External reviews
1,085 reviews
from
and
External reviews are not included in the AWS star rating for the product.
Good
What do you like best about the product?
The onboarding calls and the provided support
What do you dislike about the product?
Not sure, probably too long to implement but maybe it's the nature of Soc2
What problems is the product solving and how is that benefiting you?
Soc2 Complience
Great GRC for companies of any size
What do you like best about the product?
I love the most DRATAs approach to security controls, their monitoring and evidence mapping.
It is simple to use and saves lot of time during yearly audits. Thanks to multiple usecases - Policy Center, Vendor management, etc. - it covers most of the areas required by many security standards.
Integrations to multiple systems - HR, Communication, Vulnerability management and others - makes the DRATA super useful in gathering the data at one place and using them efficiently.
It is simple to use and saves lot of time during yearly audits. Thanks to multiple usecases - Policy Center, Vendor management, etc. - it covers most of the areas required by many security standards.
Integrations to multiple systems - HR, Communication, Vulnerability management and others - makes the DRATA super useful in gathering the data at one place and using them efficiently.
What do you dislike about the product?
I dislike the DRATA simplified approach to Risk assessmnt (don´t misread with Enterprise Risk Management). It is too generic and doesn´t help our organisation to evaluate the current risks.
We would love to see imprvements in this area so that it would be more useful.
We would love to see imprvements in this area so that it would be more useful.
What problems is the product solving and how is that benefiting you?
Drata solves:
- continuous security frameworks monitoring (controls, monitoring, evidence etc.)
- vendor management
- governance (policy management)
- internal audit (audit hub)
- sharing security posture (trust center)
- employee compliance and HR processes
- device controls / protectin (drata agent)
- integrations (Slack, AWS, GitHub, Jira)
Whole company can be more efficient while using DRATA since it keeps our security posture well maintained. It reminds us about missing security evidence, upcoming audits and tasks which keeps the information up to date.
I consider drata reasonably cheap for the ammount of service / efficiency it provides to our company.
- continuous security frameworks monitoring (controls, monitoring, evidence etc.)
- vendor management
- governance (policy management)
- internal audit (audit hub)
- sharing security posture (trust center)
- employee compliance and HR processes
- device controls / protectin (drata agent)
- integrations (Slack, AWS, GitHub, Jira)
Whole company can be more efficient while using DRATA since it keeps our security posture well maintained. It reminds us about missing security evidence, upcoming audits and tasks which keeps the information up to date.
I consider drata reasonably cheap for the ammount of service / efficiency it provides to our company.
Good organizational tool for managing IT audits
What do you like best about the product?
I like the built-in tools to help manage the various audit processes we must comply with. It has helped our various team members go to one tool to manage the disparate and various needs of our audit process.
The default integrations matched 90% of the platforms we use today. Enabling Drata to scan our various tools regularly to ensure compliance.
The default integrations matched 90% of the platforms we use today. Enabling Drata to scan our various tools regularly to ensure compliance.
What do you dislike about the product?
The interface can be confusing at times.
What problems is the product solving and how is that benefiting you?
Drata is responsible for our Compliance Management, this has aided us keep our systems secure and transcat with enterprise level customers.
The most automated compliance platform we could find!
What do you like best about the product?
Many automated tests, reminders. Once we familiarized ourselves with the UI, it's really simple to use and it provides everything we need.
What do you dislike about the product?
It took me a while to get familiar with the UI. Also setting up connections was sometimes a bit tricky and we needed to contact Drata support to reset it and try again.
What problems is the product solving and how is that benefiting you?
Drata checks our identity provider, cloud accounts, ticketing system etc. and it all clicks together.
Drata best tool to use for Infosec complaince
What do you like best about the product?
Exceptional Customer Support:In the rare instances where assistance is needed, the Drata team provides exceptional customer support. The support team is responsive, knowledgeable, and dedicated to resolving issues promptly.
Seamless Integration: Drata seamlessly integrates with existing tools and software, minimizing disruptions during the implementation phase. This allows for easy monitoring for complaince
Seamless Integration: Drata seamlessly integrates with existing tools and software, minimizing disruptions during the implementation phase. This allows for easy monitoring for complaince
What do you dislike about the product?
