Open-source SOC 2 / multi-framework compliance automation platform Β· verified
Comp AI
Comp AI runs an 'open core' model: Help Net Security (Apr 2026) reports roughly 99% of the codebase is open source under AGPLv3, with a small commercial-license slice covering enterprise features, and self-hosting remains free.
Its live pricing page (retrieved Jul 2026) has moved to a quote-only, book-a-call model with no published rate card, a change from the tiered self-serve pricing (around $199/mo cloud Starter, $997/mo Pro) that several third-party review sites reported earlier in 2026 - we flag this discrepancy rather than picking one figure. A G2 reviewer notes a genuine limitation: 'some of the automations fail randomly, and I wish there were stronger support for GDPR.'
Desk research against public sources. Every figure below carries its source and the date we retrieved it.
What Comp AI does.
Seven capabilities, graded the same way for every platform in the directory. "Not established" means we looked and could not confirm it, not that the feature is missing.
| Capability | Status | Evidence |
|---|---|---|
| Automated evidence collection | Yes | Independent write-up confirms an 'Automated Evidence' feature that builds recurring evidence-collection automations from a plain-language prompt. Source |
| Auditor workspace | Not established | Vendor FAQ (JSON-LD) says Comp AI is 'auditor-agnostic' and organizes evidence so 'any auditor can step in and verify,' but no dedicated scoped auditor login / evidence-request workspace feature is documented independently. Source |
| Trust center | Yes | Live public trust center exists and is linked from the vendor homepage; vendor claims only published policies and verified controls surface (unverified independently). Source |
| Security questionnaire answering | Yes | A Security Questionnaire feature appears in the product docs; Help Net Security confirms published policies feed answers automatically. Source |
| Enterprise admin (SSO, SCIM, RBAC) | Partial | Vendor security page confirms role-based permissions with custom roles (RBAC). No SSO or SCIM claim found anywhere in vendor docs, marketing, or press; treat as unconfirmed rather than absent. Source |
| SCIM 2.0 provisioning | Not established | The only claim of SCIM on an enterprise plan comes from an undated third-party post and could not be corroborated on Comp AI's own site, pricing page or docs. Not publishable as fact. |
| Continuous control testing | Yes | Device Agent runs hourly checks on four controls (disk encryption, AV, password policy, screen lock); homepage separately claims daily cloud-infrastructure scans. Source |
| Native multi-framework support | Partial | Pricing page states 'controls map across frameworks,' and adding ISO 27001 to an existing SOC 2 program 'starts about two-thirds done' - implying SOC 2 is the base control set with other frameworks crosswalk-mapped from it, not independently confirmed per-framework. Source |
8 frameworks, and how well each is established.
A framework on a marketing page is a vendor claim, not a confirmed capability. We grade the difference rather than repeating the list.
| Framework | Evidence | Note |
|---|---|---|
| SOC 2 | Vendor-claimed | Primary framework in all vendor and press material; independently corroborated by Help Net Security (Apr 2026). Source |
| ISO 27001 | Vendor-claimed | Source |
| HIPAA | Vendor-claimed | Source |
| GDPR | Vendor-claimed | A G2 reviewer noted a wish for stronger GDPR-specific support, see openQuestions. Source |
| PCI DSS | Vendor-claimed | Listed under "Frameworks we quote" on the pricing page. Source |
| SOC 1 | Vendor-claimed | Source |
| FedRAMP | Vendor-claimed | Also referenced on the homepage as available for enterprise-stage customers. Source |
| ISO 42001 | Vendor-claimed | Source |
Comp AI does not publish a price.
Getting a number requires a sales conversation. Anything below comes from reported quotes or marketplace listings, and is labeled as such.
- Disclosure model
- Quote-based
- Observed price
- None found
- Basis
- Estimate, 2026-07-24
Auditor fees are separate from all of these. See the SOC 2 audit cost guide for what the audit itself runs.
Who actually issues the report.
Comp AI does not issue the SOC 2 report. Per the vendor's own published FAQ, the platform is 'auditor-agnostic' - customers work with any accredited CPA firm of their choosing, and Comp AI organizes evidence, controls, and policies so that auditor can conduct the audit and produce the report. No specific named audit-firm partner was found in vendor materials or press.
Software prepares you for the audit; a licensed CPA firm performs it and issues the report. If you have not picked a firm yet, we list independent SOC 2 auditors separately, and we are not one of them.
Who Comp AI is for, and who it is not.
Good fit
A software company comfortable evaluating an open-source (AGPLv3) platform that wants a single quoted price covering the platform, audit coordination, and penetration testing rather than assembling those pieces separately.
Poor fit
A buyer who needs a published self-serve rate card to budget without a sales call, or one that requires confirmed enterprise SSO/SCIM out of the box - Comp AI's current pricing page is quote-only and we could not confirm SSO/SCIM support anywhere in vendor documentation.
Typical buyer: Engineering-led startups (seed to Series A/B) pursuing a first SOC 2 program, especially teams that want to inspect or self-host the compliance codebase rather than trust a closed-source vendor..
Where every figure on this page came from.
10 sources, each with what it establishes and when we read it. If a claim here is out of date, this is the list that tells you which one to re-check.
- Product positioning, 580+ integrations, 830+ companies claim, feature list, FAQ (auditor-agnostic / auditor issues the report), legal entity name (Bubba AI, Inc. d/b/a Comp AI). https://www.trycomp.ai/
- Current pricing model is quote-only (no published rate card); list of frameworks quoted; controls-mapping-across-frameworks claim. https://www.trycomp.ai/pricing
- RBAC / role-based permissions, encryption, multi-tenant isolation claims. https://www.trycomp.ai/security
- Feature list: AI Policy Editor, Automated Evidence, Device Agent, Security Questionnaire, Penetration Tests, MCP Server, Trust Access, cloud tests (AWS/Azure/GCP). https://www.trycomp.ai/docs
- AGPL-3.0 license, 1.7k stars, 347 forks, 9 watchers as of retrieval date; confirms the codebase is genuinely public. https://github.com/trycompai/comp
- Independent description of the open-core license split, Device Agent behavior (hourly checks, supported OS versions, no PII collected), Security Questionnaire and API existence, cloud integrations (AWS/GCP/Azure). https://www.helpnetsecurity.com/2026/04/07/comp-ai-open-source-compliance-platform/
- $2.6M pre-seed round, August 2025, co-led by OSS Capital and Grand Ventures with angels David Cramer and Ben Tossell; legal entity Bubba AI, Inc.; founded 2025. https://www.thesaasnews.com/news/comp-ai-raises-2-6-million-in-pre-seed-round/
- 4.7-star rating from 65 verified reviews. https://www.g2.com/sellers/comp-ai
- Reviewer-reported limitation: some automations fail randomly; desire for stronger GDPR support. https://www.g2.com/products/comp-ai/reviews
- Company profile confirming product description and funding record exist in Crunchbase's database. https://www.crunchbase.com/organization/comp-ai
β All SOC 2 compliance software Β· Comp AI review Β· How we verify
Some links to compliance platforms on this page are affiliate links: if you sign up through one, the vendor may pay us a commission at no cost to you. It never changes our ranking, our review, or which platform we recommend.
2 facts on this page we could not establish.
Everything above renders with its evidence state, so a gap is visible rather than quietly filled in. If you work at Comp AI, send us the sources and we will fill them.
Verification is free and always will be. It does not change where Comp AI appears in any list on this site, what our reviews conclude, or which platform we recommend to a buyer. We only accept a correction that comes with a source we can check ourselves, and the source is published in the ledger above alongside the date.