Compri logo
Operations Supply · Workflow Automation

Compri

Compri is an Italian SaaS that puts teams of AI agents inside industrial procurement: they read spend, route purchase requests, run RFQs, chase suppliers, check order confirmations and keep supplier compliance documents audit-ready, alongside your existing ERP.

Active GDPR compliant Contact Sales API available Verified by Guidaio
Overview

What is Compri?

Compri is a procurement and supply chain platform built around teams of AI agents rather than around screens. The company describes more than thirty agents organised into five teams, each owning one stage of the buying loop: an Intelligence Backbone that reads spend, contracts and supplier data; Intake Orchestration, which captures purchase requests from any channel and routes them; Smart Sourcing, which suggests suppliers, sends RFQs and compares offers; a Compliance Co-Pilot that onboards suppliers, scores their risk and keeps certifications audit-ready; and Supply Chain Automation, which issues purchase orders, chases suppliers, checks order confirmations and updates the ERP. A shared intelligence layer sits underneath all five.

Functionally, the platform starts with a base Visibility Package that switches on once data integration is complete: procurement analytics with exports, price intelligence against market indices, supplier master data with deduplication, vendor rating on punctuality and non-conformities, a conversational procurement assistant and a document repository with advanced multi-page OCR. Seven further modules can be added on top - order management, RFQ and tender management, intake and purchase requests, onboarding and compliance, insights, contract analysis and supplier scouting.

Compri is explicit that it does not replace the ERP: it connects to SAP, Oracle, Dynamics 365 or NetSuite, to Outlook and Gmail, to SharePoint and Google Sheets, and to external data sources such as Dun & Bradstreet, EcoVadis, Achilles, S&P and LME. Agents work inside approval thresholds the customer defines; anything beyond them escalates to a human buyer, every decision is logged and replayable, and no change is written back to the ERP without explicit acceptance.

The vendor claims up to 10% annual savings on total spend, 80% of routine tasks automated and 100% of compliance documents collected and vetted. Compri S.r.l. is based in Milan, was founded in 2024, employs more than thirty people and reports forty customers and over €10 billion of managed spend across Italy, Europe, the United States and South America.

What it does

  • Reads spend, contracts and supplier data to surface savings, anomalies and risks before they hit the P&L
  • Reads supplier order confirmations in PDF, Excel or free text, extracts dates, quantities and prices and flags any deviation
  • Sends purchase orders, chases suppliers and writes approved changes back into the ERP after human validation
  • Suggests suppliers, sends RFQs, chases replies and compares the offers received
  • Captures purchase requests from any channel, classifies them and routes them to the right buyer with full context
  • Onboards suppliers, scores their risk and tracks certification and contract expiry dates
  • Answers procurement questions in natural language and builds interactive charts from the underlying data
Audience

When to use Compri / When not to

A quick filter to help you decide if Compri is the right fit.

When to use Compri

  • Procurement and purchasing managers at manufacturing companies still running sourcing on spreadsheets and email
  • Category managers and strategic sourcing leads who want price trends, market benchmarks and supplier scoring in one place
  • Supply chain teams losing their days to order-confirmation chasing and delivery follow-ups
  • Compliance and third-party risk officers tracking supplier certifications, document expiry and onboarding files
  • Finance and operations leaders who need spend visibility and savings opportunities on top of an ERP they are not replacing

When not to use Compri

  • Buyers looking for a self-service tool: there is no sign-up, no free plan and no published price, only a demo request
  • Companies without an ERP or a structured data source to connect, since the base package only switches on once data integration is finished
  • Teams that need a mobile app or a browser extension, neither of which exists
  • Users who need the interface and the contractual documentation in a language other than English or Italian
  • Procurement functions outside industry and manufacturing, which is the only market the product addresses
Get started

How to use Compri

A typical end-to-end flow, from setup to results.

