{
  "slug": "drata",
  "category": "compliance-automation",
  "name": "Drata",
  "description": "Hosted compliance automation platform that monitors controls and collects evidence from connected cloud and business tools for SOC 2, ISO 27001, HIPAA, GDPR and other frameworks, with AI agents for questionnaires and risk management.",
  "website": "https://drata.com",
  "license": null,
  "platforms": [
    "web"
  ],
  "jurisdiction": {
    "code": "US",
    "name": "United States",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": "provider"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "F",
  "score": 28,
  "coverage": 100,
  "summary": "Drata scores 28 out of 100 (grade F) on the compliance automation criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales, independent audit and security headers. It does not meet open source, no trackers or telemetry, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
  "url": "https://privacyratings.com/compliance-automation/drata/",
  "markdown": "https://privacyratings.com/compliance-automation/drata/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Closed source."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": "https://drata.com/privacy",
      "note": "The privacy notice says advertising partners are allowed to collect information through cookies and tracking technologies on its websites."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://drata.com/privacy",
      "note": "Paid service with no ads, but website data is shared with advertising partners, which may count as a sale or sharing under California law."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://trust.drata.com/",
      "note": "The trust center lists SOC 2 Type 2, ISO/IEC 27001 and penetration test reports, but full reports require requesting access. Only a SOC 3 summary is listed separately."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "no",
      "evidence": "https://drata.com/privacy",
      "note": "No transparency report is published. The privacy notice only says data may be shared in response to lawful requests by law enforcement."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.drata.com&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "partial",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.drata.com",
      "note": "Grade B+ (80/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "B+",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [
      {
        "name": "Google Fonts",
        "host": "fonts.googleapis.com",
        "effect": "none"
      },
      {
        "name": "Google Tag Manager",
        "host": "www.googletagmanager.com",
        "effect": "no"
      },
      {
        "name": "HubSpot",
        "host": "js.hs-scripts.com",
        "effect": "no"
      }
    ],
    "tested_at": "2026-10-01T07:07:14.709Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}