Comp AI says it reached $8 million in annual recurring revenue and more than 1,000 customers within 17 months. As of September 16, 2026, TrustMRR showed different numbers: $12,542 in monthly recurring revenue, 58 active Stripe subscriptions, and $704,052 collected over the previous 30 days.
The figures look incompatible until you consider the business model. Annual contracts, invoices, and services can create substantial collections without appearing as ordinary monthly subscriptions. One month of cash receipts can also resemble the monthly average implied by ARR without proving those receipts will recur.
Comp AI has not disclosed enough billing detail to reconcile the two views. The public record does show a company that found a fast route into a slow category. Its founders reframed compliance as a sales problem, demonstrated real progress during short sales calls, and used an existing founder audience to find its first customers.
That operating model helps explain how Comp AI could grow quickly. The gap between its headline ARR and Stripe subscription data explains what the company still needs to prove.
Comp AI Revenue at a Glance
The public figures measure different parts of the business. Founder-reported ARR describes claimed recurring contract value, while TrustMRR records activity from a connected Stripe account.
Six Public Numbers, Two Different Sources
The first two come from the founder. The other four come from the Stripe account Comp AI connected to TrustMRR.
Recorded figures as of September 16, 2026. TrustMRR reads a connected Stripe account; it does not audit financial statements or show how revenue is recognized. Not independently verified by WebTribunal.
Lewis Carhart stated in an X post that Comp AI had reached "$8M ARR with over 1,000 customers." TrustMRR confirms substantial payment activity, but it does not audit financial statements or show how it recognizes revenue.
Comp AI Started With a Problem Its Founders Already Knew
According to Grand Ventures, Carhart founded Comp AI with Claudio Fuentes and Mariano Fuentes after the three met while working at Leap AI, where they saw how much manual work security compliance created for growing software companies.
The category already had large vendors. Vanta, Drata, and Secureframe helped companies organize controls, collect evidence, and prepare for audits. Comp AI entered with a sharper pitch: compliance should help a company close deals.
That framing connected an administrative process to a problem founders already felt. A business-to-business software company can have a useful product and an interested enterprise buyer, then stall when procurement asks for a SOC 2 report, security evidence, or documented controls.
Comp AI was not selling a certificate. It was selling a shorter path through the security review blocking revenue.
The Sales Call Became Part of the Product
Comp AI's early sales process compressed onboarding, implementation, and closing into the same conversation.
In a launch retrospective, Carhart said the team opened the platform during a 20-minute demonstration and moved prospects roughly halfway through the compliance process before sending a Stripe payment link.
He reported that about 35% of demonstrations closed, one customer-success employee could support roughly 250 customers, and response times stayed below two minutes. These figures come from the founder rather than audited operating data, but they explain the claimed growth mechanism.
How Comp AI Says Its Early Growth Engine Worked
The path from audience to supported customer, as the founder has described it. An explanatory workflow, not measured performance.
*Founder-reported. The 20-minute demonstration and the figure of roughly 250 customers per customer-success employee come from Lewis Carhart's launch retrospective. Neither has been audited or independently verified by WebTribunal.
The demonstration did more than show screens. It performed part of the work the customer was being asked to buy.
Open Source Reduced the Trust Barrier
Compliance software asks customers to connect cloud systems, upload policies, and expose security evidence. That is a difficult request from a young vendor.
Comp AI used open source to lower some of that resistance. Technical buyers could inspect its architecture, integrations, and device agents through the public GitHub repository. Carhart said the open-source community also contributed to the company's early traction, particularly among founders who wanted to understand how the product was built.
Open source does not prove that software is secure. It gives sophisticated buyers more to evaluate than a sales presentation, which matters in a category built around trust.
The First Customers Came From the Founder's Audience
Carhart said Comp AI's first customers came from his network on X. He had been speaking with some of those founders for months or years before the product launched.
That audience created a distribution advantage. Founders building business software eventually encounter enterprise security requirements, so the people already following Carhart were unusually likely to encounter the problem Comp AI was solving.
Those existing relationships may also have shortened the trust-building period. A cold buyer had to evaluate a new compliance vendor from scratch, while some of Comp AI's earliest prospects had already known Carhart for months or years.
The raw revenue figures don't show this distribution advantage. Comp AI did not grow only because AI made compliance faster. It began with access to buyers at the moment compliance became commercially urgent.
Comp AI Reported $8M ARR Within 17 Months
The company's public milestones show a rapid progression. It launched on April 16, 2025, announced $2.6 million in pre-seed funding that July, and reported $5 million ARR at its first anniversary. Five months later, Carhart said ARR had reached $8 million, and the customer count had passed 1,000.
Two Disclosed ARR Figures, 17 Months From Launch
Annual recurring revenue at the two points the founder has disclosed, placed on a timeline from the public launch.
Comp AI has disclosed two ARR figures, both through founder posts. The hollow markers are the public launch and the pre-seed announcement, which carry no revenue figure. The dashed line is not a revenue curve: nothing between the points has been published. Not audited, and not independently verified by WebTribunal.
If the two founder-reported ARR figures are comparable, recurring contract value grew by about 60% between the company's first anniversary and its 17-month mark. More than 1,000 customers against $8 million ARR implies less than $8,000 in average annual recurring revenue per customer, assuming the two figures describe the same customer base. That average is consistent with a relatively broad customer base, although the public figures do not show how revenue is distributed between smaller customers and larger contracts.
