Sign in
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Reviews from AWS customer

4 AWS reviews

External reviews

1,089 reviews
from and

External reviews are not included in the AWS star rating for the product.


    Bala K.

Drata has helped to automate our compliance and governance processes

  • August 28, 2024
  • Review provided by G2

What do you like best about the product?
Ability to track our risks w.r.t to personnel, process, infrastructure , policy and vendors - all in one place is super helpful.
What do you dislike about the product?
Not all auditors use Drata. So we need to supply the evidence manually in those cases.
Also Drata support quality can improve.
What problems is the product solving and how is that benefiting you?
It integrates well with our cloud platform and its automation to manage the risks across people, process/policy and infrastructure/technology helps us track and remediate those risks timely. It helps with our compliance needs to met our regulations and framework requirements.


    murray m.

The software is intiive and they have exelcent support

  • August 21, 2024
  • Review provided by G2

What do you like best about the product?
Defaut policy are close to what we want and they are easy to edit.
What do you dislike about the product?
Sometimes the agent does not communicate wiht the server.
What problems is the product solving and how is that benefiting you?
Getting our company SOC 2 compliant.


    Information Technology and Services

Drata is the best in class tool for maintaining continuous compliance

  • August 15, 2024
  • Review provided by G2

What do you like best about the product?
Features I like most:
Connections to most every system we use
Real Time Monitoring of security controls
Evidence collection/managment
The ability to pose audit & compliance related questions to a team of experts.
Great support, especially from Tayler Gase and the team on chat.
Trust Center portal


You need a system like this to ease the impact of audit season.
What do you dislike about the product?
My particular auditor didn't seem to care that I'm using Drata and we still end up collaborating via spreadsheets.
What problems is the product solving and how is that benefiting you?
Drata makes audit season MUCH MUCH easier, especially year over year, as now you have an excellent way of organizing evidence over time.
Drata's Trust Center provides a great method for sharing our security posture and documents with our clients.


    Johnny Chen

Collects and stores compliance evidence and documentation for you using native integrations with your tech stack.

  • August 12, 2024
  • Review provided by PeerSpot

What is our primary use case?

We mainly use Drata as our GRC tool. Previously, we didn't have a GRC tool in-house. As a payment company, we must complete two annual audits: PCI for the payment card industry and SOC 2 Type 2, which most software companies also need. Without a GRC tool, we had separate contracts with each auditing firm, and they provided their tools for us to upload audit evidence. We had to produce the same evidence every year and manually upload it to these tools. If we changed auditors, we'd have to use new software each time, and our previous year's evidence stayed with the auditors. Now, with Data, we can store all our information in-house. Instead of auditors using their platforms, they come to Drata to access the evidence. Throughout the year, we upload and complete audit evidence in Drata, so during the audit period, auditors access what they need from the Drata platform. This means that when we change auditors, it doesn't matter who they are as long as they can access Drata.

How has it helped my organization?

Data contains evidence that InfoSec-related audits are often similar. About 30-40% of SOC 2 evidence can be used for PCI audits. Previously, we had to produce separate evidence for each audit and send it to different auditors. Everything lives in Drata, and we can use the sameevidence for PCI and SOC 2 audits. Drata’s cross-mapping between evidence and requirements makes this possible.

What is most valuable?

Drata keeps adding new features, allowing us to build our entire InfoSec program within it. Adding new components and evidence for different audits is easy. Drata also integrates with various software, like ticketing systems, source code control, and cloud platforms, continuously pulling evidence from these integrations. Without a GRC tool with these integrations, we used to gather evidence from different software during audits manually.

Drata has a significant impact on our security posture management. Previously, Drata had features for security posture management, primarily through integration with AWS. For example, it would scan AWS for specific security requirements, like ensuring all S3 buckets are private. It will be reported on the Drata platform if it finds a public bucket.

Recently, Drata introduced a new feature that uses an infrastructure-as-code approach. This feature detects issues and provides AI-generated suggestions for fixing them. If an organization uses infrastructure-as-code solutions like Terraform, Drata will suggest changes to the Terraform code to address the issues. You can then review and apply these changes to fix the problems. This is particularly useful when dealing with many topics, as it helps automate and speed up the process of implementing fixes. However, this AI-generated code feature is part of Drata’s upsell options. The basic version of Drata offers limited capabilities compared to the advanced features available with a paid upgrade.

Even without this new feature, Drata's security posture management is valuable, as it scans cloud environments for deviations from defined security baselines. Many tools offer similar capabilities, but Drata’s new feature that translates issues into actionable fixes is a notable advancement. This benefits teams with the capability and resources to use this tool effectively.

