{
  "slug": "comp-ai",
  "category": "compliance-automation",
  "name": "Comp AI",
  "description": "Open-source compliance automation platform that helps companies prepare for SOC 2, ISO 27001, HIPAA and GDPR audits by collecting evidence, managing policies and tracking controls. It is offered as a hosted service or can be self-hosted.",
  "website": "https://www.trycomp.ai",
  "source": "https://github.com/trycompai/comp",
  "license": "AGPL-3.0",
  "platforms": [
    "web"
  ],
  "jurisdiction": {
    "code": "US",
    "name": "United States",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": "provider"
  },
  "pick": true,
  "pick_reason": "Open-source compliance automation for SOC 2, ISO 27001, HIPAA and GDPR, with evidence collection, policies and control tracking. Most of the code is AGPL-3.0, and it can be self-hosted, so compliance data does not have to live with a closed vendor.",
  "disclosure": null,
  "grade": "F",
  "score": 38,
  "coverage": 100,
  "summary": "Comp AI scores 38 out of 100 (grade F) on the compliance automation criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets open source, no ads or data sales, independent audit and security headers. It does not meet no trackers or telemetry, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B+.",
  "url": "https://privacyratings.com/compliance-automation/comp-ai/",
  "markdown": "https://privacyratings.com/compliance-automation/comp-ai/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://github.com/trycompai/comp/blob/main/LICENSE",
      "note": "Open core. Most of the code is AGPL-3.0, but enterprise features in the ee directory need a commercial license."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": "https://www.trycomp.ai/legal/privacy-policy",
      "note": "The website uses Google Analytics, Google Ads and PostHog session recording."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://www.trycomp.ai/legal/privacy-policy",
      "note": "Paid service with no ads, and personal information is not sold, but Google Ads conversion tracking runs on the website."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://security.trycomp.ai",
      "note": "The trust center lists SOC 2 Type 2 and ISO 27001 compliance, but the reports are only available on request."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "no",
      "evidence": "https://www.trycomp.ai/legal/privacy-policy",
      "note": "No transparency report or government request policy is published. The privacy policy only says data may be disclosed in response to lawful requests by public authorities."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.trycomp.ai&hideResults=on",
      "note": "Grade A"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "partial",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.trycomp.ai",
      "note": "Grade B+ (80/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    }
  },
  "tests": {
    "ssllabs": "A",
    "observatory": "B+",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [
      {
        "name": "Google Tag Manager",
        "host": "inline code",
        "effect": "no"
      }
    ],
    "tested_at": "2026-10-01T07:07:14.657Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}