The operating model was built for that volume. Carhart said one customer-success employee could support around 250 accounts, while the sales demonstration completed part of the customer's compliance work before payment. The growth story is therefore not just about demand for SOC 2. It is also about a standardized path from founder audience to live proof, payment, and automated support.
The $8M ARR Claim Doesn't Match Stripe at First Glance
Comp AI's public figures show substantial collections, but as with other fast-growing AI startups, different revenue snapshots do not always add up to a complete financial picture.
An $8 million annual run rate averages about $666,667 per month. TrustMRR's latest 30-day collections of $704,052 sit close to that figure, while cumulative Stripe collections exceed $5.3 million. Yet the same profile calculated only $12,542 in MRR from 58 active subscriptions.
One Month of Cash Matches the ARR Pace. Subscription MRR Does Not.
Three monthly figures for the same company, as of September 16, 2026.
Exact figures: $666,667 implied by the founder-reported ARR, $704,052 collected through Stripe in the previous 30 days, and $12,542 in MRR calculated by TrustMRR from 58 active subscriptions.
Collections are cash received in one month and may include annual prepayments, invoices, or one-time services. They do not show that the same amount will recur. Founder post and TrustMRR; not audited.
Several billing patterns could produce that result:
- Customers may pay annual contracts upfront.
- Larger accounts may pay invoices rather than monthly Stripe subscriptions.
- Audit support, penetration testing, or implementation may create separate charges.
- Some customers may use other billing arrangements.
These are plausible explanations, not confirmed facts. Comp AI has not published its contract mix, revenue-recognition policy, churn, gross margin, or software-versus-services split.
The most defensible conclusion is narrower than the headline. The Stripe account shows strong payment activity, and one recent month matched the cash pace implied by $8 million ARR. The public data cannot independently verify that the full amount is recurring software revenue.
A $34M Series A Followed the Revenue Growth
Comp AI raised a $2.6 million pre-seed round only months after its public launch. OSS Capital and Grand Ventures co-led the investment, with Sentry founder David Cramer and Ben Tossell also participating.
The funding announcement said more than 3,500 companies joined pre-launch testing and that early customers saved more than 2,500 hours of manual compliance work. Those usage figures came from Comp AI itself.
July 2025
Sep 17, 2026
funding
launch to Series A
The funding story changed substantially in September 2026. On September 17, Comp AI announced a $34 million Series A led by Roo Capital and Grand Ventures, taking its reported total funding to $37.5 million. The round came roughly 17 months after the company launched from stealth.
The new capital also points to a broader ambition. Comp AI is expanding beyond preparing companies for compliance audits toward continuous security monitoring and control validation. That makes the next stage of the company less about proving it can automate compliance work and more about whether the same approach can extend into ongoing cybersecurity.
What Comp AI Does for Compliance Teams
Traditional compliance platforms organize controls, evidence, policies, and audit preparation. Comp AI claims its agents automate more of that work.
The current platform covers:
- Evidence collection across business and infrastructure systems.
- Policies adapted to a customer's processes and technology stack.
- Continuous monitoring for control failures and security risks.
- Vendor and risk-management workflows.
- Device, cloud, and penetration-testing capabilities.
- A live trust center for prospects and customers.
Comp AI says it supports more than 580 integrations. That is a company-reported product count, not proof of how effectively each integration works.
The broader product thesis is more important than the feature count. Comp AI is trying to move compliance software from a system that records work into one that performs enough of the work to shorten the path to an audit.
The Market Will Test Whether Speed Can Survive Scrutiny
Comp AI competes in a crowded field. Vanta, Drata, and Secureframe have established brands and large integration ecosystems. Sprinto, Thoropass, Scytale, Scrut, and Hyperproof overlap with parts of its product. Auditors and consultancies compete for the service work surrounding the software.
Comp AI differentiates itself through a combination of open-source software, agents that claim to complete work, founder-led distribution, and messaging tied directly to enterprise revenue.
That combination may be harder to replicate than any single feature. Incumbents can add agents, and open-source projects can add integrations. They cannot instantly reproduce the same founder audience or the sales process that turns a short demonstration into visible compliance progress.
Speed also creates the company's central risk. Compliance buyers need reliable evidence, support, and controls that survive independent scrutiny, particularly as cybersecurity risks facing businesses continue to make security controls a procurement concern. Automation can prepare documents, map controls, and surface missing work. It cannot guarantee that controls operate effectively or that an auditor will issue a favorable report.
Services complicate the picture further. Audit support, penetration testing, and implementation can increase contract value and help customers succeed. They can also require more people and carry different margins from self-service software.
Growth Is Only the First Test
Comp AI found an effective way to sell a slow process. It connected compliance to deals founders wanted to close, used an existing audience to reach those founders, and turned the sales call into a working session.
That system helps explain its growth speed. It also explains why the company cannot be judged through a single Stripe metric.
If annual contracts account for the gap, TrustMRR may understate recurring contract value. If services or one-time work account for more of the collections, the headline ARR may overstate software-like economics. Both could be true at the same time.
The next proof point is not another revenue milestone. It is whether customers renew, the controls withstand audits, and the business preserves strong margins as support obligations grow.
Comp AI has shown that speed can win customers in a category known for friction. Now it has to show that the revenue, like the compliance work behind it, holds up under scrutiny.