What needs improvement?

There is room for improvement in Drata. The core features are solid, but some new features are in a very MVP (Minimum Viable Product) stage. They work, but the user experience isn't always smooth. While the core features are well-developed compared to the market, the new features need more polish. They could benefit from more user feedback and iterations to make them more useful. Some of these new features look promising buthave flaws, so we can’t fully adopt them or justify paying extra for them now. The user interface is clean and intuitive. However, you'll need some specific knowledge if you're a security policy manager or need to set updifferent integrations.

For how long have I used the solution?

I have been using Drata for more than one year.

What do I think about the stability of the solution?

I've never noticed Drata having stability issues, like bugs or breakdowns. It doesn’t have high real-time availability requirements, so minor outages usually go unnoticed unless they last for a day or more. I've never seen latency or significant downtime.

What do I think about the scalability of the solution?

Regarding scalability, Drata works well for small to medium-sized businesses withfewer than 500 employees like ours. However, I can't speak to its performance for large enterprises with thousands of employees. For us, it handles our cloud footprint adequately, but there could be issues with some features at a larger scale. For example, its access management lacks batch review capabilities, which could be problematic for large organizations. Reviewing every software and access in a vast enterprise might become excessively complex without betterscaling solutions.

How are customer service and support?

The support team at Drata is top-notch, the best I’ve seen. They have two main types of support: technical support for software or integration issues and auditing support from experienced consultants for audit-related advice. Technical support is excellent, with quick response times. For auditing support, they handle more straightforward issues through live chat within the software, but for more complex problems, I reach out to our customer success manager. We can collaborate through meetings or document sharing; they’re always willing to discuss questions face-to-face if needed. Overall, I have nothing but praise for their support.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Compared to other tools we tried before adopting Drata, Drata stands out. Many tools either have fundamental features with a clean UI but limited functionality or offer similar features to Drata but with a complicated, hard-to-use interface. Drata has achieved a good balance between itsfeatures and usability. However, it could become problematic if they continue adding features without maintaining thisbalance. For now, Drata is in a good place regarding usability and complexity.

What's my experience with pricing, setup cost, and licensing?

Drata's pricing is quite reasonable. Compared to other tools in the market, including its biggest competitor, Vanta, Drata is much cheaper. Even compared to other tools like AuditBoard, which aren’t as good, Drata’s price remains competitive.

What other advice do I have?

Overall, I would rate Drata a ten. I would recommend it to others. For new users, I advise relying heavily on their support team, especially if you're not experienced in compliance. The support team is accommodating and reliable.

Regarding integration capabilities, I’d rate it an eight. Drata supports many primary software tools, but there are still some gaps. For example, they currently only support Salesforce for CRM and do not yet support HubSpot, which many people use. They’re good with the integrations they offer, but there’s room for improvement in coverage.


    E-Learning

Drata has been instrumental in getting our company ISO certified!

  • July 31, 2024
  • Review provided by G2

What do you like best about the product?
Using Drata has been an outstanding experience. The platform is incredibly user-friendly, and their 24/7 support makes navigating compliance straightforward. When I started my project, I had minimal knowledge about data security and relevant frameworks. Thanks to Drata’s comprehensive resources, I was able to educate myself more effectively than any book or course could have managed. The information is presented in layman’s terms, making it accessible to everyone. I highly recommend Drata to anyone looking to enhance their security measures.
What do you dislike about the product?
Honestly there isn't anything to dislike
What problems is the product solving and how is that benefiting you?
Our company aimed to achieve ISO certification, but we lacked an in-house legal team and a data privacy officer. Drata's user-friendly platform and extensive resources addressed both of these challenges, enabling us to pass our initial certification with flying colors.


    Byron S.

Good Repository of Policies and Procedures

  • July 31, 2024
  • Review provided by G2

What do you like best about the product?
Email notifications contain links that generally take me where I need to be. Dashboards and statuses are clear. Implemented quickly and we were quickly using it. The extra support for the first month was beneficial.
What do you dislike about the product?
As an infrequent user (a couple of times a week), I don't always remember which menu/toolbar items I need to click on if I am doing something outside of an email notification. The menu isn't always intuitive for me as to what I should click. The dashboard can be a little misleading when listing the completed task percentage - many tasks may be mostly finished but I'm not sure how to see, for example, that 20 tasks are completed and 40 tasks are 90+% done.
What problems is the product solving and how is that benefiting you?
Drata helps us ensure that our cloud product is secure. Certification will help us win contracts with larger prospects that are starting to ask for certifications completed.


