Cyber compliance made easy
What do you like best about the product?
Automation, automation and automation.
I like how Drata can automate and monitor our AWS, GCP and Git resources.
Support is very helpful too!
What do you dislike about the product?
It is a hard question... I could not find what to complain about.
What problems is the product solving and how is that benefiting you?
Compliance automation, SOC 2 audit preparation
Drata at its best.
What do you like best about the product?
I had never used a tool like Drata before in my 40 years of experience. It is so easy to use and navigate. It contains all the features required for Compliance. The Risk Management, Controls, personnel & the main feature Monitoring is its best.
What do you dislike about the product?
I have still not come across any downside as I have been using it for the last two months.
What problems is the product solving and how is that benefiting you?
The tests being done by Drata is helping me in a way that I don't have to do all the tests simultaneously. Monitoring is so easy. All policies are in one place. All security controls are in one place. The risks once assessed and the risk register & risk treatment plan are all in one place. I can monitor all the employees about what they have complied with and where they are not compliant.
Offers APIs for every clause so that it can integrate into various platforms
What is our primary use case?
I have been deploying all the services to Australia and USA. These are for customer compliance on HIPAA, ISO 27001, SOC 2, and similar standards.
How has it helped my organization?
Drata provides compliance management, including customer compliance on HIPAA, ISO 27001, and other standards. The platform allows for documentation and uploads of records, which can be reviewed by qualified security assessors. This helps in seamless audit preparations.
What is most valuable?
Drata offers APIs for every clause so that it can integrate into various platforms. It has real-time features and dashboards and allows for automation. The support is excellent, with rapid response within an hour. The platform is described as very rich, offering a comprehensive array of features.
What needs improvement?
The existing features of Drata are already extensive and costly to integrate. It requires a certain level of development understanding from companies. Improvements could be in the area of reducing costs and making integrations more accessible.
For how long have I used the solution?
Drata services have been deployed to Australia and the USA.
What do I think about the stability of the solution?
Drata has a good speed and is described as a fast solution.
How are customer service and support?
Customer service is excellent, with responses typically received within an hour. The support system, including TalkShare, is available and highly efficient.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
I have used several solutions before. Every company uses different software; not everyone goes for the highest qualified security systems available.
What was our ROI?
It doesn't provide monitoring benefits or savings directly as it's an assessment platform, yet it offers comprehensive compliance features.
What's my experience with pricing, setup cost, and licensing?
Drata is very expensive with each API incurring a cost. It is described as a costly tool. Rarely do people choose the most qualified security assessment tools due to cost considerations.
Which other solutions did I evaluate?
ServiceNow is cheaper, around $25,000 per company compared to Drata. Other tools evaluated include Avaya and various VMware products.
What other advice do I have?
I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Drata has made my life SO much easier when it comes time for Audits, and continuous compliance.
What do you like best about the product?
Drata consolidates evidence in one handy place, which means extracting needed info for auditors simple.
What do you dislike about the product?
I don't love that auditors can see historical test data - this can make it look like we aren't managing some systems well, when in reality we just don't have integrations that are compatible (ie, vulnerability scanning).
What problems is the product solving and how is that benefiting you?
Solve the time problem very effectively, and makes it easy to manage multiple areas of compliance in one dashboard.
Drata - Review after a few months using the tool
What do you like best about the product?
Automatic evidence collection, friendly user interface, ease of onboarding and implementation
What do you dislike about the product?
My organization is still fairly new to using Drata, so not a ton of downsides have been discovered yet. That said, we were excited to use the Trust Center to surface various documentation to customers. It seems tha tthe Trust Center still needs to mature a bit, as you are limited types of documentation can be surfaced there and simple features, such as the order that documents appear, are not in place yet.
What problems is the product solving and how is that benefiting you?
In my role, Drata is primarly benefiting (as of now) my team in audit readiness and preparation. We are just kicking off our annual SOC 2 audit and the ease of use compared to our last tool really stands out.
Game-changer for compliance automation
What do you like best about the product?
Drata breaks down the compliance process, even making it easier to work towards multiple frameworks at once by helping to consolidate controls and deliverables into a neat and comprehensible format. Additionally, the automation tools available to help achieve compliance, such as various device and account monitoring, is invualuable to actually achieving the work required to meet controls. They offer clean integrations with a wide swath of common SaaS tools. One key benefit here for us has been their integration with Jira, which we use to both create tickets related to compliance, as well as read tickets in order to automate compliance into processes such as employee offboarding. Their team is very helpful as well, ensuring we're setup for success.
What do you dislike about the product?
Downsides are minimal. Custom fields could be useful though for assets such as personnel and hardware.
What problems is the product solving and how is that benefiting you?
Drata is solving compliance for us. Reaching our compliance goals as an SMB would be monumentally more difficult without the Drata platform and team to help us work towards our goals in a way in which they are clearly presented to us, and in a platform where we can document progress and evidence neatly.
Support Experience
What do you like best about the product?
The tracking of evidence and policy renewals
What do you dislike about the product?
The pricing is too expensive and each piece costs extra
What problems is the product solving and how is that benefiting you?
compliance timing
Excellent Service and easy to use platform
What do you like best about the product?
I love the organization of having everything in one place. I also love the new beta security questionnaire tool
What do you dislike about the product?
The policy editor is a bit simple and could use more formatting features.
What problems is the product solving and how is that benefiting you?
It is allowing us to be proactive about our security posture and see what we need to focus on in a priority fashion.
Drata makes compliance managable
What do you like best about the product?
Drata has strong integration with all the technologies and products we use.
What do you dislike about the product?
Even with Drata automation there is still a lot of work that must be done manually, especially when auditors don't fully utilize Drata
What problems is the product solving and how is that benefiting you?
Drata solves the management of SOC 2 compliance for us across all dimensions
Drata review
What do you like best about the product?
The product is very good and helps in the management of certifications.
Also, the Customer Success people are very hard working and close to the customer along with their fast and efficient support.
What do you dislike about the product?
Probably its weak point is the management of roles within the platform as they are predefined and not very granular.
What problems is the product solving and how is that benefiting you?
Drata is helping us a lot in the management of certifications, internal policies and forensic testing of equipment.