// the find
trycompai/comp
AI Native platform to get companies compliant - Vanta & Drata Alternative
Comp AI is an open-core platform for automating SOC 2, ISO 27001, HIPAA and GDPR compliance work (evidence collection, policy management, control tracking), pitched as an open-source alternative to Vanta/Drata. It's aimed at startups and small compliance/security teams who want to self-host rather than pay for a SaaS audit-prep tool.
It's a real multi-app monorepo (Next.js app + portal + a separate NestJS API) with background jobs via Trigger.dev, Prisma/Postgres, and Redis via Upstash, not a toy demo. The repo has genuine infrastructure around it: CI workflows for type-checking, migrations, SBOM generation, and even scripted security-review and RBAC-audit skills for AI coding agents, which suggests the team is actually dogfooding the compliance tooling on their own codebase. The AGPLv3 core with a clearly scoped commercial EE carve-out is an honest and fairly rare way to do open-core licensing.
Local setup is heavier than the README lets on: three separate .env files, a paid Trigger.dev cloud account, Google OAuth client, and Upstash Redis are all required just to run it, and the README's fallback advice for failed env vars is to hardcode secrets directly into auth.ts and the kv package source — a bad practice to suggest in a product whose whole pitch is security compliance. The Docker and Vercel deployment sections literally say 'coming soon,' so despite the self-hosting pitch there's no documented production deployment path. The README also has a stray unrendered HTML entity in a badge string, a small but telling sign of low doc polish for a 2k-star repo.