OSS Tanbou

Comp AI — AI-assisted evidence, policy, and control management for compliance

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
1,976
Primary language
TypeScript
License
AGPL-3.0
Repository last updated
Sep 9, 2026

Overview

Comp AI is an open-source compliance platform for frameworks such as SOC 2, ISO 27001, HIPAA, and GDPR, combining evidence collection, policy management, control implementation, and AI-assisted workflows.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Manage evidence, policies, and controls in one compliance system

The platform aims to consolidate evidence collection, policy management, and control implementation rather than spreading them across separate tools.

Sources: [2][3]

Use AI to reduce manual compliance work

The project positions AI assistance as a way to accelerate repetitive compliance tasks and framework preparation.

Sources: [2][3]

For teams evaluating an open-source alternative to Vanta or Drata

It is relevant to organizations pursuing SOC 2 or ISO 27001 while wanting more control over application data and infrastructure.

Sources: [2]

Review external-service dependencies in local and production deployments

The documented local setup includes Node.js, Bun, Postgres, Trigger.dev, Google OAuth, and Upstash. Production self-hosting requirements should be verified separately.

Sources: [2][3]

Official sources

  1. [1]trycompai/comp repository(2026-09-20)
  2. [2]Comp AI README(2026-09-20)
  3. [3]Comp AI documentation(2026-09-20)
  4. [4]Comp AI AGPL-3.0 license(2026-09-20)
Supplemental curator note

Comp AI clearly targets compliance automation, but the local setup described in the README also involves services such as Postgres, Trigger.dev, Google OAuth, and Upstash. Distinguish running the code from operating a fully self-contained compliance environment.

Try it in 3 steps

  1. 1

    Get the source

    git clone --depth 1 https://github.com/trycompai/comp.git
  2. 2

    Enter the repository

    cd comp
  3. 3

    Check the official steps

    Continue with the commands in the README Installation, Quick Start, or Getting Started section.

    find . -maxdepth 1 -iname 'README*' -exec sed -n '1,220p' {} \; -quit
Check the official README

Growth

Growth trends · Last 30 days

1,976 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
0
Open PRs
21

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • ai
  • audit
  • authjs
  • compliance
  • drata
  • gdpr
  • iso27001
  • nextjs
  • open
  • open-source
  • prisma
  • security
Stars
1,976
Forks
417
Watchers
10
Open issues
16
Contributors
36
Primary language
TypeScript
License
AGPL-3.0
Repository last updated
Sep 9, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.