Back to vendors
D

Drata

Also known as: Drata AI Agent Governance, Agentic Trust Management Platform, Drata GRC+A

Visit site
Entry priceContact sales; third party reported range 7,500 to 100,000 USD per yearFull pricing detail

Compliance automation turned agent governance: inline sensors inventory every agent including shadow ones, evaluate each action against its own policy in real time, and block violations before execution.

Drata began as compliance automation and has moved decisively into governing agents themselves. On 10 June 2026 it declared AI Agent Governance a new enterprise security category, and on 4 August 2026 it announced limited availability, with early access customers already running it in production.

The mechanism is unusually concrete for this category. Inline sensors find every agent created by every employee in the environment, including shadow agents nobody registered, and return a full inventory within minutes mapping each agent to its owner, identity, permissions and scope. Every action is then evaluated against that agent individual policy in real time, and violations are blocked inline before execution rather than flagged afterwards. Drift is caught and reported. Every decision lands in a tamper evident record that serves as one verified evidence trail for the board, auditors, customers and regulators.

Two design choices stand out. Policy is written in plain English and translated into machine enforceable rules, so the people who own the policy can author it. And customers can test a policy against up to a year of historical traffic before switching enforcement on in production, which lets them see what would have been blocked before anything is.

The product ships first and deepest for Anthropic based agents, and connects to the same controls and evidence logic Drata already uses for the EU AI Act, AIUC-1 and ISO 42001.

The honest limit, argued by a competitor but structurally sound, is scope: this governs the agents an organisation builds and operates. It does not govern what an employee types into a frontier model in a browser tab, which is a different problem solved at a different layer.

Vendor details

Canonical URL

https://drata.com

Category

Security / SOC agent

Subcategory

AI agent governance and agentic trust management

Funding status

Private, San Francisco. CEO Adam Markowitz. Reported to serve more than 8,500 organisations worldwide.

Company status

independent

Use cases & customers

Primary use cases

discovering shadow AI agents across the enterprisereal time policy enforcement on agent actions before executiontamper evident evidence trails for auditors and regulatorscontinuous compliance automation across frameworksEU AI Act and ISO 42001 readiness

Target customers

enterprise security teamsmid-marketorganisations subject to the EU AI Actcompanies deploying agents at scaleregulated industries

Deployment options

SaaS cloud

Integrations

Inline sensors deploy into the customer environment to intercept agent traffic rather than polling APIs, which is what allows enforcement before execution. AI Agent Governance ships first and deepest for Anthropic based agents. The underlying compliance platform integrates broadly across cloud infrastructure for automated evidence collection, with control mapping reused across frameworks.

In practice

A security team integrates the sensors and gets a full inventory of every agent an employee has created, including ones nobody registered, mapped to owner, identity, permissions and scope within minutes.

A compliance lead writes an agent policy in plain English, tests it against a year of historical traffic to see exactly what would have been blocked, then switches enforcement on with no surprises.

An organisation preparing for EU AI Act enforcement produces a tamper evident record of every agent decision as a single evidence trail for auditors and regulators.

