Logo Menu

Open-source SOC 2 / multi-framework compliance automation platform Β· verified

Comp AI

Comp AI runs an 'open core' model: Help Net Security (Apr 2026) reports roughly 99% of the codebase is open source under AGPLv3, with a small commercial-license slice covering enterprise features, and self-hosting remains free.

Its live pricing page (retrieved Jul 2026) has moved to a quote-only, book-a-call model with no published rate card, a change from the tiered self-serve pricing (around $199/mo cloud Starter, $997/mo Pro) that several third-party review sites reported earlier in 2026 - we flag this discrepancy rather than picking one figure. A G2 reviewer notes a genuine limitation: 'some of the automations fail randomly, and I wish there were stronger support for GDPR.'

Desk research against public sources. Every figure below carries its source and the date we retrieved it.

Capabilities

What Comp AI does.

Seven capabilities, graded the same way for every platform in the directory. "Not established" means we looked and could not confirm it, not that the feature is missing.

CapabilityStatusEvidence
Automated evidence collection Yes Independent write-up confirms an 'Automated Evidence' feature that builds recurring evidence-collection automations from a plain-language prompt. Source
Auditor workspace Not established Vendor FAQ (JSON-LD) says Comp AI is 'auditor-agnostic' and organizes evidence so 'any auditor can step in and verify,' but no dedicated scoped auditor login / evidence-request workspace feature is documented independently. Source
Trust center Yes Live public trust center exists and is linked from the vendor homepage; vendor claims only published policies and verified controls surface (unverified independently). Source
Security questionnaire answering Yes A Security Questionnaire feature appears in the product docs; Help Net Security confirms published policies feed answers automatically. Source
Enterprise admin (SSO, SCIM, RBAC) Partial Vendor security page confirms role-based permissions with custom roles (RBAC). No SSO or SCIM claim found anywhere in vendor docs, marketing, or press; treat as unconfirmed rather than absent. Source
SCIM 2.0 provisioning Not established The only claim of SCIM on an enterprise plan comes from an undated third-party post and could not be corroborated on Comp AI's own site, pricing page or docs. Not publishable as fact.
Continuous control testing Yes Device Agent runs hourly checks on four controls (disk encryption, AV, password policy, screen lock); homepage separately claims daily cloud-infrastructure scans. Source
Native multi-framework support Partial Pricing page states 'controls map across frameworks,' and adding ISO 27001 to an existing SOC 2 program 'starts about two-thirds done' - implying SOC 2 is the base control set with other frameworks crosswalk-mapped from it, not independently confirmed per-framework. Source
Frameworks

8 frameworks, and how well each is established.

A framework on a marketing page is a vendor claim, not a confirmed capability. We grade the difference rather than repeating the list.

FrameworkEvidenceNote
SOC 2 Vendor-claimed Primary framework in all vendor and press material; independently corroborated by Help Net Security (Apr 2026). Source
ISO 27001 Vendor-claimed Source
HIPAA Vendor-claimed Source
GDPR Vendor-claimed A G2 reviewer noted a wish for stronger GDPR-specific support, see openQuestions. Source
PCI DSS Vendor-claimed Listed under "Frameworks we quote" on the pricing page. Source
SOC 1 Vendor-claimed Source
FedRAMP Vendor-claimed Also referenced on the homepage as available for enterprise-stage customers. Source
ISO 42001 Vendor-claimed Source
Pricing

Comp AI does not publish a price.

Getting a number requires a sales conversation. Anything below comes from reported quotes or marketplace listings, and is labeled as such.

Disclosure model
Quote-based
Observed price
None found
Basis
Estimate, 2026-07-24

Auditor fees are separate from all of these. See the SOC 2 audit cost guide for what the audit itself runs.

Auditor handoff

Who actually issues the report.

Comp AI does not issue the SOC 2 report. Per the vendor's own published FAQ, the platform is 'auditor-agnostic' - customers work with any accredited CPA firm of their choosing, and Comp AI organizes evidence, controls, and policies so that auditor can conduct the audit and produce the report. No specific named audit-firm partner was found in vendor materials or press.

