Drata Inc.
Drata's mission is to deliver continuous trust by empowering security teams to automate compliance, manage risk, and demonstrate their security posture. Its platform combines continuous compliance, governance/risk management, and customer assurance, increasingly using agentic AI.
At a Glance
- High-growth startups and technology companies
- Mid-market and global enterprises
- Fortune 100 companies
- Security, compliance, GRC, audit, and risk teams
- +3 more
AI Tools by Drata Inc.
(1)Drata
AI Compliance Automation Platform
Discussions
No discussions yet
Be the first to start a discussion about Drata Inc.
Latest News
Drata published its State of Third-Party Risk Management research based on 309 security leaders.
Drata launched Third-Party Risk Management for defensible, evidence-backed vendor decisions.
Drata published SOC 2, Unfiltered: What the Data Tells Us, a report on SOC 2 adoption and readiness.
CEO Adam Markowitz published The Insider Agent Threat on risks from organizations' own AI agents.
Products & Services
Governance, risk, and compliance workspace that centralizes controls, risks, policies, and evidence and supports multi-framework governance.
Automates evidence collection, control monitoring, framework mapping, remediation, and audit readiness across supported frameworks.
A secure customer-facing hub for sharing security posture and documents, handling trust requests, and accelerating security reviews; expanded through the SafeBase acquisition.
Uses approved trust content and AI to draft consistent responses to customer security questionnaires.
Market Position
Drata positions itself as an integrated Trust Management platform rather than only a point SOC 2 automation tool: it combines continuous compliance, enterprise GRC, internal and third-party risk, AI governance, and customer assurance. Market alternatives and competitors include Vanta, Secureframe, Hyperproof, OneTrust, Sprinto, and Optro (formerly AuditBoard).
Leadership
Founders
Adam Markowitz
Aerospace engineer on NASA's Space Shuttle Program; later co-founded Portfolium with Troy Markowitz and Daniel Marashlian before co-founding Drata. He is Drata's CEO.
Daniel Marashlian
Previously co-founded and built Portfolium with Adam Markowitz and Troy Markowitz; he is Drata's Chief Technology Officer.
Troy Markowitz
Previously co-founded Portfolium with Adam Markowitz and Daniel Marashlian; he is Drata's Chief Operating Officer.
Executive Team
Adam Markowitz
Chief Executive Officer & Co-Founder
Former NASA Space Shuttle Program aerospace engineer and Portfolium co-founder.
Daniel Marashlian
Chief Technology Officer & Co-Founder
Portfolium co-founder; leads Drata technology.
Board of Directors
Founding Story
The founders experienced the burden of security compliance while scaling Portfolium: audit readiness required chasing evidence across tools and teams and consumed hundreds of hours. During 2020, they launched Drata to make SOC 2 and other compliance work continuous and automation-first, creating a trust layer between companies and their customers, auditors, and partners.
Business Model
Revenue Model
B2B SaaS sold through paid platform plans and personalized enterprise pricing; revenue comes from subscriptions to compliance automation, GRC, risk, assurance, and related add-ons, with sales also supported through partners and AWS Marketplace.
Pricing Tiers
Up to 50 FTEs, one pre-mapped framework, pre-built integrations, Trust Center Standard, AI Questionnaire Assistance Standard, risk management, custom controls, compliance as code, and Open API access; add-ons include additional frameworks and user access review.
Everything in Foundation plus any available framework, custom connections and tests, custom fields and formulas; add-ons include Risk Management Pro, workspaces, and custom frameworks.
Everything in Advanced plus Risk Management Pro, Compliance as Code Pro, User Access Review; add-ons include additional frameworks, workspaces, additional custom tests, custom frameworks, and Agentic TPRM Assessment.
Target Markets
- High-growth startups and technology companies
- Mid-market and global enterprises
- Fortune 100 companies
- Security, compliance, GRC, audit, and risk teams
- Regulated industries and companies selling to enterprises
- Companies using or governing AI agents
- SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS, and other compliance programs
- Continuous audit readiness for startups and scaling technology companies
- Enterprise GRC across teams, business units, and multiple frameworks
- Internal, external, and third-party risk management
- AI governance and oversight of enterprise AI agents
- Customer security reviews, trust management, and questionnaire response
- Brex
- Okta
- Calendly
- SmartRecruiters