Drata
Also known as: Drata AI Agent Governance, Drata GRC+A
Trust management platform with its own compliance agents and AI Agent Governance: a Sensor and MCP Proxy inventory agents and evaluate each tool call, block violations inline, route recommended actions for approval, and keep a tamper-evident evidence feed; public API and MCP server in US, EU and APAC.
Drata is a trust management platform that began in compliance automation and now also governs AI agents. The compliance platform unifies controls, evidence, risks and policies across 30+ frameworks (SOC 2, ISO 27001, ISO 42001, GDPR, the EU AI Act, AIUC-1 and others) and connects to hundreds of tools for evidence collection.
Drata ships agents of its own: the Agentic TPRM Assessment agent retrieves vendor documents, evaluates them against the customer's criteria, generates follow-up questions and corresponds with vendors, and the AI Questionnaire agent answers security questionnaires from the customer's Knowledge Base, Trust Center content and an answer library, with human review before responses are final.
AI Agent Governance, in limited availability since August 2026, discovers every AI agent in the environment, including shadow agents, through the Drata Sensor on managed devices and an MCP Proxy that evaluates each tool call against policy; violations are blocked inline, drift is flagged as it happens, and recommended actions go to a person for approval or, where authorized, are enforced automatically. Policies are written as plain-English intent, can be simulated against a year of historical traffic, and advance through a Trust Ladder from Training to Recommendation to Active.
Telemetry flows into a tamper-evident evidence feed. Full coverage ships for Anthropic agents, with OpenAI, Google Vertex AI and AWS Bedrock in development. A public API v2 and a generally available MCP server with 35+ tools run in US, EU and APAC regions.
Vendor details
Canonical URL
https://drata.com
Category
Security / SOC agent
Subcategory
AI agent governance and agentic trust management
Funding status
Private, San Francisco. CEO Adam Markowitz. Reported to serve more than 8,500 organizations worldwide.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
The Drata Sensor watches AI activity on managed devices, including desktop, browser and local-model AI, and the MCP Proxy sits on every agent tool call. Full lifecycle governance ships for Anthropic, with OpenAI, Google Vertex AI and AWS Bedrock in development. The compliance platform connects to hundreds of tools for evidence collection. A public API v2 and an MCP server (Claude, ChatGPT, Cursor, Microsoft Copilot) expose controls, evidence, risks, vendors and policies.
In practice
A security team integrates the sensors and gets a full inventory of every agent an employee has created, including ones nobody registered, mapped to owner, identity, permissions and scope within minutes.
A compliance lead writes an agent policy in plain English, tests it against a year of historical traffic to see exactly what would have been blocked, then switches enforcement on with no surprises.
An organization preparing for EU AI Act enforcement produces a tamper evident record of every agent decision as a single evidence trail for auditors and regulators.
Sources & related URLs
Research sources
Agentic Index coverage score
10.5 / 14 capabilities · 75%
| Integrations & Tool Calling | Full |
|---|---|
|
An MCP Proxy sits where every agent's tool call passes and evaluates each request, the Drata Sensor watches desktop, browser and local-model AI on managed devices, full lifecycle coverage ships for Anthropic with OpenAI, Google Vertex AI and AWS Bedrock in development, and the compliance platform connects to hundreds of tools for evidence collection; the TPRM agent retrieves vendor documents and corresponds with vendors. Sourcedrata.com/about/news/drata-extends-trust-management-platform-to-continuously-monitor-and-govern-ai-agentsread 2026-09-28 |
|
| Workflow Orchestration | Full |
|
Drata runs several agents of its own, each carrying out work in several steps: the Agentic TPRM Assessment agent, which retrieves vendor documents, evaluates them, generates follow up questions and corresponds with vendors; the AI Questionnaire agent; and AI Agent Governance. How the agents coordinate is not detailed. Sourcedrata.com/products/airead 2026-09-28 |
|
| Knowledge Grounding & RAG | Full |
|
The questionnaire agent answers from the customer's internal Knowledge Base, its Trust Center content and an answer library built from prior approvals, over a platform that unifies the customer's controls, evidence, risks and policies: a maintained store of the customer's knowledge that the agents draw on. Sourcedrata.com/products/airead 2026-09-28 |
|
| Human Oversight & Guardrails | Full |
|
Governance surfaces "recommended actions for manual approval or, where authorized, enforcing them autonomously", policies advance through a Trust Ladder (Training, Recommendation, Active), and the questionnaire agent's answers are reviewed by a person before they are final. Approval comes before actions commit, and violations on the customer's agents are blocked inline. Sourcedrata.com/about/news/drata-extends-trust-management-platform-to-continuously-monitor-and-govern-ai-agentsread 2026-09-28 |
|
| Security, Identity & Governance | Full |
|
