Try our new research platform with insights from 80,000+ expert users
reviewer2518548 - PeerSpot reviewer
Senior Staff Auditor at a financial services firm with 51-200 employees
Real User
Top 20
Aug 6, 2024
User-friendly and supports SAST and HIPAA frameworks
Pros and Cons
  • "The way the tool's controls are linked to the framework, specifically with SAST and HIPAA frameworks or any other frameworks, is really good."
  • "The thing with Drata is you cannot open multiple tabs on the same interface or the same desktop,"

What is our primary use case?

I use Drata from the auditor's end. I am an information security auditor for companies that provide SaaS and PaaS-based services, and that would be more concentrated on the US SaaS and PaaS-based companies. I use Drata to check and comment on my client's internal security controls, their operative effectiveness, and how they are upholding their security standards.

What is most valuable?

Drata's DCF mapping is really good. The way the tool's controls are linked to the framework, specifically with SAST and HIPAA frameworks or any other frameworks, is really good. Basically, when I look into a control, the control's particular DCF number gives me all the information about the automated tests linked to that control, and then the external evidence that the client provides to me for verification and review is also available in one place. Drata's Audit Hub is useful for communicating with the client, and it is also a really good place where the client can feel safe sharing sensitive information for audits as it is a protected platform.

What needs improvement?

For a particular control, such as vulnerability scans, we mostly have clients provide us with external third-party reports of scans. Drata could have something in place for real-time monitoring so that we could actually see the vulnerabilities directly instead of requesting external vulnerability scans for the platforms or cloud containers one uses.

The thing with Drata is you cannot open multiple tabs on the same interface or the same desktop. When you come out of Drata's Audit Hub, you will have to go back into the client interface and then return to another request. There is a lot of time-consuming activity happening in the tool. When I come out of Drata's Audit Hub, I would like to go to the previous phase I visited without being completely kicked out of the interface.

For how long have I used the solution?

I have been using Drata since September 2022. My firm has a partnership with Drata, but I am unsure about it.

Buyer's Guide
Drata
March 2026
Learn what your peers think about Drata. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.

What do I think about the stability of the solution?

In terms of stability, the product has been very smooth. Stability-wise, I rate the solution an eight out of ten.

What do I think about the scalability of the solution?

It is a scalable solution. As far as just seeing the other compliances are concerned in the tool, and since it is not the only compliance tool I use for auditing, I can say that when I compare tools, Drata is fine.


How are customer service and support?

I would not want to talk about my experience with the product's support team extensively, but I can give the technical support a rating of six out of ten. There was a time during the initial stages of my work when I found a lot of data to convert into PDFs or download in an Excel format, and a lot of metadata was coming out. When I reached out to Drata's support team, they said the metadata that was coming out was not their issue but something from my end. The issue eventually vanished, but it was never fixed. I stopped seeing the heavy data again on my interface, but it was never properly received by the tool's support team. I only had one such customer support requirement.

I rate the technical support a six or seven out of ten.

Which solution did I use previously and why did I switch?

I have experience with multiple compliance platforms like Vanta and Secureframe.

How was the initial setup?

With the product's initial setup phase, I honestly faced some issues while the clients gave us auditors access to set up cards or read-only access. I have seen a lot of back and forth for multiple clients, and even though the clients tell us that they have given us access, we don't receive it. We don't get Drata's invitation sometimes. I think there is a bit of work, but it is not difficult. It is easy to use the tool to log in to your work emails or Google, but I found some errors in the auditor assignments and access assignments.

What other advice do I have?

In terms of security posture management, as far as I am exposed to Drata, I can say that the tool has some automated tests. The autopilot feature in the tool is really helpful for verifying things, and the client's data is in sync with Drata. The tool has continuous monitoring and it provides me with real-time data on every aspect of the firm's internal security, which is also an add-on.

The tool is really user-friendly. I believe there is always room for improvement.

I do not work on integration processes. We actually have a dedicated team for it, and my team focuses only on testing.

I recommend the product to those who plan to use it since it is a seamless and easy tool to use.

I think going with what is on the interface to view could be the best thing to know more, explore more, and get to the things you want to get to.

I rate the tool an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
BhupendraSharma - PeerSpot reviewer
Cloud and DevOps Engineer at Betaque
Real User
Nov 19, 2023
A comprehensive solution to reduce vulnerabilities and address loopholes in the infrastructure
Pros and Cons
    • "The solution is quite costly."

    What is our primary use case?

    I was working on a project that required using ROC tools and SOC 2 compliance. To address this, we integrated with the Drata tool to reduce vulnerabilities in the infrastructure and address other loopholes. Additionally, Drata seamlessly integrated with our cloud services, including SysTrack S3 and other key creation and GuardDuty services.

    Drata can identify loopholes and provide solutions for improved security. Drata secures the organisation's infrastructure, achieve SOC 2 compliance, and address HIPAA requirements. It can identify and close security loopholes proactively.

    What is most valuable?

    Drata is a comprehensive and informative tool that provides in-depth guidance on how to protect your infrastructure. However, it is also quite expensive and requires restarting if any loopholes are available.

    What needs improvement?

    The solution has a latency of three to five minutes. Also, the solution is quite costly.

    For how long have I used the solution?

    I have been using Drata as a customer for eight to nine months.

    What do I think about the stability of the solution?

    The product is stable.

    I rate the solution’s stability a nine-point five out of ten.

    What do I think about the scalability of the solution?

    We were six guys using this product.

    I rate the solution’s scalability a nine-point five out of ten.

    Which solution did I use previously and why did I switch?

    We used Drata only because it is popular. Also, the organization supports the use of Drata for SOC 2 compliance.

    How was the initial setup?

    The initial setup is straightforward and user-friendly, making it accessible to anyone. If a guy starts the journey in security, this tool will help. He can quickly pick up the entire information if he has extensive knowledge about cloud services. He needs to follow the steps to use the whole infrastructure.

    What other advice do I have?

    It would be helpful if the solution could provide screenshots to illustrate the steps outlined. Additionally, provide a day-by-day breakdown of the tasks, addressing potential loopholes that users may encounter. For instance, if we need to address three buckets, we could tackle each bucket one day at a time. This approach would make the process less overwhelming and more manageable. Drata provides steps on how to handle low falls. To do this, you need to turn certain options on or off. You can also edit or track these points. Additionally, you can include screenshots and highlight specific areas of interest.

    Overall, I rate the solution a nine-point five out of ten.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free Drata Report and get advice and tips from experienced pros sharing their opinions.
    Updated: March 2026
    Product Categories
    Compliance Management
    Buyer's Guide
    Download our free Drata Report and get advice and tips from experienced pros sharing their opinions.