Best Software for 2025 is now live!
Save to My Lists
Paid
Claimed

Drata Reviews & Product Details - Page 2

Drata Overview

What is Drata?

Drata is a security and compliance automation platform that continuously monitors and collects evidence of a company's security controls, while streamlining compliance workflows end-to-end to ensure audit readiness. Drata helps thousands of companies streamline their compliance efforts through continuous, automated control monitoring and evidence collection, resulting in lower costs and time spent preparing for annual audits and better overall security posture. Drata's supported frameworks include: SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, CCPA, CCM, CMMC, ISO 27701, ISO 27017, ISO 27018, Cyber Essentials, Microsoft SSPA, NIST 800-53, NIST CSF, NIST AI, FFIEC, NIST 800-171, and Custom Frameworks. Drata is backed by ICONIQ Growth, GGV Capital, SVCI (Silicon Valley CISO Investments), Okta Ventures, Salesforce Ventures, Cowboy Ventures, Leaders Fund, SV Angel, and many key industry leaders.

Drata Details
Product Website
Discussions
Drata Community
Languages Supported
German, French, Spanish
Show LessShow More
Product Description

Drata is the world's most advanced security and compliance automation platform with the mission to help businesses earn and keep the trust of their users, customers, partners, and prospects. With Drata, thousands of companies streamline risk management and over 12 compliance frameworks—such as SOC 2, ISO 27001, GDPR, CCPA, PCI DSS and more—through automation, resulting in a strong security posture, lower costs, and less time spent preparing for audits.

How do you position yourself against your competitors?

Drata is a leading compliance and risk automation platform that continuously monitors and collects evidence of a company's security posture, while streamlining workflows.

Drata provides customers with real-time 24 hour in-app support and expertise from a team of compliance and technical support, to solution architects, and compliance experts.

We ensure ease and quality by partnering with GRC experts to build our product and feature enhancements from the ground up. The results? With Drata, you are collecting the right evidence the first time, no matter which framework you are pursuing. We save you time and money by doing it the first time.

Whether you are brand new and looking to achieve SOC 2 compliance or more advanced with your regulatory and risk needs, Drata is built to scale with you. We meet you where you are with your goals and support you through your entire journey.


Seller Details
Seller
Drata
Company Website
Year Founded
2020
HQ Location
San Diego, US
Twitter
@DrataHQ
1,232 Twitter followers
LinkedIn® Page
www.linkedin.com
639 employees on LinkedIn®
Description

Replace manual GRC efforts, reduce costs, and save time preparing for audits and maintaining compliance. Drata is the world’s most advanced security and compliance automation platform with the mission to help companies earn and keep the trust of their users, customers, partners, and prospects. We help thousands of companies streamline compliance for SOC
, ISO
7001, HIPAA, GDPR, your own custom frameworks, and many more through continuous, automated control monitoring and evidence collection. Drata is backed by ICONIQ Growth, Alkeon, Salesforce Ventures, GGV Capital, Okta Ventures, SVCI (Silicon Valley CISO Investments), Cowboy Ventures, Leaders Fund, Basis Set Ventures, SV Angel, and many key industry leaders. Drata is based in San Diego, CA with team members across the globe.


Adam M.
AM
Overview Provided by:
Co-Founder/CEO at Drata (We're hiring!)

Recent Drata Reviews

Lajah S.
LS
Lajah S.Small-Business (50 or fewer emp.)
5.0 out of 5
"Suuportive and cooperative team"
Althought the support team member, Pablo, worked on a different time zone he did his best to keep up with the issues I was facing and also assistin...
Verified User
A
Verified UserMid-Market (51-1000 emp.)
4.5 out of 5
"The new updates have been bit rickety but otherwise experience with Drata is good"
Ease of use is the best part about drata
Verified User
C
Verified UserSmall-Business (50 or fewer emp.)
5.0 out of 5
"100% Drata support satisfaction"
Ease of use, Ease of implementation, Customer Support, Ease of Integration
Security Badge
Drata Security
Get security information from Drata to help you buy the right software. View Security Information

