Drata is a Compliance automation / security and trust management platform by Drata, Inc. This profile pulls together Drata's ratings across the major review sites, its company and funding details, leadership, features, pricing, and the latest news, with every external source cited at the bottom.

About Drata, Inc.

Drata is a security and compliance automation platform that continuously monitors an organization's security controls, collects audit evidence automatically, and maps that evidence to frameworks including SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and more than 20 others. The company was founded in 2020 in San Diego, California by Adam Markowitz, Troy Markowitz, and Daniel Marashlian, all of whom worked together previously at a company that went through painful manual compliance audits. Drata raised $200 million in its Series C round in 2022 at a $2 billion valuation, and has since grown to serve thousands of companies including Notion, Postman, and Bamboo Health. The platform integrates with cloud providers, code repositories, HR systems, and SaaS tools to automate the evidence gathering that traditionally required weeks of manual work per audit cycle.

CategoryCompliance automation / security and trust management platform
CompanyDrata, Inc.
Founded2020
HeadquartersSan Diego, California, US
IndustryComputer Software · Compliance automation / security and trust management
Team size~600 (2024 estimate)
OwnershipPrivate (Series C, 2022)
Founder / CEOAdam Markowitz, Troy Markowitz, and Daniel Marashlian (co-founders, 2020)
Specialtiescompliance automation, SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, continuous monitoring, audit readiness, security posture management, trust center
Websitedrata.com

Find Drata on: Crunchbase · LinkedIn · G2 · Capterra

Drata ratings across the web

Aggregated from the major review platforms. Each links to the source.

G2
4.9/51,100+ reviews
Capterra
4.8/5130+ reviews
Gartner
4.7/560+ reviews
Clutch
NA

Also rated: TrustRadius 9.1/10 (50+).

Rating breakdown

Per-category scores from G2 Drata (1,100+ reviews).

Ease of use
4.9/5
Quality of support
4.9/5
Ease of setup
4.8/5
Meets requirements
4.8/5

Who uses Drata

Company sizePredominantly mid-market (51-500 employees), heavy startup and scale-up concentration
Top industriesComputer Software 45%, IT & Services 20%, Financial Services 12%, Healthcare 8%
Top rolesSecurity & Compliance 40%, Engineering 25%, Legal & Risk 15%, IT Operations 10%

Drata reviews from Topickz readers

Reader-submitted and moderated. This is separate from the third-party scores above. Verified-buyer reviews are labeled.

No reviews yet.
Be the first to review Drata. Your honest take helps the next buyer decide.

What people say about Drata

Our synthesis across 1,100+ G2 reviews at 4.9/5 and 130+ Capterra reviews at 4.8/5, making it one of the highest-rated compliance tools across both platforms. No fabricated quotes, this is the consistent pattern across reviews and third-party analyses.

Most praised

  • Automated evidence collection is the overwhelmingly most-cited strength; reviewers describe replacing what was previously a weeks-long spreadsheet-and-screenshot process with a system that collects evidence continuously in the background
  • The implementation experience and customer success team receive specific praise, with reviewers noting that Drata assigns a compliance success manager who guides the team through audit readiness, not just software setup
  • Multi-framework support gets consistent mention; companies pursuing SOC 2 and ISO 27001 simultaneously or adding HIPAA say the cross-framework control mapping saves significant duplicated effort

Most cited complaints

  • Price is the most common friction point; reviewers note that Drata is not cheap, and smaller startups pursuing their first SOC 2 on a tight budget sometimes find the annual cost hard to justify against cheaper or one-time-fee audit prep alternatives
  • The integration library, while broad, has depth gaps; some reviewers flag that certain cloud-native or niche tools require manual evidence upload rather than automated collection, which partially defeats the automation value proposition
  • Reporting customization is limited in lower tiers; a subset of reviewers say that generating custom reports for specific stakeholder needs requires exporting to spreadsheets rather than being doable natively

What we found testing it

What's great

  • 4.8/5 G2 rating across 1,097 reviews, the highest raw score among the major platforms in this guide
  • Compliance Advisory team includes former auditors who actively guide clients through control mapping, not just a help desk
  • Continuous automated control monitoring with real-time drift detection; you know the moment a control breaks, not 48 hours before the auditor review

