AI COMPLIANCE COMPARE

Dispatch · openness · 2026-09-18

Open source in compliance software: what a public codebase gives a buyer

By the Signal Desk, AI Compliance Compare · Published · Updated 2026-09-29 · 3 min read

Short answer

A public codebase lets a buyer see how evidence is collected and how integrations work, and lowers the risk of being locked in. It does not replace the audit, the auditor or the vendor's own security posture. In our line-up only Comp AI publishes its code, which is why it leads our openness criterion.

What does Comp AI publish?

Comp AI's homepage links to its open-source codebase on GitHub (github.com/trycompai/comp). The same homepage states 580+ integrations and 1,000+ companies, and it leads with SOC 2, ISO 27001, HIPAA and GDPR. TechCrunch reported Comp AI's $34M Series A on 2026-09-17. None of the other five vendors here publishes its product code on the pages we reviewed.

What can a buyer do with open code?

Three things. First, inspect how an integration collects evidence: which API calls it makes, which fields it stores, how often it runs. That is useful for a security team that has to approve the tool's access to production systems. Second, check how a control test decides pass or fail, which helps when an auditor asks how a result was produced. Third, reduce lock-in: if the vendor relationship ends, the logic of your controls is not trapped in a closed product.

What does open code not give you?

An audit. The report or certificate still comes from a CPA firm or a certification body. Open code also does not tell you how the hosted service is run, who has access to your data or how quickly issues are fixed; those are questions for the vendor's own security documentation and trust center. And most teams will not read the code themselves. The value is that someone can.

How do we score openness?

Openness carries 8% of the weight in our ranking. Comp AI scores 9.5 for publishing its codebase. The other five score 3.0, our default for closed products; we would score higher for published APIs or documented agent actions, but none earned that on the pages we reviewed. The criterion is one reason Comp AI ranks where it does despite a lower score on audit path clarity.

Who should weight openness higher?

Engineering-led companies that want to audit the tool that audits them, teams in regulated sectors that must justify every production integration, and buyers worried about switching costs. In the stack builder, the 'Open and self-run' preset raises openness, integrations and pricing transparency and lowers human expert involvement; try it to see how the order changes.

What should you ask a vendor with open code?

Ask which parts of the product are in the public repository and which are not, for example hosted services, AI features or integrations. Ask how releases in the repository relate to what runs in the hosted service, and whether customers can run their own instance. Ask how security issues in the code are reported and fixed, and whether the vendor holds its own SOC 2 report or ISO 27001 certificate for the hosted service. Ask what the licence allows: reading and auditing the code is different from modifying and redistributing it. And ask what support you get if you choose to self-host, since the Slack support Comp AI describes may be tied to the hosted product. Open code is a strong signal of transparency; these questions turn it into terms you can rely on in a contract.

Keep reading

More from Dispatch