What Drata publishes about its security, privacy and use of your data, with a link to the page each fact came from. Checked October 10, 2026.
"Not found" means our reader didn't find it on the public pages it could read; the vendor may still publish it.
Statements differ between pages
Drata's own words (drata.com/responsible-ai):
By default, Drata does not use Customer Data to train shared or general-purpose AI models or models used to provide services to other customers.
Vendors often have different rules for consumer or free plans and for business or enterprise plans. Check the terms for the plan you would use.
If a customer expressly authorizes Drata to use its Customer Data to train or customize a tenant-specific model, Drata limits that use to the customer’s authorized purpose and applies appropriate safeguards, which may include data minimization, access restrictions, data saniti…
drata.com/responsible-ai
Different pages say different things. This is often a split between business plans and free or consumer plans. Read each quote for the plan you would use.
| Certification or report | Mentioned on |
|---|---|
| SOC 2 | drata.com |
| SOC 1 | drata.com |
| ISO/IEC 27001 | drata.com |
| ISO/IEC 42001 | drata.com |
| HIPAA | drata.com |
| PCI DSS | drata.com |
| FedRAMP | drata.com |
| HITRUST | drata.com |
Privacy laws and frameworks mentioned: GDPR. These are laws the vendor says it follows, not certifications.
A certification on a website is a claim. For anything sensitive, ask Drata for the SOC 2 report or ISO certificate.
Our reader didn't find a subprocessor list on Drata's public pages. It may be published somewhere we couldn't reach, such as a trust portal that needs JavaScript or a login. Ask Drata for it if you need it.
| SSO / SAML | Not found |
| SCIM provisioning | Not found |
| Multi-factor authentication | Not found |
| Encryption at rest | Not found |
| Encryption in transit | Not found |
| Penetration testing | Not found |
| Bug bounty / disclosure program | Not found |
| Audit logs | Not found |
| Data residency | Not found |
| security.txt contact | Not found |
| Trust / security center | drata.com/products/compliance-automation |
| Privacy policy | drata.com/privacy |
| Subprocessor list | Not found |
| Data processing agreement (DPA) | drata.com/data-processing-addendum |
| AI policy | drata.com/responsible-ai |
| Terms | Not found |
| Status page | status.drata.com |
| Check | Points | Result |
|---|---|---|
| Security or trust page | 15 | Yes |
| Certifications listed | 20 | Yes |
| Privacy policy | 10 | Yes |
| Subprocessor list | 15 | No |
| DPA available | 10 | Yes |
| AI training policy stated | 15 | Yes |
| security.txt contact | 5 | No |
| Status page | 10 | Yes |
The score measures how much of a standard security review our reader could answer from Drata's public pages. It is not a rating of how secure Drata is, and a "No" can mean the document exists where our reader couldn't see it.
Get the same profile for any vendor in seconds, or let your AI agent do it with Stormap's free MCP server.
1Password · Abnormal Security · Bitwarden · CrowdStrike · Duo · Jamf · JumpCloud · Kandji · KnowBe4 · LastPass · Okta · Proofpoint
Source: Drata's own public website (6 pages read on October 10, 2026). Stormap is not affiliated with Drata. Facts are what the vendor publishes about itself; certifications are claims, not verified audit reports. Something wrong or out of date? Pages are re-checked every two weeks.