Reviews from AWS Marketplace
0 AWS reviews
-
5 star0
-
4 star0
-
3 star0
-
2 star0
-
1 star0
External reviews
External reviews are not included in the AWS star rating for the product.
Excellent ROI. Cut 90% off of our audit effort. Manage risk, vendors, and access reviews, now, too.
What do you like best about the product?
The daily automated evidence collection, great UX (that even auditors understand), and the reduction of our audit effort by 90%, make Drata one of my highest returning investment. We use it every day.
What do you dislike about the product?
There is notihng I dislike, but there are a few boutique integrations I would like Drata to develop.
What problems is the product solving and how is that benefiting you?
The most important problem Drata has solved for us is reducing the effort to do SOX ITGC, SOC2 Type2, and PCI-DSS audits by 90%. Beyond that, Drata has solved most of my evidence collection problem by automating the collection of most evidence. Drata also solved the problem of meaningfully tracking and managing information security risk, somethign that has become a regulatory requirement.
Drata is also solving other problems for us, including access reviews and attestations, and responding to partner information security questionnaires.
Drata is also solving other problems for us, including access reviews and attestations, and responding to partner information security questionnaires.
- Leave a Comment |
- Mark review as helpful
Superb customer support, documentation, and platform
What do you like best about the product?
Drata's customer support and success team has been amazing in helping us achieve compliance across all our efforts. They've been super on top of helping us through both automated and manual outreach efforts. Their documentation and platform have also been AWESOME!
What do you dislike about the product?
Using Drata can be expensive depending on what you are going for (compliance framework wise), so just be mindful of costs! This is true for anything to do with compliance to be honest, goes with the territory.
What problems is the product solving and how is that benefiting you?
SOC2 compliance, GDPR/CCPA compliance
Drata: A great tool for centralized compliance
What do you like best about the product?
Drata centralizes all of our compliance data and allows us to continuously monitor for changes. This saves our compliance team a huge amount of effort in auditing our customer-facing products and IT services. It also helps our technical/operations staff quickly identify and document changes to infrastructure.
What do you dislike about the product?
The user interface can be difficult to use. Some of the test failures are hard to interpret and diagnose, requiring jumps back and forth from Drata app to Drata docs to provider docs to certification/standard definitions, etc.
What problems is the product solving and how is that benefiting you?
It's difficult to monitor and audit the compliance of our infrastructure as it evolves to meet product needs. Drata solves this and pushes us to implement better patterns for infrastructure and software.
Excellent environment for supervising your compliance efforts
What do you like best about the product?
Intuitive UI design and excellent/close customer support
What do you dislike about the product?
The document editor might be more advanced.
What problems is the product solving and how is that benefiting you?
Decreasing the overall burden and required effort to manage compliance processes for multiple standards/frameworks.
Great product
What do you like best about the product?
Compliance certifications can be grueling tasks but Drata simplifies things as much as possible.
What do you dislike about the product?
When we started using Drata, we started using the general SOC2 framework provided by Drata, however when we hired an auditor they brought their own SOC2 framework which was much simpler, it would have been better to know that from the start.
What problems is the product solving and how is that benefiting you?
Drata is helping us simplify compliance, by connecting to our systems and automating compliance controls.
Smooth experience with Drata
What do you like best about the product?
Drata has great customer support - I have reached out to them for help a lot of times and they have always been responsive and extremely helpful. The platform is straightforward and easy to use.
What do you dislike about the product?
I wish they had more integrations. Some of the things we use they don't have automatic integrations yet so I have to manually upload evidence.
What problems is the product solving and how is that benefiting you?
Drata is helping me organize everything we need to get our SOC2 and ISO 27001 compliance certifications done.
SOC 2 Type 2 experience
What do you like best about the product?
Continous monitoring throughout the period that allows you to fix issues as you go and you don't have stress out just before the audit starts.
What do you dislike about the product?
Sometimes the behaviour is not intuitive or consistent accross the product e.g. task view - adds task for expiring evidences that are monitored but that is not always true for resources in settings page e.g. org chart.
I would like to nore distribute the work accross the team but Drata permission model doesn't allow that though that was improved recently.