  1. Request a demo through the form on the site, which is the only entry point: there is no self-service sign-up
  2. Agree the scope commercially, choosing the base Visibility Package and any additional modules, under a Commercial Agreement
  3. Sign the published Data Processing Agreement and, where relevant, the Data Act switching addendum
  4. Connect the ERP and the other data sources so that the base visibility package can be activated automatically
  5. Set up authentication: SSO with your own identity provider is the recommended route, otherwise magic-link sign-in
  6. Use the sandbox environment to test before the production environment goes live
  7. Configure approval thresholds so agents know what they may do alone and what must escalate to a buyer
  8. Configure follow-up rules by order type, supplier and criticality, and co-design the order-confirmation compliance rules
  9. Let the agent teams run: they chase suppliers, read confirmations and prepare changes for your buyers to accept, reject or counter
  10. Query the assistant in natural language for spend, supplier and price questions, and export analyses to Excel, CSV or PDF
Quick read

Pros & Cons

Pros

  • Unusually complete public contractual documentation: full DPA with a named subprocessor list, Data Act addendum, technical annex with figures and a module-by-module functional specification
  • Precise, verifiable hosting: AWS eu-west-1 in Dublin, Ireland, backups replicated to another EU region and thirty days' notice before any change of location
  • Explicit commitment that customer data is not used to train AI models
  • Concrete service levels: 99.9% uptime in business hours, a one-month fee credit below 99.5% quarterly, four-hour RTO, twenty-four-hour RPO and AES-256 encryption at rest
  • Human validation is mandatory before anything is written back to the ERP, with configurable approval thresholds and replayable decision logs
  • Reversibility is organised in writing through the Data Act addendum: two-month notice and thirty days to retrieve exportable data
  • Named, quantified customer stories, including roughly €360,000 saved and more than 2,000 hours freed per year at one industrial customer

Cons

  • No public pricing at all: the pricing page does not exist and every commercial conversation starts with a demo
  • No terms and conditions are published; the Commercial Agreement itself is not accessible, only its annexes
  • The site contradicts itself on ISO 27001, which the compliance page calls certified by an accredited third-party auditor while the dedicated page says the standard is being implemented, with no certificate number given
  • The two downloadable ISO 27001 policies are only available in Italian, and the EU AI Act applicability statement announced as available is not linked to any document
  • No public API documentation, although the technical annex reserves the right to limit API access
  • No support email is published: the only visible channel is the demo form
  • The Italian version of the privacy policy points to an address on a domain that belongs to an unrelated company, which is a plain typo but sits in a legal document
Pricing

Pricing & Plans

Compri does not publish a price. No permanent free plan and no free trial are announced, and there is no pricing page: the expected address returns a genuine 404 and the sitemap lists no commercial page. Annex B of the SaaS technical documentation states that the licence fee is payable annually for the duration of the Commercial Agreement and that the implementation cost is a one-time payment, but gives no amount for either. Commercial terms are therefore set case by case after a demo, and no starting price, currency or billing unit could be recorded. Two euro figures visible on the site should not be mistaken for prices: the €2k tile on the homepage belongs to an animated demonstration dashboard, and the €3,754,238 and €58,738.18 shown on the Net Zero Lombardy page are a regional project budget and the public grant awarded to Compri within it.

Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Compri handles your data.

GDPR overview

GDPR implementation is documented in unusual detail for a company of this size. The privacy notice is drafted under Article 13 of Regulation (EU) 2016/679 and was last updated on 15 April 2026; it names Compri S.r.l. as controller at its Milan address, gives a legal basis for each purpose (Articles 6(1)(b), (c) and (f)), lists the access, rectification, erasure, restriction, objection and portability rights, and points complaints to the Italian Garante. A complete Article 28 Data Processing Agreement is published, with a named subprocessor list, a 48-hour breach notification, the Article 30(2) processing record and Standard Contractual Clauses under Article 46(2)(c) for any transfer outside the EEA. The compliance page declares GDPR, NIS 2 and EU AI Act compliance. No data protection officer is named; no Article 27 representative is designated, and none is required for a company established in Milan.

Who owns the data?

Under the Data Processing Agreement published in full on the site, Compri acts as a processor within the meaning of Article 28 GDPR and the customer stays the controller, so the data entered into the platform remains the customer's. Clause 13.1 guarantees, for the whole term of the agreement, that the customer can export or delete its data automatically or on request by email; Compri may keep backup copies without processing them. The Data Act addendum defines exportable data as the input and output data generated by the customer's use of the service, excluding assets covered by Compri's or a third party's intellectual property or trade secrets, and allows thirty calendar days to retrieve everything after a two-month switching notice.