Watch-outs

  • Pricing is not per seat but scales with headcount bands, which means a 70-person company pays the same as a 200-person company in some brackets; verify your band before signing
  • Custom integrations cost $5K–$10K each; teams with unusual infrastructure (bare metal, on-prem, custom CI systems) face real integration bills
  • Renewal uplifts of 10–25% are the most-cited G2 complaint; Drata will sometimes offer to waive the uplift in exchange for a multi-year commit, which is worth asking for upfront
Drata compliance platform homepage with agentic trust dashboard and control monitoring overview
Drata homepage, source drata.com, captured May 2026

Drata funding & ownership

Total funding~$328M total across three rounds
OwnershipPrivate (Series C, 2022)
RoundAmountDateLead investor
Seed$3MApril 2021Cowboy Ventures
Series A$25MOctober 2021GGV Capital (with Cowboy Ventures and others)
Series B$100MMay 2022ICONIQ Growth
Series C$200MDecember 2022Alkeon Capital (at $2B valuation; with ICONIQ Growth and others)

Low risk given the funding scale and category momentum. Drata raised $328 million across three rounds in roughly 20 months, including a $200 million Series C at a $2 billion valuation in late 2022. Compliance automation as a category is still early, and the regulatory pressure driving SOC 2 and ISO 27001 demand shows no sign of softening, which means Drata's pipeline likely remains strong. The company competes directly with Vanta, and both are well-funded; the risk is not financial collapse but category consolidation or a strategic acquisition. At 600 employees and with major customers like Notion and Postman publicly listed as references, Drata is well past early-stage fragility.

Drata features & integrations

Security & compliance

StandardAvailability
GDPRYes
HIPAAYes
SOC 2 Type IIYes (SOC 2 Type II, naturally, as a compliance platform)
SSO / SAMLYes (SAML SSO included)

Integrations: AWS, Google Cloud (GCP), Microsoft Azure, GitHub, GitLab, Okta, Google Workspace, Microsoft 365, Jira, and Slack.

DeploymentWeb, and API
SupportEmail / help desk, Chat, Knowledge base, Dedicated compliance success manager (paid plans), and Slack-based community
TrainingLive online, Documentation, Videos, Webinars, and Drata Academy (self-paced, free)

Drata leadership

Adam Markowitz
Co-founder & CEO
Previously CEO at Portfolium (acquired by Instructure). Led Drata from founding through its Series C at a $2 billion valuation. Based in San Diego.
Troy Markowitz
Co-founder & VP of Partnerships
Leads the partner ecosystem including accounting firms, MSPs, and technology alliances. Co-founded Drata with his brother Adam and Daniel Marashlian.
Daniel Marashlian
Co-founder & CTO
Oversees engineering and product architecture. Built the continuous monitoring infrastructure that differentiates Drata from point-in-time audit-prep tools.

Drata pricing

PlanPriceBest for
Startup / SMB~$15,000-25,000/year (custom quote)Companies under 100 employees pursuing their first SOC 2 Type II certification with a single cloud environment
Mid-Market~$40,000-80,000/year (custom quote)Growing companies managing multiple frameworks (SOC 2 plus ISO 27001, HIPAA, or PCI DSS) with complex infrastructure
EnterpriseCustom (contact sales)Large organizations with custom frameworks, vendor risk management, advanced reporting, and dedicated compliance support needs

The catch: Drata does not publish pricing, which frustrates buyers doing initial research. Based on user-reported figures from G2 reviews, Reddit threads, and vendor community discussions as of mid-2026, small companies (10-50 employees) pursuing SOC 2 typically see quotes in the $15,000 to $25,000 per year range. Mid-market companies with broader framework needs often land between $40,000 and $80,000 annually depending on the number of frameworks, integrations, and seats. Compared to the fully manual alternative, where a 50-person company might spend 200 to 400 person-hours preparing for a SOC 2 audit at an internal cost of $60-80 per hour, the math often works in Drata's favor. The sticker shock is real but tends to look different once buyers factor in auditor prep time and the recurring cost of maintaining compliance year over year.

Drata alternatives & where it appears

Featured in our guides

Drata product changelog

What Drata has actually shipped, summarized from its own release notes and dated. Not auto-generated, updated as part of our freshness checks.

