Can your own AI agents be [TRUSTED]? Check out our latest newsletter below 👇
Drata
Software Development
San Francisco, California 99,061 followers
Drata is the Agentic Trust Management Platform for enterprise security leaders.
About us
Drata provides the trust network that enables businesses to operate, scale, and partner with confidence. Powered by AI and designed to operationalize trust, the Drata Agentic Trust Management Platform continuously interprets controls, risk, and assurance signals—reducing repetitive manual work while improving visibility into internal and third-party risk, enabling always-on audit readiness across compliance frameworks, and accelerating security reviews. Purpose-built for enterprise complexity, Drata unifies governance, risk, compliance, and assurance to deliver faster time-to-value, reduce operational overhead, and enable continuous trust for 8,000+ organizations worldwide.
- Website
-
https://drata.com
External link for Drata
- Industry
- Software Development
- Company size
- 501-1,000 employees
- Headquarters
- San Francisco, California
- Type
- Privately Held
- Specialties
- compliance, cybersecurity, automation, SOC 2, ISO 27001, HIPAA, and PCI DSS
Locations
-
Primary
Get directions
634 2nd St
San Francisco, California 94107, US
Employees at Drata
Updates
-
Context is what keeps an agent swarm from becoming a staffing model for bad outputs. Join us next Thursday at our office in San Francisco for the next event in our Builders Series: Context Tames the Swarm. 🐝 We’re bringing together builders shipping the tooling underneath agentic development for an evening focused on context engineering: what to feed agents, what to withhold, and how to keep a dozen of them productive at once. 🔶 Hear from Jinjing Liang, CEO at Orca ADE, and Nathan Burg, CPO and Co-founder at GitHits. 🔶 Get into the real failure modes behind multi-agent development — from hallucinated APIs to stale dependency assumptions to parallel work racing toward the same bad patch. 🔶 See how the right context helps agent teams work more productively in parallel. Doors open at 5:30 PM. Register now: https://okt.to/NUVRjf
-
-
Manual document approvals turn security reviews into a sales bottleneck. Jellyfish felt that friction firsthand. After migrating to Drata’s new Trust Center experience and connecting approvals to Salesforce, the team turned a static repository into a branded, self-serve experience built for faster buyer access. 🎯 Document access turnaround dropped from minutes or hours to seconds. 🎯 Roughly 2-3 hours per week were saved by automating questionnaire and inbound request work. 🎯 International prospects now get assurance documentation instantly instead of waiting for a security analyst to come online. As James Richardson, CISSP, Senior Security Analyst at Jellyfish, put it: “The move transformed compliance from a backend operational function into a direct driver of sales velocity.” Read the full case study: https://okt.to/j0F3pw
-
SOC 2 opens the healthcare conversation. It doesn’t decide what comes next. 🏥 For teams handling PHI, the next move is getting HIPAA operational before jumping into HITRUST. That sequencing matters. 🔷 Map your existing SOC 2 controls to HIPAA safeguards. 🔷 Close the gaps before scoping a certifiable assessment. 🔷 Confirm whether a buyer actually requires HITRUST i1 or r2 before you invest. (In one example from our latest playbook, confirming the right HITRUST tier changed project scope by roughly $150K and 4-6 months.) We map HIPAA and HITRUST controls against the evidence a team is already collecting for SOC 2, so nobody recreates documentation every time a new health system or payer asks for a different credential. Start charting your healthcare compliance roadmap here: https://okt.to/OXFxqW
-
-
The rules of trust have changed. We're joining Wolfpack Information Risk on August 27 for a practical discussion on how leading organizations are replacing reactive compliance with continuous trust. 🎯 If you've wondered... 👉 How do organizations demonstrate responsible AI? 👉 How does ISO 42001 fit alongside ISO 27001? 👉 What evidence will auditors increasingly expect? ...then register for the webinar here: https://okt.to/wc9onY
-
-
And we've lifted off! 🚀 Black Hat Las Vegas was a launchpad this week — here's what it looked like from the ground: 🪐 Held hundreds of conversations at Booth #5335 about what it actually takes to govern AI agents, not just deploy them. 🪐 Launched AI Agent Governance in Limited Availability, giving enterprises real-time discovery, monitoring, and control over the agents already running in their environment. 🪐 Made the case that the lessons that have stuck with us through life are the same ones the enterprise needs now for agentic AI. Until next time. 🧑🚀
-
-
This is your brain. This is your brain on drugs. 🍳 Four words, an egg and a hot pan did more convincing than most ad campaigns manage in thirty seconds — because it wasn't an argument, it was just the same thing shown twice, once whole and once not. These are your AI agents. These are your AI agents without governance. Same agents. Same tasks. The difference is whether every action they take is watched, policed, and provable — or found out about later, in an audit, in an incident report, in a headline. AI Agent Governance. Outcomes you can measure. Any questions? https://okt.to/P7NlFw
-
The bigger AI agent risk may not be someone else’s agent. It may be your own. We’re calling it the Insider Agent Threat: when an agent inside your environment pursues the goal it was given, finds a path it was never meant to use, and touches systems or data it should never reach. No attacker required. That’s what makes this category different from a traditional intrusion story. The agent can look “successful” while still bypassing process, abusing inherited access, and leaving your team unable to answer a basic question later: what did it touch, and where did that data go? 🔷 Agents inherit privileges, but not judgment. 🔷 They don’t get tired. 🔷 They move at machine speed. That’s why governance has to happen before the action executes, not after. Our CEO Adam Markowitz covers that in more depth here, along with a closer look at AI Agent Governance, now in Limited Availability: https://okt.to/ub2ZwE
-
-
The More You Know. 🌠 For over three decades, that shooting star closed out a plain fact and got out of the way — no pitch, just information on the theory that people act differently once they actually know something. Here's a fact: 33% of IT and security professionals say AI adoption is moving faster than their organization's ability to govern or monitor it — and that number climbs to 40% at companies over 2,500 employees. The bigger you are, the wider the gap tends to run. The More You See. Discover your sprawl with Drata AI Agent Governance — a real inventory of what's running, not an estimate. https://okt.to/G2UgWR
-
-
Big news from mission control yesterday: Drata AI Agent Governance is now in Limited Availability, giving enterprises a way to discover, monitor, and govern the AI agents already running inside their walls. Our Dratanauts are still at booth #5335 at Black Hat Las Vegas, walking through AI Agent Governance live, along with everything else powering our Agentic Trust Management Platform. Come see what continuous control monitoring looks like when it's built for agents, not just humans. 👽
-