The trust center at trust.drata.com lists SOC 2 Type 2, SOC 3, ISO/IEC 27001:2022, ISO/IEC 42001:2023 and FedRAMP among others, alongside role based access control and MFA. MCP access is limited to the intersection of OAuth scopes and the user's Drata role. Sourcetrust.drata.comread 2026-09-28 |
|
| Observability & Auditability | Full |
|
The MCP Proxy evaluates each agent tool call against policy, monitoring logs every action with a trust score per agent and flags drift as it happens, and on device telemetry flows into a durable, tamper evident evidence feed, so every tool call the customer's agents make leaves a record. Sourcedrata.com/about/news/drata-extends-trust-management-platform-to-continuously-monitor-and-govern-ai-agentsread 2026-09-28 |
|
| Memory & State Persistence | Not documented |
|
The claim that the platform "continuously learns based on human approvals and edits" describes learning, not a memory store with a stated scope. The answer library and Knowledge Base are knowledge the agents draw on, the tamper evident evidence feed is an audit record, and the simulation against historical traffic tests policy, so none of them is agent memory. Sourcedrata.com/products/airead 2026-09-28 |
|
| Deployment & Data Residency | Full |
|
US, EU and APAC deployments with regional endpoints (mcp.drata.com, mcp-euc1.drata.com and mcp-apse2.drata.com; EU and APAC API variants), and data residency across multiple regions listed on the trust center. Sourcedevelopers.drata.com/developer-portal/v2/mcp-serverread 2026-09-28 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
Customers adopt named prebuilt agents (Agentic TPRM Assessment, AI Questionnaire Assistance, AI Agent Governance), each of which keeps doing its own job if another is removed, plus packaged coverage for 30+ frameworks with prebuilt controls. Sourcedrata.com/products/airead 2026-09-28 |
|
| Triggers & Channel Coverage | Full |
|
The MCP Proxy evaluates each tool call as it passes, violations are blocked inline before execution, and drift (OAuth expansion, API changes, behavior outside scope) is flagged as it happens, so work starts on events with no user launching it. Sourcedrata.com/products/agent-governanceread 2026-09-28 |
|
| Model Flexibility & Routing | Not documented |
|
No provider, model choice or routing is named for Drata's own agents. Anthropic, OpenAI, Vertex AI and Bedrock appear as platforms whose agents Drata governs, and Claude or ChatGPT can reach Drata through its MCP server, but neither describes the models Drata's agents run on. Sourcedrata.com/products/airead 2026-09-28 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
Public API v2 at public-api.drata.com with bearer API keys, cursor pagination and resource groups for frameworks, controls, evidence, risks, assets, personnel, vendors, custom data and policies; plus a generally available MCP server at regional endpoints with OAuth and 35+ tools that create, update and delete controls, evidence, risks and vendors. Sourcedevelopers.drata.com/openapi/reference/v2/overviewread 2026-09-28 |
|
| Testing, Debugging & Optimization | Partial |
|
Every policy can be simulated against a year of real historical traffic before enforcement is switched on, and the Trust Ladder moves a policy from Training to Recommendation to Active. That amounts to a dry run of the governance configuration; no red teaming or scored tests of the customer's agents themselves are published. Sourcedrata.com/about/news/drata-extends-trust-management-platform-to-continuously-monitor-and-govern-ai-agentsread 2026-09-28 |
|
| Browser & Computer Use | Not documented |
|
No browser or computer use by Drata's agents; the Sensor observes browser and desktop AI on managed devices, which is monitoring rather than an agent operating an interface. Sourcedrata.com/about/news/drata-extends-trust-management-platform-to-continuously-monitor-and-govern-ai-agentsread 2026-09-28 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
Contact sales
not disclosed
What is public
Nothing on price on the vendor site.
Billing mechanics
Not publicly disclosed; sold through sales.
Cost watchouts
Inference, not stated by the vendor: an independent audit firm's fee for the attestation itself sits outside any compliance platform subscription.
Variable cost rationale
Inference, not stated by the vendor: with no billing unit published, cost depends on scope (frameworks, company size, and how AI Agent Governance is licensed).
Additional watchouts
Establish how AI Agent Governance is metered before committing, since it is in limited availability with no published pricing.
Sales call required
Yes, required for paid access
Free / trial
None retrieved
Key ambiguities
No rate card or billing unit is published, and how AI Agent Governance is licensed (per agent, per action or as a module) is not disclosed.
Missing data
All pricing and the licensing model for AI Agent Governance.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Drata
The closest documented capability profiles to Drata among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Zeron10.5 / 14Matches Drata across all 14 documented capabilities
- Cyware10.0 / 14A lighter documented profile than Drata
- BlinkOps10.5 / 14Adds documented Memory & State Persistence
- SentinelOne10.5 / 14Adds documented Model Flexibility & Routing
- Vanta9.5 / 14A lighter documented profile than Drata
- ContraForce11.0 / 14Adds documented Model Flexibility & Routing
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded