# trycompai/comp

AI Native platform to get companies compliant - Vanta & Drata Alternative

Repository: https://github.com/trycompai/comp
Canonical: https://ross.abutalabs.com/products/comp
Homepage: https://trycomp.ai
Language: TypeScript
License: AGPL-3.0
License Family: copyleft
Topics: ai, audit, authjs, compliance, drata, gdpr, iso27001, nextjs, open, open-source, prisma, security, soc2, t3-stack, tailwindcss, turborepo, vanta, zod
Last push: 2026-08-09T20:14:07+00:00

## Health v2 (maintenance only)
Score: 81/100 (v2, computed 2026-09-03T02:39:23.370411+00:00)
- activity 96, release rhythm 84, longevity 42
- inputs: {"age_days": 595, "days_push": 24, "days_rel": 28, "gap_med": 0, "n_releases_24m": 424}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1896, forks 394 (observed 2026-08-28T04:05:51.001243+00:00)

## What it is
Comp AI is an open-source, AI-native compliance platform that automates evidence collection, policy generation, and continuous monitoring for frameworks like SOC 2, ISO 27001, HIPAA, and GDPR. It is positioned as an open-source alternative to Vanta and Drata, with 580+ integrations, cloud posture tests, security questionnaires, and a public API plus MCP server.

## Use cases
- get my company SOC 2 compliant
- automate compliance evidence collection
- open-source alternative to Vanta or Drata
- generate security policies with AI
- answer security questionnaires automatically
- monitor cloud security posture across AWS, Azure, and GCP
- host a public trust center for prospects

## When to choose
- you want an auditable, open-source compliance platform with no vendor lock-in
- you need to get audit-ready for SOC 2, ISO 27001, HIPAA, or GDPR quickly
- you want automated evidence collection from many integrations in one place
- you want to drive compliance workflows via API or AI assistants through MCP

## When to avoid
- you need a fully managed commercial audit service with guaranteed auditor relationships
- you cannot self-host or operate a Next.js/Prisma-based platform
- your compliance needs are limited to frameworks Comp AI does not support
- you require FedRAMP-grade accreditation out of the box

## Facets
- artifact type: application
- maturity: active
- function: security, workflow-automation, monitoring, api-framework, mcp
- domain: security, legal, self-hosted, developer-tools
- platform: self-hosted
- tags: soc2, iso27001, gdpr, hipaa, compliance-automation, trust-center, evidence-collection, vanta-alternative, drata-alternative, nextjs, t3-stack, agpl, automation, web-server, docker, nodejs, typescript

## Member repositories
- trycompai/comp (main) score 81

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:51.001243+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:12:50.543789+00:00, confidence not recorded.
  - readme: https://github.com/trycompai/comp (fetched 2026-08-28T04:05:51.001243+00:00, sha a1d034f7ec3a)
  - homepage: https://trycomp.ai (fetched 2026-08-29T10:52:03.829067+00:00, sha fe6611cb8802)
  - site_page: https://www.trycomp.ai/docs (fetched 2026-08-29T10:52:03.834186+00:00, sha b724af59ac89)
  - site_page: https://www.trycomp.ai/pricing (fetched 2026-08-29T10:52:03.832182+00:00, sha d9ea74bfff32)
  - site_page: https://www.trycomp.ai/vanta-pricing (fetched 2026-08-29T10:52:03.835949+00:00, sha 5e1e112f9995)
  - site_page: https://www.trycomp.ai/drata-pricing (fetched 2026-08-29T10:52:03.837579+00:00, sha 31b1fda5011d)
  - site_page: https://www.trycomp.ai/secureframe-pricing (fetched 2026-08-29T10:52:03.839153+00:00, sha 5a3db3fa0d2a)
- Data as of 2026-08-30T08:39:29.467469+00:00.