Software prepares you for the audit; a licensed CPA firm performs it and issues the report. If you have not picked a firm yet, we list independent SOC 2 auditors separately, and we are not one of them.

Fit

Who Comp AI is for, and who it is not.

Good fit

A software company comfortable evaluating an open-source (AGPLv3) platform that wants a single quoted price covering the platform, audit coordination, and penetration testing rather than assembling those pieces separately.

Poor fit

A buyer who needs a published self-serve rate card to budget without a sales call, or one that requires confirmed enterprise SSO/SCIM out of the box - Comp AI's current pricing page is quote-only and we could not confirm SSO/SCIM support anywhere in vendor documentation.

Typical buyer: Engineering-led startups (seed to Series A/B) pursuing a first SOC 2 program, especially teams that want to inspect or self-host the compliance codebase rather than trust a closed-source vendor..

Source ledger

Where every figure on this page came from.

10 sources, each with what it establishes and when we read it. If a claim here is out of date, this is the list that tells you which one to re-check.

  • Product positioning, 580+ integrations, 830+ companies claim, feature list, FAQ (auditor-agnostic / auditor issues the report), legal entity name (Bubba AI, Inc. d/b/a Comp AI). Vendor site Β· vendor-doc Β· 2026-07-24 Β· https://www.trycomp.ai/
  • Current pricing model is quote-only (no published rate card); list of frameworks quoted; controls-mapping-across-frameworks claim. Vendor site Β· vendor-doc Β· 2026-07-24 Β· https://www.trycomp.ai/pricing
  • RBAC / role-based permissions, encryption, multi-tenant isolation claims. Vendor site Β· vendor-doc Β· 2026-07-24 Β· https://www.trycomp.ai/security
  • Feature list: AI Policy Editor, Automated Evidence, Device Agent, Security Questionnaire, Penetration Tests, MCP Server, Trust Access, cloud tests (AWS/Azure/GCP). Vendor docs (Mintlify) Β· vendor-doc Β· 2026-07-24 Β· https://www.trycomp.ai/docs
  • AGPL-3.0 license, 1.7k stars, 347 forks, 9 watchers as of retrieval date; confirms the codebase is genuinely public. GitHub Β· vendor-doc Β· 2026-07-24 Β· https://github.com/trycompai/comp
  • Independent description of the open-core license split, Device Agent behavior (hourly checks, supported OS versions, no PII collected), Security Questionnaire and API existence, cloud integrations (AWS/GCP/Azure). Help Net Security Β· press Β· 2026-07-24 Β· https://www.helpnetsecurity.com/2026/04/07/comp-ai-open-source-compliance-platform/
  • $2.6M pre-seed round, August 2025, co-led by OSS Capital and Grand Ventures with angels David Cramer and Ben Tossell; legal entity Bubba AI, Inc.; founded 2025. The SaaS News Β· press Β· 2026-07-24 Β· https://www.thesaasnews.com/news/comp-ai-raises-2-6-million-in-pre-seed-round/
  • 4.7-star rating from 65 verified reviews. G2 Β· review-platform Β· 2026-07-24 Β· https://www.g2.com/sellers/comp-ai
  • Reviewer-reported limitation: some automations fail randomly; desire for stronger GDPR support. G2 Β· review-platform Β· 2026-07-24 Β· https://www.g2.com/products/comp-ai/reviews
  • Company profile confirming product description and funding record exist in Crunchbase's database. Crunchbase Β· press Β· 2026-07-24 Β· https://www.crunchbase.com/organization/comp-ai

← All SOC 2 compliance software Β· Comp AI review Β· How we verify

Some links to compliance platforms on this page are affiliate links: if you sign up through one, the vendor may pay us a commission at no cost to you. It never changes our ranking, our review, or which platform we recommend.

For Comp AI

2 facts on this page we could not establish.

Everything above renders with its evidence state, so a gap is visible rather than quietly filled in. If you work at Comp AI, send us the sources and we will fill them.

Verification is free and always will be. It does not change where Comp AI appears in any list on this site, what our reviews conclude, or which platform we recommend to a buyer. We only accept a correction that comes with a source we can check ourselves, and the source is published in the ledger above alongside the date.

Correct this record