Drata can expand the scope of the tools they integrate with so that users can have a wide variety
Drata can implement recurring tasks option to allow easy tracking of tasks
Drata can implement recurring tasks option to allow easy tracking of tasks
What problems is the product solving and how is that benefiting you?
compliance
Great experience navigating a challenging process
What do you like best about the product?
Clear instructions on navigating complex compliance needs and stellar customer service to guide you through compliance processes.
What do you dislike about the product?
Automated tests sometimes flag non-existent issues.
What problems is the product solving and how is that benefiting you?
Provides clear instructions on navigating SOC2 and HIPAA compliance procedures. Provides tools to maintain compliance year after year.
Great tool for compliance automation and customer assurance for cloud based applications
What do you like best about the product?
Great support / implementation experience. Modern and effective user experience across the portal. Comprehensive coverage for most major compliance and assurance programs. It is an investment to get fully onboarded by mapping existing controls to monitors for your environment, but the investment pays off in time saved each year during audit periods, and the ability to show real time monitoring status on the Trust Portal, which I recommend. Very good list of integrations for us, including our primary cloud provider, training provider, endpoint protection and policy management.
What do you dislike about the product?
The inherent problem with any compliance automation platform is that it must be opinionated, meaning you must have controls that match assumptions. If you are implementing Drata on top of an exisiting security program, and your controls don't match the "default" implementation expected, then you can't take advantage of automation on those controls. Drata is exceptionally powerful if it's implemented at the same time as your security controls, but has done very well being retrofit on an existing one as well.
What problems is the product solving and how is that benefiting you?
Compliance automation to save time and effort during audit cycles, and securely provide artifacts to customers.
Excellent software to monitor a certification
What do you like best about the product?
We liked it because it monitors different security parameters and it is also tracking who did what from a security standpoint.
We used it first when we were doing our Iso 27001 certification and we are still using it to monitor our current performance. It was also very useful when we upgraded from ISO27001-13 to 27001-22. It is comprehensive that made the qualification and audit easier for us and for the reviewer.
We used it first when we were doing our Iso 27001 certification and we are still using it to monitor our current performance. It was also very useful when we upgraded from ISO27001-13 to 27001-22. It is comprehensive that made the qualification and audit easier for us and for the reviewer.
What do you dislike about the product?
Sometimes there are no reg flags where some proof should be found and also sometimes there are flags just because a employe computer was not online for more than a day. Overall these are minors concerns and we were able to relay the information to the support team.
What problems is the product solving and how is that benefiting you?
we were looking for an easier way of achieving our iso certification and tracking our progress over time. It was also very useful when we upgraded from ISO27001-13 to Iso-27001-22. The tool is easy to use for our team and provides good visibility into our progress.
Build a security strategy from scratch
What do you like best about the product?
I use Drata every day. Drata offers a comprehensive list of requirements to meet and controls to be put in place for each certification. They are easily understandable if you have some basic skills in security.
What do you dislike about the product?
There are often issues with the different connections and the support struggles to sort them out.
What problems is the product solving and how is that benefiting you?
It provides me the precise list of requirements I need to meet to pass a security certification.
I get access to templates and it gathers automatically a lot of information from the connections.
I get access to templates and it gathers automatically a lot of information from the connections.
Still the best place for compliance and audit checking
What do you like best about the product?
The software is simple enough that anyone can understand what is happening but complex enough so that when passing information about technical tasks no one is looking at you with a blank face.
Implementation of the tasks are described well and any time I have any queries I the in app chat is always handy and if it is something more complex my account manager will contact me shortly afterwards.
Implementation of the tasks are described well and any time I have any queries I the in app chat is always handy and if it is something more complex my account manager will contact me shortly afterwards.
What do you dislike about the product?
When you having a failing tasks there is no notification either through email or some other method to advise this. Had a case where something change and the monitored task was failing but didn't pick it up until i checked Drata at the end of the week.
What problems is the product solving and how is that benefiting you?
Drata solved our problems with setting up, monitoring and tracking SOC2 compliance. We have gone further than this and using it to keep on top of our GDPR and soon ISO27001.
showing 161 - 170