Drata Media

Drata Demo - Drata's Automated Security Control Monitoring
Automated monitoring of your controls mapped to your framework
Drata Demo - Drata's SOC 2 Framework
Get audit ready with Drata's SOC 2 product. Drata gives you a single view of your security and compliance with 75+ deep integrations, automated monitoring and evidence collection, dashboards with real-time audit readiness, policy templates, compliance monitoring of your personnel, streamlined ven...
Drata Demo - Drata's Automated Security and Compliance Dashboard
With Drata's Dratameter and central dashboard, you will always know your overall control and requirement readiness.
Drata Demo - Drata's Open API
Drata’s Open API allows you to build and configure your security posture with flexible workflows, any integrations, and data exchanges. There is little to no code and the ability to connect to any solution—like security training solutions, background check providers, MDM systems, and more—to brin...
Drata Demo - Trust Center by Drata
Trust Center provides real-time transparency into your organization’s security posture. It seamlessly integrates with your website and allows you to publicly display security reports like vulnerability assessments and penetration test summaries, certifications and attestations like SOC 2, ISO 270...
Drata Demo - Risk Management
Drata's Risk Management is an integrated solution that helps you manage risk and compliance in one place.
Play Drata Video
Play Drata Video
Play Drata Video
Play Drata Video
Play Drata Video

Official Downloads

Answer a few questions to help the Drata community
Have you used Drata before?
Yes

967 Drata Reviews

4.8 out of 5
The next elements are filters and will change the displayed results once they are selected.
Search reviews
Popular Mentions
The next elements are radio elements and sort the displayed results by the item selected and will update the results displayed.
Hide FiltersMore Filters
The next elements are filters and will change the displayed results once they are selected.
The next elements are filters and will change the displayed results once they are selected.
967 Drata Reviews
4.8 out of 5
967 Drata Reviews
4.8 out of 5

Drata Pros and Cons

How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Cons

Overall Review Sentiment for DrataQuestion

Time to Implement
<1 day
>12 months
Return on Investment
<6 months
48+ months
Ease of Setup
0 (Difficult)
10 (Easy)
Log In
Want to see more insights from verified reviewers?
Log in to view review sentiment.
G2 reviews are authentic and verified.
PK
Consultant
Small-Business(50 or fewer emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Drata?

It pools all the users from cloud, pools evidences from all events, gives rating, and easily integrates everything, makes the life comfortable every step of the way. Its easy to implement any compliance if we have this tool.

Have been using for 2 days, its very intutive and easy to work with. gives all the required documents and criterias needed in less than a min. Gives lot of automtion and customisation with complete ease. Well developed tool to handle GRC, i would recomend everyone to use this and make your process faster and easier.

They have 24/5 customer support, who works like you buddies at work. supporting all the way in your accomplishments. Review collected by and hosted on G2.com.

What do you dislike about Drata?

Nothing much yet, in less than 2 days am able to handle everything very esily, its a great tool. will comeback and write if there is anything that i feel needs to be updated. Review collected by and hosted on G2.com.

What problems is Drata solving and how is that benefiting you?

getting complaint and an easy approch for the same. Review collected by and hosted on G2.com.

Federick F.
FF
Senior Security Engineer
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about Drata?

What makes Drata helpful is the overall consolidation and mapping of the security standards and technical requirements needed to achieve compliance. There are functionalities too that can automate tasks for compliance evaluation which makes it very helpful in analyzing the gaps as to what needs remediation. Review collected by and hosted on G2.com.

What do you dislike about Drata?

There are certain options that can be quite challenging to integrate and this needs to be head leveled in the documentation procedures. Review collected by and hosted on G2.com.

What problems is Drata solving and how is that benefiting you?

Evaluation and mapping of our current security posture which is needed for our ISMS certification. The ability to automate the evidence collection, control monitoring, and documentation for frameworks like SOC 2, ISO 27001, PCI DSS, HIPAA, and GDPR are hepful. Although there are no one-size fits all in security evaluation, the pre-built frameworks and controls are sufficient to come of with substantial evaluation for a security audit. Review collected by and hosted on G2.com.

Lola K.
LK
Cyber Security Engineer
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Organic
(Original )Information
What do you like best about Drata?

The feature I've enjoyed the most is having centralized and detailed visibility of all our personnel, assets and also being able to see what compliance requirements need our attention. Drata's customer service has been excellent, even being available to chat in real time late at night (EST time) and offering clear instructions.

Our representative Noah Barnett meets with us frequently to address any issues we might have, get feedback, and give us excellent support on our SOC 2 type 2 compliance process.

Using Drata as our security compliance platform was an excellent decision and has made the compliance process much more manageable. Highly recommend it! Review collected by and hosted on G2.com.

What do you dislike about Drata?

