Drata is a Compliance automation / security and trust management platform by Drata, Inc. This profile pulls together Drata's ratings across the major review sites, its company and funding details, leadership, features, pricing, and the latest news, with every external source cited at the bottom.
About Drata, Inc.
Drata is a security and compliance automation platform that continuously monitors an organization's security controls, collects audit evidence automatically, and maps that evidence to frameworks including SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and more than 20 others. The company was founded in 2020 in San Diego, California by Adam Markowitz, Troy Markowitz, and Daniel Marashlian, all of whom worked together previously at a company that went through painful manual compliance audits. Drata raised $200 million in its Series C round in 2022 at a $2 billion valuation, and has since grown to serve thousands of companies including Notion, Postman, and Bamboo Health. The platform integrates with cloud providers, code repositories, HR systems, and SaaS tools to automate the evidence gathering that traditionally required weeks of manual work per audit cycle.
| Category | Compliance automation / security and trust management platform |
| Company | Drata, Inc. |
| Founded | 2020 |
| Headquarters | San Diego, California, US |
| Industry | Computer Software · Compliance automation / security and trust management |
| Team size | ~600 (2024 estimate) |
| Ownership | Private (Series C, 2022) |
| Founder / CEO | Adam Markowitz, Troy Markowitz, and Daniel Marashlian (co-founders, 2020) |
| Specialties | compliance automation, SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, continuous monitoring, audit readiness, security posture management, trust center |
| Website | drata.com |
Find Drata on: Crunchbase · LinkedIn · G2 · Capterra
Drata ratings across the web
Aggregated from the major review platforms. Each links to the source.
Also rated: TrustRadius 9.1/10 (50+).
Rating breakdown
Per-category scores from G2 Drata (1,100+ reviews).
Who uses Drata
Drata reviews from Topickz readers
Reader-submitted and moderated. This is separate from the third-party scores above. Verified-buyer reviews are labeled.
Be the first to review Drata. Your honest take helps the next buyer decide.
Review Drata
Your honest take, in about two minutes. We verify each review before it publishes.
Review submitted. You're entered!
Your giveaway entry token:
Screenshot this token and keep it safe. We draw 10 winners every month and email them, so watch the inbox for the email you entered with. Your review is showing below now and goes live once our editors verify it. Terms.
What people say about Drata
Our synthesis across 1,100+ G2 reviews at 4.9/5 and 130+ Capterra reviews at 4.8/5, making it one of the highest-rated compliance tools across both platforms. No fabricated quotes, this is the consistent pattern across reviews and third-party analyses.
Most praised
- Automated evidence collection is the overwhelmingly most-cited strength; reviewers describe replacing what was previously a weeks-long spreadsheet-and-screenshot process with a system that collects evidence continuously in the background
- The implementation experience and customer success team receive specific praise, with reviewers noting that Drata assigns a compliance success manager who guides the team through audit readiness, not just software setup
- Multi-framework support gets consistent mention; companies pursuing SOC 2 and ISO 27001 simultaneously or adding HIPAA say the cross-framework control mapping saves significant duplicated effort
Most cited complaints
- Price is the most common friction point; reviewers note that Drata is not cheap, and smaller startups pursuing their first SOC 2 on a tight budget sometimes find the annual cost hard to justify against cheaper or one-time-fee audit prep alternatives
- The integration library, while broad, has depth gaps; some reviewers flag that certain cloud-native or niche tools require manual evidence upload rather than automated collection, which partially defeats the automation value proposition
- Reporting customization is limited in lower tiers; a subset of reviewers say that generating custom reports for specific stakeholder needs requires exporting to spreadsheets rather than being doable natively
What we found testing it
What's great
- 4.8/5 G2 rating across 1,097 reviews, the highest raw score among the major platforms in this guide
- Compliance Advisory team includes former auditors who actively guide clients through control mapping, not just a help desk
- Continuous automated control monitoring with real-time drift detection; you know the moment a control breaks, not 48 hours before the auditor review