Agentic Index coverage score

10.5 / 14 capabilities · 75%

Integrations & Tool CallingINLINE SENSORS deploy into the customer environment and intercept agent traffic directly rather than polling APIs, which is what makes pre execution enforcement possible; AI Agent Governance ships first and deepest for Anthropic based agents, and the underlying platform integrates broadly across the customer stack for automated evidence collection. Drata AI Agent Governance launch and platform pages 2026-08-07 Full
Workflow OrchestrationAutonomous AI agents automate compliance work across control mapping, evidence collection, monitoring and remediation sequencing, and AI Agent Governance runs a three stage discover, monitor and govern pipeline over the agent estate. Drata platform pages and AI Agent Governance launch 2026-08-07 Full
Knowledge Grounding & RAGControls, risks, policies and evidence are unified in one system with map once reuse everywhere cross framework mapping, and the agent inventory grounds enforcement by mapping each agent to its owner, identity, permissions and scope. Platform data spans 2.1 million security questions analysed over nine months. Drata platform pages and launch materials 2026-08-07 Full
Human Oversight & GuardrailsTHE STRONGEST OVERSIGHT MECHANISM GRADED IN THIS INDEX: every action is evaluated against that agent's INDIVIDUAL policy in real time and VIOLATIONS ARE BLOCKED INLINE BEFORE EXECUTION rather than flagged afterwards. Policy is authored in plain English and translated to machine enforceable rules, and the mode is configurable - Drata can recommend actions for human approval or enforce automatically where the customer permits. Drata AI Agent Governance launch and trade coverage 2026-08-07 Full
Security, Identity & GovernanceNOT RETRIEVED AND ALMOST CERTAINLY AN UNDERGRADE - FLAGGED FOR CORRECTION. Drata sells compliance automation to 8,500 organisations so its own attestations certainly exist, but none were retrieved in this pass. SIXTH instance of the Sec paradox after conveyor, wolfia, anvilogic, arctic-wolf and vanta. Check trust.drata.com directly and correct. Drata public sources 2026-08-07 Partial
Observability & AuditabilityInline sensors return a full agent inventory within minutes including SHADOW AGENTS nobody registered, mapping each to owner, identity, permissions and scope, and every decision is logged in a TAMPER EVIDENT record providing a single verified evidence trail for the board, auditors, customers and regulators. Discovery plus tamper evidence is a stronger combination than either alone. Drata AI Agent Governance launch 2026-08-07 Full
Memory & State PersistenceA tamper evident record persists every agent decision as a durable evidence trail, and up to a year of historical traffic is retained for policy backtesting, but this is an audit and evidence store rather than an agent memory or learned context layer. Same shape as the vanta and airtable rulings. Drata AI Agent Governance launch 2026-08-07 Partial
Deployment & Data ResidencyCloud SaaS with inline sensors deployed into the customer environment, which places interception locally, but no self hosting option, government cloud or published residency matrix was retrieved in this pass. Drata public sources 2026-08-07 Partial
Prebuilt Agents, Templates & PacksShips packaged framework coverage with prebuilt controls and automated cross framework mapping, and AI Agent Governance reuses the same controls and evidence logic for the EU AI Act, AIUC-1 and ISO 42001 rather than requiring a separate programme. Drata platform pages and launch coverage 2026-08-07 Full
Triggers & Channel CoverageEvery agent action is evaluated in real time as it happens, with drift caught and flagged immediately, alongside continuous control monitoring across the compliance platform. The trigger surface is the agent traffic itself, intercepted inline. Drata AI Agent Governance launch 2026-08-07 Full
Model Flexibility & RoutingAI Agent Governance ships FIRST AND DEEPEST FOR ANTHROPIC based agents, which indicates provider specific depth with broader coverage implied but unstated, and no model selection or routing capability for Drata's own agents was documented. Drata AI Agent Governance limited availability announcement 2026-08-07 Partial
APIs, SDKs & MCP ExtensibilityInline sensors and broad platform integrations imply a programmable surface, and policy authored in plain English is translated into machine enforceable rules which is itself an extension mechanism, but no public API reference, SDK family or MCP support was retrieved. Drata platform and launch materials 2026-08-07 Partial
Testing, Debugging & OptimizationCustomers can TEST POLICIES AGAINST UP TO A YEAR OF HISTORICAL TRAFFIC before turning enforcement on in production, so the buyer sees exactly what would have been blocked against their own past data before anything is. That is a genuine backtest, the same shape as charta-health's retrospective evaluation, and it is rare in this index. Drata AI Agent Governance limited availability coverage 2026-08-07 Full
Browser & Computer UseOperates on agent traffic and evidence collection through sensors and integrations; no browser control, page navigation or computer use capability exists. Notably a competitor argues this is the boundary of the product - it cannot see a human typing into a frontier model in a browser tab. Drata product documentation and competitor analysis 2026-08-07 Unable to verify

The Agentic Index coverage score grades every vendor Full, Partial or Unable to verify against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Pricing

Contact sales; third party reported range 7,500 to 100,000 USD per year

framework count and company size, agent governance pricing undisclosed

Included quota

Not published.

What is public

Nothing. All figures in this record are third party reported, several from sources that compete with Drata.

Billing mechanics

Not publicly disclosed. Annual subscription scaled by company size and framework count, sold through direct enterprise sales.

Cost watchouts

**THE CATEGORY TRUTH APPLIES HERE TOO: no compliance platform can issue its own attestation, so an independent audit firm fee sits on top of the software and buyers who budget only the platform fee are reported to underestimate total compliance cost by 30 to 50 percent.** Beyond that, AI Agent Governance is a new product in limited availability, so whether it is bundled, a separate SKU, or priced by agent count is unknown - and agent count is the fastest growing quantity in the estate, exactly the exposure flagged on okta and cyberark. Framework add ons remain separate lines even at the lower Drata rate.

Variable cost rationale

Nothing is published, framework count and company size both drive the base, and the differentiating product reached limited availability days before this record with no pricing model disclosed at all. If AI Agent Governance meters by agent or by action, exposure tracks the fastest growing population in the enterprise. The independent audit fee sits outside the platform regardless.

Additional watchouts

Establish how AI Agent Governance is metered before committing, since it is the differentiating capability and its unit is undisclosed. If it prices by agent count, model it against expected agent growth rather than today's inventory.

Overage / add-ons

Not published.

Sales call required

Yes, required for paid access

Free / trial

None retrieved

Commercial notes

**THE PER FRAMEWORK RATE IS THE REAL DIFFERENTIATOR AGAINST VANTA AND IS WORTH A VS PAGE: Drata reported at 1,500 to 3,000 USD per additional framework against Vanta at 5,000 plus. Over a three framework programme that gap compounds. Both figures are third party, and note that several sources reporting them are competitors of both.** Drata reports serving more than 8,500 organisations.

Key ambiguities

How AI Agent Governance is licensed. It reached limited availability on 4 August 2026 with no pricing disclosed, and whether it meters by agent, by action, by seat or as a flat module is the single most important unknown given it is the reason to buy Drata over a pure compliance tool.

Missing data

All vendor confirmed pricing, and specifically the licensing model for AI Agent Governance.

Agentic Index verified 2026-08-07

Alternatives to Drata

The closest documented capability profiles to Drata among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Abnormal AI9.0 / 14A lighter documented profile than Drata
  • Arctic Wolf9.0 / 14A lighter documented profile than Drata
  • Crogl10.0 / 14Fuller documented coverage on Deployment & Data Residency
  • Darktrace9.0 / 14A lighter documented profile than Drata
  • depthfirst11.0 / 14Fuller documented coverage on Security, Identity & Governance and Memory & State Persistence
  • Palo Alto Networks11.0 / 14Fuller documented coverage on Security, Identity & Governance and APIs, SDKs & MCP Extensibility

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.