Privacy Ratings

Compliance automation

Drata privacy rating

Hosted compliance automation platform that monitors controls and collects evidence from connected cloud and business tools for SOC 2, ISO 27001, HIPAA, GDPR and other frameworks, with AI agents for questionnaires and risk management.

Summary

Drata scores 28 out of 100 (grade F) on the compliance automation criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales, independent audit and security headers. It does not meet open source, no trackers or telemetry, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.

Score 28 out of 100. How scoring works

Criteria

  • No

    Open source Weight 3 of 3

    Is all the source code needed to run the product public?

    Closed source.

  • No

    No trackers or telemetry Weight 3 of 3

    Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?

    The privacy notice says advertising partners are allowed to collect information through cookies and tracking technologies on its websites.

    drata.com

  • Partial

    No ads or data sales Weight 2 of 3

    Is the product funded without advertising, ad targeting or selling user data?

    Paid service with no ads, but website data is shared with advertising partners, which may count as a sale or sharing under California law.

    drata.com

  • Partial

    Independent audit Weight 2 of 3

    Has an independent security or privacy audit been published within the last three years?

    The trust center lists SOC 2 Type 2, ISO/IEC 27001 and penetration test reports, but full reports require requesting access. Only a SOC 3 summary is listed separately.

    trust.drata.com

  • No

    Transparency report Weight 2 of 3

    Does the provider regularly publish how many government and legal requests it receives and how it responds?

    No transparency report is published. The privacy notice only says data may be shared in response to lawful requests by law enforcement.

    drata.com

  • No

    Tells users about requests Weight 1 of 3

    Does the provider promise to tell users about requests for their data, unless a court forbids it?

    No published policy on notifying users about data requests.

Automated tests

  • Yes

    TLS configuration Weight 2 of 3

    Does the website pass the Qualys SSL Labs test with a grade of A or better?

    Grade A+

    ssllabs.com

  • Partial

    Security headers Weight 1 of 3

    Does the website pass the Mozilla HTTP Observatory test with a grade of A or better?

    Grade B+ (80/100+)

    developer.mozilla.org

  • Not tested yet

    Modern web standards Weight 1 of 3

    Does the website score 90% or higher on the Internet.nl website test?

    Not tested yet.

Other compliance automation

All 11 compliance automation