crail
Security Compliance Automation (GRC)Organic listing

Drata

AI-powered continuous compliance automation and GRC platform (SOC 2, ISO 27001, HIPAA) with fully quote-based, sales-led pricing.

Last verified:

Drata is a privately held compliance-automation and trust-management platform founded in 2020 by Adam Markowitz, Daniel Marashlian, and Troy Markowitz, headquartered in San Francisco with additional offices in San Diego, New York, London, and Sydney. It continuously monitors 100+ security controls and automates evidence collection across frameworks like SOC 2, ISO 27001, HIPAA, GDPR, and PCI DSS, plus a Trust Center product for sharing security posture with prospects. All pricing is quote-based: the public pricing page lists no tiers or dollar amounts, only "Get a Demo"/"Contact Sales" calls to action, and the marketing site's robots.txt and llms.txt are both gated behind a Cloudflare bot challenge. Drata does publish a REST APIv2 with an OpenAPI reference and, as of 2026, an official but experimental cloud-hosted "Drata MCP" server for AI agents to summarize failed tests and generate compliance/risk reports.

Pricing

TierPriceKey features
Custom (Contact Sales)CustomContinuous control monitoring, Automated evidence collection, Framework mapping (SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, etc.), Trust Center, Drata MCP (early access)

Source: https://drata.com/pricing

Agent-readiness

33/100
Discoverability
15/100
Machine-readable content
30/100
Programmatic access
55/100
MCP / agent support
55/100
Self-serve transactability
5/100
Transparency
40/100

Security & compliance

SOC 2 Type 2ISO/IEC 27001:2022HIPAAGDPRCCPA
SSO / SAML
Yes
Encryption at rest
Yes
Encryption in transit
Yes
Audit log
Yes
Pentest report
Not publicly documented

"Not publicly documented" means Crail found no public evidence either way — not a confirmed absence. See our methodology. Trust center: https://trust.drata.com/.

FAQ

Does Drata have a free tier?

No — Drata does not offer a free tier as of 2026-07-26.

Can you buy Drata without talking to sales?

No — Drata requires a sales call to purchase.

Does Drata have an official MCP (Model Context Protocol) server?

Yes, Drata publishes an official MCP server (https://drata.com/blog/drata-mcp-built-for-ai-native-trust-management).

What compliance certifications does Drata hold?

Drata holds: SOC 2 Type 2, ISO/IEC 27001:2022, HIPAA, GDPR, CCPA.

Reviews

No reviews yet for Drata. Be the first to submit a verified review.

Submit a review

Reviews are manually verified before publishing (LinkedIn/corporate-email cross-check) — see our methodology. Submitting does not guarantee publication.

Methodology & disclosure

Data verified via agent crawled, last checked 2026-07-26. Agent-readiness methodology version crail-ar-v0.1. No vendor payment influences these scores — see our methodology page.