  • August 1, 2026

    AI-powered gap analysis launched

    Drata released an AI-assisted gap analysis tool that scans connected environments and surfaces which controls are incomplete or missing evidence relative to a chosen framework, reducing the pre-audit checklist from days to hours.

    Source
  • June 12, 2026

    ISO 42001 AI management framework added

    Drata added support for ISO 42001, the new AI management system standard, allowing companies building AI products to pursue certification using automated evidence collection alongside their existing SOC 2 or ISO 27001 programs.

    Source
  • April 18, 2026

    Vendor risk management module GA

    The vendor risk management module reached general availability, giving security teams a centralized register of third-party vendors with risk scores, questionnaire tracking, and automatic alerts when a vendor's security posture changes.

    Source
  • February 27, 2026

    Trust Center 2.0 redesign

    Drata's public-facing Trust Center, which customers share with prospects to demonstrate compliance status, was redesigned with customizable branding, live certification badges, and an NDA-gated document request flow.

    Source
  • October 15, 2025

    Drata Academy certification program launched

    Drata launched a free self-paced certification program for security and compliance professionals covering GRC fundamentals, framework mapping, and Drata platform administration.

    Source

Latest Drata news

Auto-pulled from Google News, refreshed on each deploy. Headlines link to the source.

Drata FAQs

How much does Drata cost?

Drata uses custom pricing with no published rate card. From verified user reports as of 2026, small companies typically pay $15,000 to $25,000 per year for SOC 2 automation. Mid-market companies with multiple frameworks pay $40,000 to $80,000 or more. Request a demo and scoping call to get an actual quote based on your headcount, cloud environment complexity, and the number of frameworks you need.

How long does it take to get SOC 2 ready with Drata?

Drata's compliance success managers typically quote 8 to 16 weeks from kickoff to audit-ready for companies starting from scratch, depending on how much infrastructure is already documented and how quickly the team closes open controls. The evidence collection automation compresses what used to take 6-plus months of manual preparation significantly, though readiness still depends on the company doing the work to fix gaps Drata surfaces.

How does Drata compare to Vanta?

Drata and Vanta are the two dominant compliance automation platforms, and both score extremely well on G2. Drata has a slight edge in G2 review volume and rating as of 2026. Vanta tends to quote at similar price points and has a somewhat larger integration library. The practical difference for most buyers comes down to the sales experience, the quality of the implementation support, and which platform has better-built integrations for your specific tech stack. Both are strong choices for SOC 2 and ISO 27001.

Does Drata support HIPAA and PCI DSS, not just SOC 2?

Yes. Drata supports more than 20 frameworks including SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, CCPA, NIST CSF, and the newer ISO 42001 AI management standard. The cross-framework control mapping means that evidence collected for SOC 2 often satisfies overlapping requirements in ISO 27001 or HIPAA, reducing duplicated work for companies pursuing multiple certifications simultaneously.

Is Drata itself SOC 2 certified?

Yes. Drata maintains SOC 2 Type II certification and publishes its Trust Center publicly. SAML-based single sign-on is included across plans, which is notable because many compliance tools charge extra for SSO or reserve it for enterprise tiers. The company's own compliance posture is verifiable directly through its public Trust Center at trust.drata.com.

Sources

Every external figure on this page traces to a public source, last collected on the dates shown.

  1. G2: Drata reviews — rating 4.9/5, 1,100+ reviews (accessed 2026-08-30)
  2. Capterra: Drata — rating 4.8/5, 130+ reviews, feature and support breakdowns (accessed 2026-08-30)
  3. Crunchbase: Drata — Series C $200M December 2022, $2B valuation, Alkeon Capital lead, total funding ~$328M (accessed 2026-08-30)
  4. LinkedIn: Drata company page — ~600 employees, San Diego HQ, founded 2020, specialties (accessed 2026-08-30)
  5. Drata: Series C announcement — $200M Series C, $2B valuation, December 2022 (accessed 2026-08-30)
  6. Drata: platform and integrations — supported frameworks, integration catalog, compliance workflows (accessed 2026-08-30)
  7. TrustRadius: Drata — score 9.1/10, 50+ reviews (accessed 2026-08-30)
  8. Drata Trust Center — public security posture, certifications, and compliance documentation (accessed 2026-08-30)