Drata
AI-powered continuous compliance automation and GRC platform (SOC 2, ISO 27001, HIPAA) with fully quote-based, sales-led pricing.
Last verified:
Drata is a privately held compliance-automation and trust-management platform founded in 2020 by Adam Markowitz, Daniel Marashlian, and Troy Markowitz, headquartered in San Francisco with additional offices in San Diego, New York, London, and Sydney. It continuously monitors 100+ security controls and automates evidence collection across frameworks like SOC 2, ISO 27001, HIPAA, GDPR, and PCI DSS, plus a Trust Center product for sharing security posture with prospects. All pricing is quote-based: the public pricing page lists no tiers or dollar amounts, only "Get a Demo"/"Contact Sales" calls to action, and the marketing site's robots.txt and llms.txt are both gated behind a Cloudflare bot challenge. Drata does publish a REST APIv2 with an OpenAPI reference and, as of 2026, an official but experimental cloud-hosted "Drata MCP" server for AI agents to summarize failed tests and generate compliance/risk reports.
Pricing
| Tier | Price | Key features |
|---|---|---|
| Custom (Contact Sales) | Custom | Continuous control monitoring, Automated evidence collection, Framework mapping (SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, etc.), Trust Center, Drata MCP (early access) |
Source: https://drata.com/pricing
Agent-readiness
- Discoverability
- 15/100
- Machine-readable content
- 30/100
- Programmatic access
- 55/100
- MCP / agent support
- 55/100
- Self-serve transactability
- 5/100
- Transparency
- 40/100
Security & compliance
- SSO / SAML
- Yes
- Encryption at rest
- Yes
- Encryption in transit
- Yes
- Audit log
- Yes
- Pentest report
- Not publicly documented
"Not publicly documented" means Crail found no public evidence either way — not a confirmed absence. See our methodology. Trust center: https://trust.drata.com/.
FAQ
Does Drata have a free tier?
No — Drata does not offer a free tier as of 2026-07-26.
Can you buy Drata without talking to sales?
No — Drata requires a sales call to purchase.
Does Drata have an official MCP (Model Context Protocol) server?
Yes, Drata publishes an official MCP server (https://drata.com/blog/drata-mcp-built-for-ai-native-trust-management).
What compliance certifications does Drata hold?
Drata holds: SOC 2 Type 2, ISO/IEC 27001:2022, HIPAA, GDPR, CCPA.
Reviews
No reviews yet for Drata. Be the first to submit a verified review.
Methodology & disclosure
Data verified via agent crawled, last checked 2026-07-26. Agent-readiness methodology version crail-ar-v0.1. No vendor payment influences these scores — see our methodology page.