Reuse rights

The customer instructs Compri to process the data only in order to deliver the SaaS and its technical support. One reservation is written into clause 3.2 of the agreement: Compri keeps the right to process the same data in anonymised and/or aggregated form for statistical purposes and to improve its services. Apart from that, the homepage states that nothing trains on customer data and that data does not leave the customer's ecosystem, and the site's llms.txt repeats that no customer data is used for AI model training. Personal data is never disseminated. Six subprocessors are named in Annex 3 of the agreement - Amazon Web Services, MongoDB, Microsoft, Anthropic, Google and Datadog - and the customer is informed at least fifteen days before a new one is added, with a right to object. Reusing the data outside the platform is a matter of export, which the customer can trigger itself at any time without asking permission.

Data retention & training

Retention summary
Retention is set purpose by purpose in the privacy notice: account and IT infrastructure data is kept for ten years from account deletion, infrastructure security data for ten years from collection, helpdesk records and statistical analysis for one year, and legal and dispute data for as long as the applicable limitation periods require. The technical annex is stricter on operational logs, which are retained for no more than ninety days, while daily backups are kept for twenty-one days on an alternate site. During the contract the customer can export or delete its data at any time, automatically or on request by email; deletion is carried out by irreversibly removing the database rows tied to the individuals concerned, and backup copies may survive without being processed. After a switch, thirty calendar days are allowed to retrieve exportable data.
Trains on customer data
No
Subprocessors disclosed
Yes
DPA available
Yes
GDPR contact

Hosting summary

All Compri data and infrastructure are hosted in the AWS eu-west-1 region in Dublin, Ireland, according to the SaaS technical annex, which also states that backups are replicated to a different AWS region inside the European Union and that at least thirty days' notice will be given before any change of data location. The homepage FAQ describes the same arrangement in broader terms: an EU-based AWS cloud, fully isolated per tenant, with no data crossing regional boundaries, and EU data residency for GDPR purposes. Transfers outside the European Economic Area remain possible through subprocessors and are covered by Standard Contractual Clauses under the data processing agreement. Data is encrypted at rest with AES-256, backed up daily to an alternate location with a maximum data loss of twenty-four hours, and a disaster recovery site is tested periodically. One caveat: the public website itself resolves to an anycast CDN address geolocated in the United States, which says nothing about where customer data actually lives.

Hosting countries
🇮🇪 Ireland
Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Compri.

  • The ISO 27001 claim is inconsistent across the site - certified on one page, being implemented on another - and no certificate number or certification body is published, so do not rely on it without asking for the certificate
  • NIS 2 and EU AI Act compliance are self-declared, with no third-party attestation and no downloadable applicability statement despite one being announced
  • The no-training promise sits next to a contractual clause letting Compri process the same data in anonymised or aggregated form to improve its services; read both together before assuming full exclusion
  • The platform relies on third-party models from Microsoft, Anthropic and Google, so part of the processing chain is outside Compri's own control, and the press release also mentions OpenAI, which the subprocessor list does not
  • Certifications displayed inside the product - supplier ISO 9001, EcoVadis or Achilles ratings - belong to your suppliers or to data providers, not to Compri
  • Delegating supplier chasing and confirmation checking to agents can erode the tacit knowledge buyers build through those same conversations; the approval thresholds are the only thing keeping a human in the loop, so set them deliberately
  • Account data is kept for ten years after account deletion while application logs are kept for ninety days: two very different horizons that are worth checking against your own retention policy
Setup

Setup & Integrations

Technical difficulty

Moderate, and mostly organisational rather than technical. The base package only activates once the ERP and other data sources are integrated, so the real effort is the data connection and the configuration that follows: approval thresholds, follow-up rules by order type, supplier and criticality, and co-designed order-confirmation compliance rules. Authentication is passwordless, with SSO against the customer's own identity provider recommended and magic-link sign-in as the fallback, and a sandbox environment is provided alongside production. The vendor claims a working pilot in days and an average go-live in a couple of weeks.