There was few shakes of trust that happend to us and we were loosing a trust to product little bit:
1. Drata agent - provide false sense of being on checked when we discovered that some HW haven't reported checks for more than 9 months which equals to situation that we hands over the PC and than have no checks
2. During the audit the auditor was claiming that he don't see evidences that were uploaded on quarterly basis which was scary given the fact that we are not backing up evidences uploaded to Drata. Thankfully it was restored with support and provided extra to auditor. But finally we don't know what was a problem as acting via middleman is clumsy. We were instructed with support to raise it that additional training will be provided with auditor. But what I think would be more appropriate and well appriciated would be auditor communicating with drata folks directly either resulting in either additional training or restoring data. The result we got are ok we survived the audit, but I have no clarity whether it was problem with the auditor or with platform and I am afraid it will be repeated next audit.
The features that would be really appriciated and are missing is measuring SLAs for offboarding where a lot of focus is during the audit.
I would like to nore distribute the work accross the team but Drata permission model doesn't allow that though that was improved recently.
There was few shakes of trust that happend to us and we were loosing a trust to product little bit:
1. Drata agent - provide false sense of being on checked when we discovered that some HW haven't reported checks for more than 9 months which equals to situation that we hands over the PC and than have no checks
2. During the audit the auditor was claiming that he don't see evidences that were uploaded on quarterly basis which was scary given the fact that we are not backing up evidences uploaded to Drata. Thankfully it was restored with support and provided extra to auditor. But finally we don't know what was a problem as acting via middleman is clumsy. We were instructed with support to raise it that additional training will be provided with auditor. But what I think would be more appropriate and well appriciated would be auditor communicating with drata folks directly either resulting in either additional training or restoring data. The result we got are ok we survived the audit, but I have no clarity whether it was problem with the auditor or with platform and I am afraid it will be repeated next audit.
The features that would be really appriciated and are missing is measuring SLAs for offboarding where a lot of focus is during the audit.
What problems is the product solving and how is that benefiting you?
Continous monitoring and automatic evidence collection. Providing a sense of security in some aspects.
Solid product, helpful support
What do you like best about the product?
- Most important integrations are available and easy to setup
- Drata Agent as lightweight MDM solution
- Simple UI which gets the job done
- REST API to build custom workflows
- OOTB policy templates with guidance
- Customer support is friendly, helpful and usually quick to respond
- Trust page
- Drata Agent as lightweight MDM solution
- Simple UI which gets the job done
- REST API to build custom workflows
- OOTB policy templates with guidance
- Customer support is friendly, helpful and usually quick to respond
- Trust page
What do you dislike about the product?
- While SOC 2 is well documented in the help center, ISO 27001 is not always mentioned as well.
- More integrations that could be helpful
- More integrations that could be helpful
What problems is the product solving and how is that benefiting you?
Drata is helping us building and improving processes around compliance and security, preparing us for ISO 27001.
Security monitoring platorm
What do you like best about the product?
I like the effectiveness of Drata in identifying security vulnerabilities and promptly notifying users about pending tasks. Additionally, I find the numerous connectors available to integrate with other applications impressive. The seamless and user-friendly process, coupled with the responsive and helpful customer support, enhances the overall experience with Drata.
What do you dislike about the product?
Cost to operate Drata is very high for Startups.
What problems is the product solving and how is that benefiting you?
Creating and managing policies. Keeping track of Cloud platform security vulnerabilities.
Drata as unique business enabler - compliance is no longer obligation - it's a joy.
What do you like best about the product?
Drata team that designs the product they sell in the way how every single CISO would like it. Simple for users, comprehensive and detailed for auditors, and - visible and transparent for CISOs and other C-level stakeholders. I even made my customers to like Drata via Trust Center, which is truly unexpected result.
What do you dislike about the product?
A lot of dependencies locked in integrations, making me so excited about Integration 2.0 which will allow me integrate my specific tools faster than Drata fastest guy will do it.
What problems is the product solving and how is that benefiting you?
Drata automates my approach to the security way beyond just compliance.
showing 211 - 220