Founded Year

2020

Stage

Series C | Alive

Total Raised

$328.2M

Valuation

$0000 

Last Raised

$200M | 3 yrs ago

Mosaic Score
The Mosaic Score is an algorithm that measures the overall financial health and market potential of private companies.

-5 points in the past 30 days

About Drata

Drata is a security and compliance automation platform that specializes in streamlining audit readiness and maintaining compliance across various frameworks. The company offers solutions for continuous control monitoring, automated evidence collection, and workflow optimization to ensure companies are audit-ready. Drata's platform is designed to serve startups, growth-stage companies, and enterprises by providing scalable compliance automation tools and support for custom frameworks. It was founded in 2020 and is based in San Diego, California.

Headquarters Location

4660 La Jolla Village Drive Suite 100

San Diego, California, 92122,

United States

858-754-8811

Loading...

Drata's Product Videos

ESPs containing Drata

The ESP matrix leverages data and analyst insight to identify and rank leading companies in a given technology landscape.

EXECUTION STRENGTH ➡MARKET STRENGTH ➡LEADERHIGHFLIEROUTPERFORMERCHALLENGER
Enterprise Tech / Cybersecurity

The third-party vendor risk management market, or TPRM, helps organizations assess and manage risks associated with third-party vendors. Solutions automate vendor risk assessments and provide continuous monitoring of supplier security. These platforms typically include questionnaire management, security posture scoring, and workflow automation tools.

Drata named as Highflier among 15 other companies, including SecurityScorecard, AuditBoard, and MetricStream.

Drata's Products & Differentiators

    Frameworks - Continuous Compliance Automation

    Drata automates compliance operations and evidence collection with security monitoring integrations across your SaaS services. Gain visibility into your compliance status, control across your security program, and build a single picture of controls, people, devices, applications, vendors, and risk across your company. Currently, Drata automates SOC 2, ISO 27001, PCI DSS, GDPR, HIPAA, & CCPA The Fastest & Smartest Way to Achieve Continuous SOC 2 Compliance

Loading...

Research containing Drata

Get data-driven expert analysis from the CB Insights Intelligence Unit.

CB Insights Intelligence Analysts have mentioned Drata in 1 CB Insights research brief, most recently on Feb 25, 2025.

Expert Collections containing Drata

Expert Collections are analyst-curated lists that highlight the companies you need to know in the most important technology spaces.

Drata is included in 2 Expert Collections, including Unicorns- Billion Dollar Startups.

U

Unicorns- Billion Dollar Startups

1,256 items

C

Cybersecurity

10,918 items

These companies protect organizations from digital threats.

Drata Patents

Drata has filed 1 patent.

The 3 most popular patent topics include:

  • computer memory
  • computer security
  • data management
patents chart

Application Date

Grant Date

Title

Related Topics

Status

8/29/2022

10/1/2024

Computer memory, Operating system security, Computer security, Networking hardware, Data management

Grant

Application Date

8/29/2022

Grant Date

10/1/2024

Title

Related Topics

Computer memory, Operating system security, Computer security, Networking hardware, Data management

Status

Grant

Latest Drata News

Drata and AWS Collaborate on Trust Center Test Integration to Accelerate Software Security Reviews in AWS Marketplace

Jun 11, 2025

News provided by Share this article The pilot program allows faster, more transparent procurement for cloud software buyers SAN DIEGO, June 11, 2025 /PRNewswire/ -- Drata , the leader in AI-native Trust Management, today announced its collaboration with Amazon Web Services (AWS) to support a new test integration in AWS Marketplace. The initiative allows participating Independent Software Vendors (ISVs) to showcase their security and compliance postures through their Drata-powered Trust Centers, directly embedded into their product listings in AWS Marketplace. This allows buyers to evaluate vendor risk with greater confidence and speed, reducing procurement friction and reinforcing trust at the point of sale. With cloud-based solutions now central to modern enterprise tech stacks, organizations face mounting pressure to validate vendor security and regulatory compliance. This pilot program—powered by Drata's AI-native Trust Management platform—meets that need by allowing ISVs to share real-time Governance, Risk, and Compliance (GRC) data, framework adherence, and security documentation directly within their listings. More than 50 Drata customers who are AWS Marketplace Sellers—including Abnormal AI, Obsidian Security, Tealium, and Sigma Computing—have listed their Trust Centers in AWS Marketplace, offering an enhanced level of transparency to their prospective buyers. Participating listings now provide direct access to each vendor's Trust Center, streamlining security reviews and empowering procurement teams with verified compliance data at the point of decision. "As a cloud-first organization, integrating Obsidian Security's Trust Center directly into our AWS Marketplace listing empowers us to proactively showcase our security posture and compliance certifications where buyers are already making decisions," said Alfredo Hickman, CISO, Obsidian Security. "This level of transparency not only speeds up procurement but also builds instant trust with customers." "Trust is the foundation of every successful business relationship, and we're proud to work alongside AWS to make trust more visible and accessible across the software ecosystem," said Kevin Kriebel, SVP of Business Development at Drata. "As the first GRC provider participating in this test, we're delivering a first-of-its-kind buyer experience that brings trust signals to the point of sale." To explore a live Trust Center, visit a participating listing in AWS Marketplace (e.g., Abnormal AI, Obsidian Security, Tealium, and Sigma Computing), or learn more at: try.drata.com/aws . About Drata Drata is the trust layer between great companies and those they do business with. Over 7,500 organizations globally, including over a third of the Cloud 100, use Drata to automate governance, risk, compliance, and assurance resulting in a strong security posture, streamlined security reviews, lower costs, and less time spent preparing for audits. The company is backed by ICONIQ Growth, Notable Capital, Alkeon Capital, Salesforce Ventures, and other leading investors. For more information, visit   drata.com . Media Contact