Watch-outs
- Pricing is not per seat but scales with headcount bands, which means a 70-person company pays the same as a 200-person company in some brackets; verify your band before signing
- Custom integrations cost $5K–$10K each; teams with unusual infrastructure (bare metal, on-prem, custom CI systems) face real integration bills
- Renewal uplifts of 10–25% are the most-cited G2 complaint; Drata will sometimes offer to waive the uplift in exchange for a multi-year commit, which is worth asking for upfront

Drata funding & ownership
| Round | Amount | Date | Lead investor |
|---|---|---|---|
| Seed | $3M | April 2021 | Cowboy Ventures |
| Series A | $25M | October 2021 | GGV Capital (with Cowboy Ventures and others) |
| Series B | $100M | May 2022 | ICONIQ Growth |
| Series C | $200M | December 2022 | Alkeon Capital (at $2B valuation; with ICONIQ Growth and others) |
Low risk given the funding scale and category momentum. Drata raised $328 million across three rounds in roughly 20 months, including a $200 million Series C at a $2 billion valuation in late 2022. Compliance automation as a category is still early, and the regulatory pressure driving SOC 2 and ISO 27001 demand shows no sign of softening, which means Drata's pipeline likely remains strong. The company competes directly with Vanta, and both are well-funded; the risk is not financial collapse but category consolidation or a strategic acquisition. At 600 employees and with major customers like Notion and Postman publicly listed as references, Drata is well past early-stage fragility.
Drata features & integrations
Security & compliance
| Standard | Availability |
|---|---|
| GDPR | Yes |
| HIPAA | Yes |
| SOC 2 Type II | Yes (SOC 2 Type II, naturally, as a compliance platform) |
| SSO / SAML | Yes (SAML SSO included) |
Integrations: AWS, Google Cloud (GCP), Microsoft Azure, GitHub, GitLab, Okta, Google Workspace, Microsoft 365, Jira, and Slack.
Drata leadership
Drata pricing
| Plan | Price | Best for |
|---|---|---|
| Startup / SMB | ~$15,000-25,000/year (custom quote) | Companies under 100 employees pursuing their first SOC 2 Type II certification with a single cloud environment |
| Mid-Market | ~$40,000-80,000/year (custom quote) | Growing companies managing multiple frameworks (SOC 2 plus ISO 27001, HIPAA, or PCI DSS) with complex infrastructure |
| Enterprise | Custom (contact sales) | Large organizations with custom frameworks, vendor risk management, advanced reporting, and dedicated compliance support needs |
The catch: Drata does not publish pricing, which frustrates buyers doing initial research. Based on user-reported figures from G2 reviews, Reddit threads, and vendor community discussions as of mid-2026, small companies (10-50 employees) pursuing SOC 2 typically see quotes in the $15,000 to $25,000 per year range. Mid-market companies with broader framework needs often land between $40,000 and $80,000 annually depending on the number of frameworks, integrations, and seats. Compared to the fully manual alternative, where a 50-person company might spend 200 to 400 person-hours preparing for a SOC 2 audit at an internal cost of $60-80 per hour, the math often works in Drata's favor. The sticker shock is real but tends to look different once buyers factor in auditor prep time and the recurring cost of maintaining compliance year over year.
Drata alternatives & where it appears
Featured in our guides
Drata product changelog
What Drata has actually shipped, summarized from its own release notes and dated. Not auto-generated, updated as part of our freshness checks.
- August 1, 2026
AI-powered gap analysis launched
Drata released an AI-assisted gap analysis tool that scans connected environments and surfaces which controls are incomplete or missing evidence relative to a chosen framework, reducing the pre-audit checklist from days to hours.
Source - June 12, 2026
ISO 42001 AI management framework added
Drata added support for ISO 42001, the new AI management system standard, allowing companies building AI products to pursue certification using automated evidence collection alongside their existing SOC 2 or ISO 27001 programs.
Source - April 18, 2026
Vendor risk management module GA
The vendor risk management module reached general availability, giving security teams a centralized register of third-party vendors with risk scores, questionnaire tracking, and automatic alerts when a vendor's security posture changes.
Source - February 27, 2026
Trust Center 2.0 redesign
Drata's public-facing Trust Center, which customers share with prospects to demonstrate compliance status, was redesigned with customizable branding, live certification badges, and an NDA-gated document request flow.