    Computer Software

Great customer service and features that solve real-world problems.

  • July 31, 2024
  • Review provided by G2

What do you like best about the product?
Amazing product and customer service. The best feature are it's customizable cross-map that can go in-depth and assign tasks.
What do you dislike about the product?
It's a good product. The dislike would be probably more investment into the User Experience.
What problems is the product solving and how is that benefiting you?
Agile compliance.


    Juan Esteves

Friendly to use and offers powerful functionalities

  • July 29, 2024
  • Review from a verified AWS customer

What is our primary use case?

I use the solution in my company to apply for SOC 2 certification and to take notes on some controls that we have in AWS and other stuff.

What needs improvement?

I wish the tool were more granular with some configurations about the controls or the platforms. I don't know whether the information and the way that we share it with third parties could be made more granular, if the benefit could be done, and if it would be a fine product.

The product can improve in its API documentation area.

For how long have I used the solution?

I have been using Drata for a year and eight months. I am the solution's customer.

What do I think about the stability of the solution?

I never had any issues with the stability of the product.

What do I think about the scalability of the solution?

I was impressed the first time using Drata because you could put all the data that you have in all across all the platforms over there. Drata tells you how good or bad you will be for applying for those certifications. I rate the tool's scalability a nine out of ten.

In the cybersecurity team, three or four people used to use the tool. The rest of the team used only the agents in their laptops.

How are customer service and support?

I didn't use the solution's technical support a lot, but when I had to, it was great. I had no problem. I rate the technical support an eight out of ten.

How would you rate customer service and support?

Positive

What's my experience with pricing, setup cost, and licensing?

The product is really expensive. I remember that my company used to pay 25,000 USD to use the product, but I can recommend it to those who have no team and still need a certification, evidence or anything related to such areas. The product's cost is really high, but it is a powerful tool.

What other advice do I have?

Impact of the product on your company's security posture management has been great because we had a team of three people in the security part, and I was their technical leader. In our company, we have a CIO and an operations team. We have only three people on the team, and Drata helps us to increase and enhance the maturity of our controls and evidence for future auditing and other compliance assessments.

With the automated evidence feature of the product, we connected all our platforms, like Amazon, and then we connected with GitHub Enterprise to get information about the outbound application. Data has a control panel for third parties so that they can read or know what controls are working and how, which is a breaking advantage for such a tool.

The product is 100 percent friendly to use.

I rate Drata's integration capabilities as an eight out of ten.

If I have ten people with Excel and fully commit to write the controls, then maybe we won't require Drata. If you have a small team, and you want to hurry up with things in your company, Drata is the perfect solution.

I rate the tool an eight out of ten.


    Jason S.

The Drata platform is instrumental in our ability to maintain our security posture.

  • July 29, 2024
  • Review provided by G2

What do you like best about the product?
As we started our journey for SOC 2 and ISO certification, having policy templates at our fingertips expedited the process of compliance. In additional, the realtime monitoring of our posture and security controls is invaluable.
What do you dislike about the product?
There is nothing in Drata that would be considered disliked. Every feature, whether we leverage said feature or not, is or will be valuable at some point.
What problems is the product solving and how is that benefiting you?
Drata is part of 3 pillars that we leverage in security and compliance. Drata is the security automation platform, our partner Rhyemetic is our vCISO and other partner Insight Assurance is our auditor. Having all three of those componants allows us to convey our dedication to compliance to our existing and prospective customers.


    Patrick L.

Drata Makes Compliance Easy

  • July 29, 2024
  • Review provided by G2

What do you like best about the product?
Drata made it easy to migrate to their tool. Between dedicated onboarding support, easy to use features, and well written documentation, I was able to get started very quickly.

Drata's prebuilt integrations make life easier. I was using a lot of manual scripting to generate inventories and perform basic configuration checks, and Drata automated that all away.

Drata has a ton of small features that you don't know you need until you have them:
- A vendor inventory tool with the ability to attach security documentation and complete structured reviews of third-party audit reports.
- An evidence library that supports one-off evidence tasks and recurring evidence for whatever period you want.
What do you dislike about the product?
As someone who is very particular about how I want my compliance program to work, I want to be able to customize every aspect of a tool. There are some areas where I can't quite customize as I'd like, however Drata has recently introduce some interesting features around building custom monitors.
What problems is the product solving and how is that benefiting you?
A compliance program has a lot of moving parts. Drata helps keep all of it organized, letting you know what needs to be done and when. This frees up a lot of time and saves me from a ton of manual work.