There isn't anything significant that I dislike about Drata (I'm the person in charge of using the platform). My latest request/feedback is that I would love it if they had the option for dark mode in their UI, and I am confident the feature will be made available soon! Review collected by and hosted on G2.com.

What problems is Drata solving and how is that benefiting you?

One crucial part for any compliance (and security) issues is having detailed and centralized visibility of all company assets and through all integrations available in Drata, we can have full control of what is necessary to achieve not only compliance, but also security best practices that benefit our company and our clients as well. Review collected by and hosted on G2.com.

Response from Ashley Hyman of Drata

Hi Lola!

So happy to hear you've had such a positive experience with Drata and my team. Customer experience is of utmost importance to us--from our real time support chat to your meetings with your CSM (Isn't Noah just the best?! :) ).

I know your request for dark mode has been heard and many on the team were excited about---keep your eye out for product updates. We'll keep you informed as it it prioritized!

Thank so much!

Ashley Hyman

VP of Customer Success

Jeremy M.
JM
Director of IT
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
(Original )Information
What do you like best about Drata?

There are real people there to help me along the way. Our company is going through SOC2 Type 2 comliance for the first time and learning a lot. Drata is there to help with every step of the process. The Patform is easy to use, implemented quickly, has good customer support, and easily integrates with other tools to simplify the process. Review collected by and hosted on G2.com.

What do you dislike about Drata?

I feel like there are parts of the platform which feel disconnected and confusing. We have to use the tool everyday. We are also missing some of the integrations to tools we use daily. Review collected by and hosted on G2.com.

What problems is Drata solving and how is that benefiting you?

They are solving the SOC2 Type2 puzzle for us providing a nice platform to use throughout the process. Review collected by and hosted on G2.com.

Neil W.
NW
CTO
Small-Business(50 or fewer emp.)
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about Drata?

They really streamlined and automated alot of the tasks that require SOC 2 compliance. They also send reminders and have due dates around tasks needing to be completed, so for smaller companies with limited resources, it really helps to make sure we are continually staying compliant. We continue to login and use the system monthly and their customer support is extremely responsive and helpful when it is necesary. Review collected by and hosted on G2.com.

What do you dislike about Drata?

The main thing I have trouble with in Drata is the expansive set of different frameworks they support and me wanting to align to all of them, but with a small team I can not stay on top of it all, but for larger companies this would be a benefit. Review collected by and hosted on G2.com.

What problems is Drata solving and how is that benefiting you?

Unknown requirements when first starting out and understanding what the compliance standards are along with gathering of evidence to satisfy the auditors. Review collected by and hosted on G2.com.

Verified User in Computer Software
AC
Small-Business(50 or fewer emp.)
Validated Reviewer
Verified Current User
Review source: Organic
(Original )Information
What do you like best about Drata?

I have been thoroughly impressed with Drata. The dashboard and modules provided are clear and concise which creates a clear learning experience and offers precise insights into our progress towards achieving security compliance. The customer service provided by Drata has exceeded my expectations. As someone who started the SOC2 compliance journey with very little knowledge of security protocols, I was lucky to have an outstanding Customer Success Manager guiding me through every step. Elizabeth John's expertise were evident in her explanation of each process during our meetings, allowing me to grasp concepts gradually. She has been instrumental in assisting me at every step. I cannot emphasize enough how invaluable her support has been. I recommend Drata to anyone looking for comprehensive security compliance solutions! Review collected by and hosted on G2.com.

What do you dislike about Drata?

I cannot express any negatives about my experience with Drata. Review collected by and hosted on G2.com.

What problems is Drata solving and how is that benefiting you?

As a startup operating in the cloud environment, ensuring security is extremely important to our success. Navigating security protocol standards can be confusing, especially for a cloud startup with very limited resources. Drata's platform offers clear guidance, streamlining the process of achieving SOC 2 compliance. As we scale our operations, maintaining visibility and control over our security posture becomes increasingly challenging. Drata's dashboard provides real-time overview into our security posture, identifying vulnerabilities and ensuring that we remain proactive in mitigating risks. Drata's Trust Center enable us to instill confidence in our customers and enhance our credibility. Drata has been an invaluable partner in our journey towards building a secure and compliant platform. Review collected by and hosted on G2.com.

Ben  B.
BB
Compliance and Information Security Manager
Small-Business(50 or fewer emp.)
Validated Reviewer
Review source: Seller invite
Incentivized Review
(Original )Information
What do you like best about Drata?