Deployment

Web appAPI

Integrations

SAP Oracle Dynamics 365 NetSuite Outlook Gmail Google Sheets SharePoint Dun & Bradstreet EcoVadis Achilles S&P LME Cribis

Supported languages

EnglishItalian
Company

Behind Compri

Company name
Compri S.r.l.
Founded
27/08/2024
Country of origin
🇮🇹 Italy
Headquarters
Via Luigi Porro Lambertenghi 7, 20159, Milan (MI), Italy
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States

Fundraising

June 2026 - €3.2 million seed round led by Picus Capital, with Shapers, Italian Founders Fund, DFF Ventures and private investors, bringing total funding to more than €5 million
March 2025 - €1.6 million pre-seed round co-led by Italian Founders Fund and DFF Ventures

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What does Compri actually do?
It runs teams of AI agents inside procurement and supply chain operations for manufacturers: they analyse spend, route purchase requests, run RFQs, onboard and score suppliers, chase order confirmations and update the ERP, working alongside the buyers rather than replacing the system of record.
Does Compri replace our ERP?
No. Compri connects to the ERP and to other data sources - SAP, Oracle, Dynamics 365, NetSuite, Outlook, Gmail, SharePoint, Google Sheets and external providers such as Dun & Bradstreet, EcoVadis, Achilles, S&P and LME - and adds an agent layer on top of it.
How much does it cost?
No price is published. The technical annex says the licence fee is paid annually for the duration of the commercial agreement, with a one-time implementation cost on top, but neither amount is given. Pricing is agreed after a demo, and no free plan or free trial is advertised.
Where is our data hosted?
In the AWS eu-west-1 region in Dublin, Ireland, with backups replicated to another AWS region inside the European Union. The vendor undertakes to give at least thirty days' notice before any change of data location, and states that tenants are isolated from one another.
Is our data used to train AI models?
The vendor states that nothing trains on customer data and that no customer data is used for AI model training. The data processing agreement does however reserve the right to process data in anonymised or aggregated form for statistics and service improvement.
Which subprocessors are involved?
Annex 3 of the published data processing agreement names six: Amazon Web Services for cloud hosting, MongoDB for the database, Microsoft for Azure generative AI, Anthropic for the Claude API, Google for the Gemini API and Datadog for observability and security.
What happens if an agent gets something wrong?
Agents operate inside approval thresholds set by the customer. Anything outside those thresholds is escalated to a human buyer before action is taken, every decision is logged and replayable, and no change reaches the ERP without an explicit acceptance from a buyer.
Is there an API?
No public API documentation exists on the site, and the robots file disallows the API path. The technical annex nevertheless reserves the right to limit API access in order to preserve uptime, which implies customers do get API access; ask the vendor for the details.
How long does it take to go live?
The homepage promises a working pilot in days and the June 2026 press release says go-live takes a couple of weeks on average, with the first measurable outcomes appearing within days of go-live. The base package activates automatically once data integration is complete.
How long is our data kept?
Account and infrastructure data is kept for ten years, helpdesk and statistical data for one year, connection and action logs for no more than ninety days and daily backups for twenty-one days. Export and deletion can be triggered at any time during the contract.
Conclusion

Should you pick Compri?

Compri is a deliberately narrow product: procurement and supply chain operations for industrial companies, sold as a workforce of agents rather than as another dashboard. That focus shows in the functional specification, which is far more concrete than most vendor marketing, and in the design choice that matters most for a buyer - agents prepare work, humans approve it, and nothing is written back into the ERP without an explicit acceptance.

The compliance file is the other genuine strength. A full data processing agreement with six named subprocessors, an EU Data Act switching addendum, an annex naming the exact AWS region in Dublin, quantified service levels and an explicit no-training commitment are more than a two-year-old company usually publishes. Anyone evaluating a European procurement tool will find most of the due-diligence answers already on the site.

Two reservations deserve weight. The first is complete pricing opacity: no plan, no amount, no trial, only an annual licence and a one-time implementation cost whose size you discover in a sales conversation. The second is that the security claims are self-declared and, on ISO 27001, internally inconsistent - the compliance hub says certified while the dedicated page says the standard is being implemented, and no certificate number is given. The EU AI Act applicability statement announced as available is not linked to any document either.

Weighed together, Compri looks like a credible fit for a manufacturer that already runs an ERP, wants to stop chasing order confirmations by hand and can absorb an enterprise buying cycle. It is not a fit for anyone who needs to try a tool before talking to a salesperson.