the model at Astronomer, Payload, Tembo, Traceloop, and now Comp AI.

Developers find a useful open-source project and try it without asking for procurement’s permission or sitting through a sales demo. It solves a real problem for them, and adoption spreads throughout the org from the bottom up. Later, when the org needs collaboration, governance, continuous monitoring, support, security, or enterprise features, the commercial platform becomes the natural step-up.

Compliance has become continuous

The compliance automation business was already a large market before Comp AI’s arrival. The bigger reason why we initially invested in Comp AI and then doubled down is where we think the GRC (Governance, Risk, and Compliance) goes next.

Traditionally, compliance was a point-in-time problem. You prepare for the audit, the auditor examines the environment, you show the controls exist, you get the report. Then the software changes. A new service gets deployed, a permission changes, someone connects another model, an AI agent gets access to a system it couldn’t touch yesterday, and the environment you audited is no longer quite the environment you’re running.

That world has worsened as dev has sped up and AI agents are now taking actions inside production. The logical next step is continuous compliance and security: validating controls in real time instead of proving once a year that they existed on audit day.

That’s the world Comp AI is building toward. It means continuous control validation, AI-driven penetration testing across applications and infrastructure, and tracking the permissions and accountability of the AI agents companies are deploying inside their own environments.

I’ve experienced this problem multiple times before I moved into venture. I spent a big chunk of my career in observability. Monitoring started as something you checked periodically. Then infrastructure got too dynamic for that; systems changed constantly, and monitoring had to become continuous. Eventually, continuous telemetry turned into infrastructure nobody could run without. Compliance looks to me like they’re at the start of the same shift. Software changes continuously, and AI agents act continuously, so controls have to be validated continuously too.

The companies built for the old world were designed to help organizations document compliance. Today’s opportunity is to build the layer that always knows whether an environment is secure and operating within policy. That’s a much larger opportunity than the one we originally underwrote at pre-seed.

Why Grand doubled down on Comp AI

At pre-seed, Grand believed AI could take most of the human effort out of becoming compliant. That’s working. The first 1000 customers (in less than 18 months) are proof of it.

What changed since our initial pre-seed check is how big we think Comp AI can become. The team has executed at an exceptionally rare pace, our portfolio companies are recommending the product to one another, open-source adoption is creating organic pull, and the market itself is moving from periodic compliance toward continuous security and trust. Easy to see how our conviction grew alongside the company. That’s why we doubled down.

With this round, Comp AI will keep expanding its core compliance capabilities and building for larger, more complex organizations.

Nathan Owen with founding team September 2026

To Lewis, Claudio, Mariano, and the whole Comp AI team: congratulations. We’re proud to be alongside you again.

Onward,

Nathan Owen

General Partner, Grand Ventures

P.S. If you’re building a commercial open-source company and trying to figure out whether your project can support a venture-scale business, I’d love to hear from you. We’ve walked this path with many teams now, and we’re still learning from each one.

Similar Posts