External reviews
                                
                                371 reviews 
                            
                            from
                            
                                
                                    
                                    
                                    
                                    
                                
                            
                                
                                    
                                     and 
                                    
                                    
                                
                            
                        External reviews are not included in the AWS star rating for the product.
Continuous monitoring all the way!
What do you like best about the product?
Drata allows companies to automate the control of what's going on internally, having these controls monitored every single second rather than just seeing pictures of this over time is the most helpful thing ever for people and companies that care about their compliance.
What do you dislike about the product?
Ohh, if you could complete the endless security questionnaires that come to our emails it would be so good :)
What problems is the product solving and how is that benefiting you?
Automated compliance controls for achieving SOC2. It should be awesome to see how we compare to all the other standards, but I guess we'll check it over time
                        
                            Pretty unintrusive agent
What do you like best about the product?
My computer performs the same with the Drata agent as it does without it. That's not something you get from many endpoint software. Granted Drata itself mostly checks for configuration things and doesn't, for example, do virus scanning on its own, but still.
And it's cross platform and supports all the different kinds of computers we have in our organizatino.
And it's cross platform and supports all the different kinds of computers we have in our organizatino.
What do you dislike about the product?
Haven't found anything deal-breaking so far. But the endpoint software isn't open source, which makes it harder to reason about how safe it is to install. Or to verify that it only does what it says it does. They have a GitHub "repo" that hosts the releases https://github.com/drata/agent-releases but not the source. That just seems kind of an oblique use of GitHub. Eh.
What problems is the product solving and how is that benefiting you?
We're using it to verify that certain computer configurations are in place, e.g. disk encryption is enabled. These vary from computer to computer because different people at our organization use different operating systems.
                        
                            Drata review
What do you like best about the product?
I like the UI, it's very clean, nice looking, and understandable. I really like how we can use it as a unification tool for compliance, keeping all of our policies in the same location that we sign off on them is very convenient. I'm looking forward to having audits go smoother.
What do you dislike about the product?
I don't love that the connection to background checks requires a lot of manual interaction. We do background checks with Checkr before hiring a candidate so its always completed before they are in the Drata system, this makes it so we have to individually status each person instead of it being detected automatically. I realize that this is probably completely a limitation of Checkr.
What problems is the product solving and how is that benefiting you?
Easy compliance auditing
                        
                            Easy SOC2 Preparation and Monitoring
What do you like best about the product?
Great support and easy to use interface which is perfect for beginners. Drata is the easiest solution to go from zero to being ready for SOC2 for a small startup.
What do you dislike about the product?
Only SOC2 compliance for now and no support for other compliance frameworks. The security program that Drata recommends is harder to customize for existing security programs or more complex use cases.
What problems is the product solving and how is that benefiting you?
As a startup that is new to SOC2 compliance, we found the individual tests provided by Drata and explanations to address them very easy to follow and setup. Furthermore, the recommendations provided by Drata to achieve SOC2 compliance are sensible to adopt and didn't require our organization make large changes to existing procedures. Without an extensive background in security, we were able to figure out what we needed to do from the generated SOC2 policies, support resources, and automated tests. Finally, we have high confidence that we are staying in compliance over the course of the year for our SOC2 Type 2 audit since Drata is continuously evaluating our configuration every night.
                        
                            
                    
            showing 101 - 104