Stars
Forks
Watchers
Developer links
Comp AI
Comp AI turns the months-long slog of SOC 2, ISO 27001, HIPAA, and GDPR certification into a largely automated process by connecting to your existing infrastructure and continuously collecting the evidence auditors actually ask for. Point it at your AWS account, Google Cloud project, GitHub organization, or any of 580+ supported integrations, and autonomous agents pull configuration snapshots, access logs, encryption status, and policy compliance data on a recurring schedule so your compliance posture reflects reality rather than last quarter's manual export. The AI policy engine analyzes your tech stack, team structure, and risk tolerance to generate organization-specific policies for information security, access control, incident response, data retention, and vendor management; no two companies get the same boilerplate. An open-source device agent runs on employee machines checking disk encryption, firewall status, screen lock settings, password length, and antivirus presence around the clock, flagging failures the moment they occur instead of surfacing them during an audit. Built-in penetration testing agents scan your codebase and API endpoints for vulnerabilities like SQL injection and output audit-ready reports. The vendor risk management module scores third-party services and surfaces compliance gaps before they become findings. A public trust center lets prospects verify your compliance status directly, eliminating security questionnaire bottlenecks. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
Benefits
- Automated Evidence From 580+ Integrations
- Agents connect to AWS, Google Cloud, GitHub, Supabase, and hundreds more services to pull configuration snapshots, access logs, and compliance data automatically on a recurring schedule.
- AI-Generated, Organization-Specific Policies
- The policy engine analyzes your tech stack, team size, and risk profile to produce information security, access control, and incident response policies tailored to your business, not generic templates.
- 24/7 Endpoint Compliance Monitoring
- An open-source device agent checks disk encryption, firewall status, screen lock, password strength, and antivirus on every employee machine continuously, flagging failures instantly.
- Multi-Framework Progress Tracking
- Track SOC 2 Type I/II, ISO 27001, HIPAA, GDPR, and FedRAMP progress simultaneously from a single dashboard with percentage completion, upcoming audit dates, and risk distribution views.
Features
- Evidence Collection
- Pulls configurations, logs, and screenshots from 580+ integrations on a recurring schedule with support for manual uploads, API pulls, and webhook listeners.
- Penetration Testing
- AI agents scan your codebase and API endpoints for vulnerabilities like SQL injection and cross-site scripting, producing audit-ready findings reports.
- Vendor Risk Management
- Scores third-party vendor compliance with progress bars, flags risky integrations, and surfaces gaps before they become audit findings.
- Cloud Infrastructure Monitoring
- Daily scans verify S3 bucket encryption, IAM policy configuration, VPC flow logs, RDS backups, and other cloud security controls across AWS and GCP.
- Public Trust Center
- Publish a live, branded trust page that lets prospects verify your compliance status, certifications, and security posture without back-and-forth questionnaires.