Drata is a trust management platform that supports compliance, governance, risk management and security assurance. It collects evidence automatically, monitors controls continuously and maps controls across frameworks such as SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS and DORA. It also offers a Trust Center for sharing security posture with prospects and customers, AI-assisted answers to security questionnaires, third-party risk management and integrations with many tools. It is aimed at startups, growing companies and enterprises and is delivered as software as a service.
Drata was founded in 2020 and is based in the United States, with offices including San Francisco, New York and San Diego, as well as London and Sydney. US legislation such as the CLOUD Act can therefore apply. Drata accounts are created in a North America, Europe or Asia-Pacific region, and the organisation settings show the region where the data is hosted. The documentation does not state which cloud locations sit behind each region, so a European organisation is best advised to record the hosting location contractually. Drata is not open source.