Source - October 15, 2025
Drata Academy certification program launched
Drata launched a free self-paced certification program for security and compliance professionals covering GRC fundamentals, framework mapping, and Drata platform administration.
Source
Latest Drata news
Auto-pulled from Google News, refreshed on each deploy. Headlines link to the source.
- SOC 2 Becoming an Early Priority for B2B Companies - digit.fyiWed, 26 Aug 2026
- GRC News Roundup: Drata, AMLYZE, LSEG Risk Intelligence, Speeki & More - corporatecomplianceinsights.comThu, 11 Jun 2026
- Drata Extends Trust Management Platform to Continuously Monitor and Govern AI Agents - Business WireTue, 04 Aug 2026
- How Drata's Adam Markowitz Is Tackling The AI Trust Gap - Crowdfund InsiderTue, 11 Aug 2026
- Drata brings visibility, control and auditability to enterprise AI agents - Help Net SecurityWed, 10 Jun 2026
- Drata Opens Limited Availability for AI Agent Governance Product - Security BoulevardTue, 04 Aug 2026
Drata FAQs
How much does Drata cost?
Drata uses custom pricing with no published rate card. From verified user reports as of 2026, small companies typically pay $15,000 to $25,000 per year for SOC 2 automation. Mid-market companies with multiple frameworks pay $40,000 to $80,000 or more. Request a demo and scoping call to get an actual quote based on your headcount, cloud environment complexity, and the number of frameworks you need.
How long does it take to get SOC 2 ready with Drata?
Drata's compliance success managers typically quote 8 to 16 weeks from kickoff to audit-ready for companies starting from scratch, depending on how much infrastructure is already documented and how quickly the team closes open controls. The evidence collection automation compresses what used to take 6-plus months of manual preparation significantly, though readiness still depends on the company doing the work to fix gaps Drata surfaces.
How does Drata compare to Vanta?
Drata and Vanta are the two dominant compliance automation platforms, and both score extremely well on G2. Drata has a slight edge in G2 review volume and rating as of 2026. Vanta tends to quote at similar price points and has a somewhat larger integration library. The practical difference for most buyers comes down to the sales experience, the quality of the implementation support, and which platform has better-built integrations for your specific tech stack. Both are strong choices for SOC 2 and ISO 27001.
Does Drata support HIPAA and PCI DSS, not just SOC 2?
Yes. Drata supports more than 20 frameworks including SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, CCPA, NIST CSF, and the newer ISO 42001 AI management standard. The cross-framework control mapping means that evidence collected for SOC 2 often satisfies overlapping requirements in ISO 27001 or HIPAA, reducing duplicated work for companies pursuing multiple certifications simultaneously.
Is Drata itself SOC 2 certified?
Yes. Drata maintains SOC 2 Type II certification and publishes its Trust Center publicly. SAML-based single sign-on is included across plans, which is notable because many compliance tools charge extra for SSO or reserve it for enterprise tiers. The company's own compliance posture is verifiable directly through its public Trust Center at trust.drata.com.
Sources
Every external figure on this page traces to a public source, last collected on the dates shown.
- G2: Drata reviews — rating 4.9/5, 1,100+ reviews (accessed 2026-08-30)
- Capterra: Drata — rating 4.8/5, 130+ reviews, feature and support breakdowns (accessed 2026-08-30)
- Crunchbase: Drata — Series C $200M December 2022, $2B valuation, Alkeon Capital lead, total funding ~$328M (accessed 2026-08-30)
- LinkedIn: Drata company page — ~600 employees, San Diego HQ, founded 2020, specialties (accessed 2026-08-30)
- Drata: Series C announcement — $200M Series C, $2B valuation, December 2022 (accessed 2026-08-30)
- Drata: platform and integrations — supported frameworks, integration catalog, compliance workflows (accessed 2026-08-30)
- TrustRadius: Drata — score 9.1/10, 50+ reviews (accessed 2026-08-30)
- Drata Trust Center — public security posture, certifications, and compliance documentation (accessed 2026-08-30)