Offers APIs for every clause so that it can integrate into various platforms
What is our primary use case?
I have been deploying all the services to Australia and USA. These are for customer compliance on HIPAA, ISO 27001, SOC 2, and similar standards.
How has it helped my organization?
Drata provides compliance management, including customer compliance on HIPAA, ISO 27001, and other standards. The platform allows for documentation and uploads of records, which can be reviewed by qualified security assessors. This helps in seamless audit preparations.
What is most valuable?
Drata offers APIs for every clause so that it can integrate into various platforms. It has real-time features and dashboards and allows for automation. The support is excellent, with rapid response within an hour. The platform is described as very rich, offering a comprehensive array of features.
What needs improvement?
The existing features of Drata are already extensive and costly to integrate. It requires a certain level of development understanding from companies. Improvements could be in the area of reducing costs and making integrations more accessible.
For how long have I used the solution?
Drata services have been deployed to Australia and the USA.
What do I think about the stability of the solution?
Drata has a good speed and is described as a fast solution.
How are customer service and support?
Customer service is excellent, with responses typically received within an hour. The support system, including TalkShare, is available and highly efficient.
Which solution did I use previously and why did I switch?
I have used several solutions before. Every company uses different software; not everyone goes for the highest qualified security systems available.
What was our ROI?
It doesn't provide monitoring benefits or savings directly as it's an assessment platform, yet it offers comprehensive compliance features.
What's my experience with pricing, setup cost, and licensing?
Drata is very expensive with each API incurring a cost. It is described as a costly tool. Rarely do people choose the most qualified security assessment tools due to cost considerations.
Which other solutions did I evaluate?
ServiceNow is cheaper, around $25,000 per company compared to Drata. Other tools evaluated include Avaya and various VMware products.
What other advice do I have?
I'd rate the solution eight out of ten.
Drata - Review after a few months using the tool
What do you like best about the product?
Automatic evidence collection, friendly user interface, ease of onboarding and implementation
What do you dislike about the product?
My organization is still fairly new to using Drata, so not a ton of downsides have been discovered yet. That said, we were excited to use the Trust Center to surface various documentation to customers. It seems tha tthe Trust Center still needs to mature a bit, as you are limited types of documentation can be surfaced there and simple features, such as the order that documents appear, are not in place yet.
What problems is the product solving and how is that benefiting you?
In my role, Drata is primarly benefiting (as of now) my team in audit readiness and preparation. We are just kicking off our annual SOC 2 audit and the ease of use compared to our last tool really stands out.
Support Experience
What do you like best about the product?
The tracking of evidence and policy renewals
What do you dislike about the product?
The pricing is too expensive and each piece costs extra
What problems is the product solving and how is that benefiting you?
compliance timing
Excellent Service and easy to use platform
What do you like best about the product?
I love the organization of having everything in one place. I also love the new beta security questionnaire tool
What do you dislike about the product?
The policy editor is a bit simple and could use more formatting features.
What problems is the product solving and how is that benefiting you?
It is allowing us to be proactive about our security posture and see what we need to focus on in a priority fashion.
Drata makes compliance managable
What do you like best about the product?
Drata has strong integration with all the technologies and products we use.
What do you dislike about the product?
Even with Drata automation there is still a lot of work that must be done manually, especially when auditors don't fully utilize Drata
What problems is the product solving and how is that benefiting you?
Drata solves the management of SOC 2 compliance for us across all dimensions
Compliance automation made easy.
What do you like best about the product?
The implementation service offered was great. 30 days handheld through the process with experienced users. Support is always fast and incredibly helpful. SSO worked really well and it integrated with the majority of our tech stack. Most of my team are able to navigate their way around it easily. For me, its easy to use and has become an unconscious standard practice to use it every day.
What do you dislike about the product?
Quite a bit of the products newer useful features don't support our versioning control i.e. 'compliance as code' and gitlab.
A lot of newer features released, i.e., risk management and trust centre pro are rather costly addons and during the procurement process, we weren't made aware of this.
What problems is the product solving and how is that benefiting you?
Evidence gathering is largely automated with helpful reminders for the less automated bits. It is a single pain of glass for our various standards and their controls.
Fast support
What do you like best about the product?
Fast support: we raised a request for help and were answered with a solution within the day.
What do you dislike about the product?
Page load and login speeds could be improved.
What problems is the product solving and how is that benefiting you?
ISO and SOC2 compliance.
Good experience
What do you like best about the product?
User friendly platform and great responsive feedback from our account manager
What do you dislike about the product?
DORA Framework still not available and we only 3 months out to new law.
What problems is the product solving and how is that benefiting you?
Multiple framework available for our global needs. Also special shout out to Ben Chau as our account manager for his responsive and detailed responses, appreciate your professionalism and continued relationship.
Compliance success depends on Customer Success
What do you like best about the product?
Drata is constantly evolving and it takes some time to become efficient using it, like no other compliance platform would be. However, it sticks out in two points:
1. Complete documentation and real-time, helpful support powered by AI and humans
2. An outstanding customer success support from Jordan Penn - he provides uncompared Customer Care making sure we use Drata to the fullest and meet our business objectives. He takes the time it needs to explain every bit of it and was available anytime despite time differences. Further, his proactive approach ensured we were all set for compliance of ISO 27001:2022 and SOC 2.
The key features saving time and ensuring compliance:
- Control and Policy library
- Automation of compliance tasks such as security training, policy signature, onboarding
What do you dislike about the product?
- Automated controls such as hardware compliance are a headache
- Recent Drata control changes require a full rehaul of the scope
- several Customer Success and Account Management changes in a short time
What problems is the product solving and how is that benefiting you?
Customer acquisition
Streamlines compliance
What do you like best about the product?
Templates, all in one place to manage compliance, fast support
What do you dislike about the product?
Add-ons and segmented features which would be really useful as part of core package e.g user access control
What problems is the product solving and how is that benefiting you?
Streamlining compliance