Drata provides a clear dashboard view of the frameworks we work towards, clear connections to controls, the capabilities of ownership and maintenance of out ISMS and risk management.

The supplier management section is also super helpful!

Implementation was easy and using the connections and integrations we were set up and running within two weeks.

The ability to be part of the roadmap and feedback to Drata using customer support really makes you feel part of a family.

When I log on to our system, Drata is one of the first applications I open and it stays with me all day. Review collected by and hosted on G2.com.

What do you dislike about Drata?

The downside of Drata for me personally, is that it is that efficient, the moment any part of ISMS falls out of review I see the percentage score drop and this messes with my OCD! Review collected by and hosted on G2.com.

What problems is Drata solving and how is that benefiting you?

Single source of truth for our ISMS - this means all evidence is streamlined into one excellent platform.

This is making meetings easier and managment of our ISMS and risk mangagement much more time-efficient. Review collected by and hosted on G2.com.

Guangyu L.
GL
Chief Operating Officer
Small-Business(50 or fewer emp.)
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about Drata?

I would say the structure of the platform is excellent, providing clear guidance for a company to manage its security issues comprehensively. Initially, we were not familiar with the security area, especially regarding how to periodically address security issues under the SOC2 and GDPR frameworks. Our customer success manager, Elizabeth John, is very nice and gentle. She has provided me with a wealth of instructions patiently and efficiently. I would recommend Drata to anyone needing to address security regulations. Review collected by and hosted on G2.com.

What do you dislike about Drata?

Drata is well-suited for those who really need to meet security regulations. Startups should carefully evaluate whether they have sufficient resources to commit, as once you begin implementing security regulations, it's not easy to stop and you should also expect a long-term commitment. Therefore, if you have a significant number of customers requiring this, it's advisable to proceed. Otherwise, carefully consider your starting point. Review collected by and hosted on G2.com.

What problems is Drata solving and how is that benefiting you?

Drata helps us meet the regulations of SOC2 and GDPR. Review collected by and hosted on G2.com.

CT
Cyber Security Analyst
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about Drata?

Drata really helped us prepare for our SOC 2 audit, providing a starting framework to work from, continuous monitoring of various controls through integrations, and personal assistance from our customer success manager, Elizabeth. We've since decided to attempt to centralize our compliance processes and efforts within Drata, as the platform is naturally suited to this task. Review collected by and hosted on G2.com.

What do you dislike about Drata?

Drata is still growing and changing regularly, so expect changes to your process and the occasional idiosyncracy/bug. Review collected by and hosted on G2.com.

What problems is Drata solving and how is that benefiting you?

Drata allows us to continuously monitor the functionality of our controls, as well as the status of evidence and policy tied to those controls. This has allowed us to prepare for and successfully complete our SOC 2 audits within a relatively short period of time. Review collected by and hosted on G2.com.

Robert B.
RB
Cloud Operations and Compliance Consultant
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Drata?

Drata enables "continuous compliance." This has shown itself to be very helpful in practice. When working on SOC2 at prior companies we would often find issues and gaps during the Audit or as we generated populations for the audit. Drata's constant checks for compliance allows us to show auditors a track record of continual work on our compliance journey and allows us to find and fix gaps and deviations without being already in the room in front of an auditor.

I also have had great experience with their customer support and their AI chatbot. The chatbot is able to understand our internal policies and procedures and generate adhoc answers to audit questions that pull from our actual policies. Customer support has also been able to go the extra mile to diagnose indepth issues with how their platform was interpreting our cloud setup and provide pointers on how to adjust our Azure settings to make them more secure. Review collected by and hosted on G2.com.

What do you dislike about Drata?

Drata sometimes can feel like a game of "whack-a-mole." The graphs show a track record overtime per control and as a company grows it will get harder and harder to show "constant" compliance. Invariably some user is always going to be late on their training or an engineer will create an improper resource in the cloud and cause a permanant blemish on the record over time. I'm not sure how to make it work but being able to show constant forward progress would be more advantatageous versus showing all the red marks where we failed for a day. Review collected by and hosted on G2.com.

What problems is Drata solving and how is that benefiting you?

Drata gives us a single pane of glass view of our security posture across all the tooling that we use accross the enterprise. Without Drata it would be impossible to go through the dozen pieces of our environment and ensure that our teams are following the policies and procedures that the company requires. Drata removes the embarrassment of having to find those defecits with the auditors in the room. Review collected by and hosted on G2.com.