Drata Frequently Asked Questions (FAQ)

  • When was Drata founded?

    Drata was founded in 2020.

  • Where is Drata's headquarters?

    Drata's headquarters is located at 4660 La Jolla Village Drive, San Diego.

  • What is Drata's latest funding round?

    Drata's latest funding round is Series C.

  • How much did Drata raise?

    Drata raised a total of $328.2M.

  • Who are the investors of Drata?

    Investors of Drata include Cowboy Ventures, Notable Capital, Salesforce Ventures, Alkeon Capital Management, Silicon Valley CISO Investments and 13 more.

  • Who are Drata's competitors?

    Competitors of Drata include Trava, Cynomi, Anecdotes, SafeBase, Convercent and 7 more.

  • What products does Drata offer?

    Drata's products include Frameworks - Continuous Compliance Automation and 1 more.

  • Who are Drata's customers?

    Customers of Drata include Lemonade.

Loading...

Compare Drata to Competitors

Vanta Logo
Vanta

Vanta provides a trust management platform for compliance processes, governance, risk management, and vendor risk management. It serves various business sectors including startups, mid-market companies, and enterprises. It was founded in 2018 and is based in San Francisco, California.

T
Thoropass

Thoropass specializes in end-to-end compliance solutions within the information security and data privacy sectors. The company offers services such as achieving and maintaining compliance, automating compliance processes, conducting security audits, and providing integrations for various compliance frameworks. Thoropass primarily serves sectors such as health technology and finance technology. Thoropass was formerly known as Laika. It was founded in 2019 and is based in New York, New York.

S
Secureframe

Secureframe is a company that specializes in compliance and risk management within the cybersecurity sector. They offer a compliance platform that focuses on evidence collection, monitoring, and risk management to assist businesses in adhering to security and privacy standards. Secureframe serves sectors that have compliance requirements, including healthcare, finance, and technology. It was founded in 2020 and is based in San Francisco, California.

S
Sprinto

Sprinto specializes in security compliance automation for tech companies, operating within the information security and compliance domain. The company offers a platform that automates the monitoring of compliance frameworks, facilitates audit readiness, and manages risk. Sprinto's platform is designed to integrate with cloud services, providing automated evidence collection, vulnerability assessments, and access control management to ensure robust security compliance. It was founded in 2020 and is based in Bangalore, India.

Hyperproof Logo
Hyperproof

Hyperproof operates in the security assurance and compliance operations sector. The company provides a platform that centralizes compliance, offering tools for compliance and audit management, as well as integrations with task management tools. Hyperproof serves sectors that require compliance frameworks, including healthcare, technology, and fintech. It was founded in 2018 and is based in Bellevue, Washington.

H
Hicomply

Hicomply specializes in information security management systems within the data security and compliance sector. The company offers a software platform that facilitates the building, automation, and management of an ISMS, helping businesses adhere to regulatory standards like ISO 27001, SOC 2, and GDPR. Hicomply's platform serves various sectors that require stringent information security and compliance solutions. It was founded in 2019 and is based in Durham, England.

Loading...

CBI websites generally use certain cookies to enable better interactions with our sites and services. Use of these cookies, which may be stored on your device, permits us to improve and customize your experience. You can read more about your cookie choices at our privacy policy here. By continuing to use this site you are consenting to these choices.