Reviews from AWS Marketplace
0 AWS reviews
-
5 star0
-
4 star0
-
3 star0
-
2 star0
-
1 star0
External reviews
External reviews are not included in the AWS star rating for the product.
Compliance Controls Simplified
What do you like best about the product?
Drata is very perscriptive on what you need to t do to be compliant. It has very easy out of the box automation and integrations with key parts of our tech stack that make compliance a breeze. The CSM team is also great (Special shoutout to Laci).
What do you dislike about the product?
Long term we hope the risk library improves along with better slack notifications.
What problems is the product solving and how is that benefiting you?
Compliance for Security - ISO27001, PCI, SOC2, and HIPAA.
- Leave a Comment |
- Mark review as helpful
Great Software for SOC2
What do you like best about the product?
Their technical teams and attention to product feature introduction and development. Our CSM is one of the best, that I've worked with in a long while. Shoutout to Laci!
What do you dislike about the product?
The product can be overwhelming, based on the organization and the security principles you are trying to tackle. The artifact and policy linking can be a little clumsy.
What problems is the product solving and how is that benefiting you?
SOC2 compliance automation for new digital properties.
Used to achieve SOC 2 compliance and enable visibility on controls
What do you like best about the product?
Three things stand out for us. 1) Drata is a product that is aligned with our compliance needs. 2) It is still delivering a strong ROI for us, saving time and making life easier with automation. 3) We used Drata to collect and demonstate evidence for the SOC 2 Type 1 and 2 audit. This contributed to a smooth process with our auditor.
Three key product highlights: integrations are compatible with our tech stack, visibility of controls for continous monitoring, mapping controls to frameworks (SOC 2 Type 1 and 2 + GDPR).
Our experience with Customer Success is excellent. We have been supported by Sara M and Victoria C who has seen our journey with SOC 2 as a start up without any security expertise in the early days. Throughout the past year, I have learned a lot more about maximising Drata's features. They have done this by proactively sharing help center guides, answering questions specific to our challenges and escalating to their Product/Engineering teams (when required). It is evident that they evaluate their processes with intent and are serious about what great looks like for us and themselves.
Three key product highlights: integrations are compatible with our tech stack, visibility of controls for continous monitoring, mapping controls to frameworks (SOC 2 Type 1 and 2 + GDPR).
Our experience with Customer Success is excellent. We have been supported by Sara M and Victoria C who has seen our journey with SOC 2 as a start up without any security expertise in the early days. Throughout the past year, I have learned a lot more about maximising Drata's features. They have done this by proactively sharing help center guides, answering questions specific to our challenges and escalating to their Product/Engineering teams (when required). It is evident that they evaluate their processes with intent and are serious about what great looks like for us and themselves.
What do you dislike about the product?
From my experience, there is no dislike because it has been doing what we need it to do. To nitpick, for us the GDPR framework has require more manual evidence uploads compared to SOC 2. We try to maximise the control mapping feature by ensuring any security controls are also mapped to GDPR (particularly useful for demonstarting compliance with Article 5 and 32).
What problems is the product solving and how is that benefiting you?
Problems: huge task of organising SOC 2 tasks and evidence collection, ongoing monitoring of control effectiveness, poor visibility of controls across the teck stack. Drata is benefiting us by: providing a meaningful view of controls that is mapped against industry frameworks (SOC 2 and GDPR), flagging issues that need our attention, visibility that facilitates conversations with key stakeholders in the company. Time saved and stress reduced.
Taking the fear out of certifications
What do you like best about the product?
We are new to the Drata platform, The prospect of working towards a certification for a small company such as ours with limited personell resources is daunting. Drata so far has taken the fear out of this project for us. The dashboard shows you in a very intuative way what you need to do and when. It has just overall improved our security posture as a company too by highlighting areas we'd not considered could be issues. Drata also fast tracks the documentation process when it comes to policies by having very detailed default policies for you to be able to get started. we are still early in our Drata Journey but having a dedicated customer sucess manager for a product such as this is a must, This is something Drata put a big emphasis on. Victoria our CSM is always avalible for questions and our bi-weekly calls keep us accountable. Drata care that you make the most from your investment.
What do you dislike about the product?
Not found anything so far that I dislike but im still in the setup phase.
What problems is the product solving and how is that benefiting you?
Holding our hands in the ISO and SOC certification path. We have a small team and we are wear many hats, Drata logically guides us to the path of certification
Powerful Automation and Clean Design
What do you like best about the product?
I like how the software provides continuous automation monitoring and helps you build policies. I also like how it helps you onboard and off-board employees. Their real-time customer support gives me quick access to answers, and my dedicated Account Manager is always there when I need her. Finally, I love how they continue adding and updating existing frameworks.
What do you dislike about the product?
Completing compliance can take a long time. I don't think this is a Drata thing, but more to do with the amount of work required for completing an audit-ready compliance.
What problems is the product solving and how is that benefiting you?
It is helping us become HIPAA, GDPR and NIST compliant. It guides us along the steps needed and prevents us from missing anything important along the way. The monitoring of our AWS services has helped us find unused infrastructure and also tighten down IAM polices.
Drata Advocate
What do you like best about the product?
Risk Management modules are very useful. We're also excited about the potential of expanding our compliance management within drata to additional standards frameworks. Having LinnF as our advocate and CSM has been massive. You won't find anyone who combines customer focus with an instinct for deliverability & sustainability quite like Linn does.
What do you dislike about the product?
I was disappointed ISO 9001 wasn't a supported framework. Everything revolves around our ISO 9001 Quality Management System. Having that fully integrated would've been huge.
What problems is the product solving and how is that benefiting you?
Supporting SOC 2 Type 1 and Type 2 reports. Possibly FedRamp next?
Exceptional Customer Service and Highly Innovative Features
What do you like best about the product?
Drata has provided our company with invaluable support that has led to improving our security posture. They have consistently proved that are very reliable. Specifically, our customer success manager, Sam, is exceptionally responsive and has deep knowledge of the platform. Their customer service should be an example for all companies to mirror.
What do you dislike about the product?
So far, we have not experienced any issues with Drata. We are looking forward to continuing our partnership with them!
What problems is the product solving and how is that benefiting you?
Based on our experience with Drata so far, I am confident that we have vastly improved our privacy and security practices. They provide a variety of easy-to-use features to improve our security posture. For example, security training for our team, policy templates mapped to controls, integration with AWS, and frequent updates to add new frameworks and features to meet regulations. Overall, it provides a one-stop solution for managing all the pieces for compliance, with new frameworks being added frequently.
An indispensable tool in our SOC2 compliance journey
What do you like best about the product?
Drata took the guesswork out of our compliance gaps by clearly presenting which aspects of our system needed attention. As a result, we formulated a clear strategy of action items to make us audit-ready. Not only that, but their system provides a streamlined and central evidence-collection process, helping us to stay organized. Lastly, their client support is second to none. I can't count how many times we messaged their live support with compliance and other questions. Each time, they provided clear guidance. I highly recommend Drata to anyone looking to bring their company into compliance with industry standards.
What do you dislike about the product?
N/A. I can't think of any issues that we had with Drata.
What problems is the product solving and how is that benefiting you?
Improving our security posture and meeting SOC2 certification requirements.
Great service and product for SOC 2 compliance
What do you like best about the product?
Our customer success manager, Tony, went above and beyond to meet with us regularly, answer all questions thoroughly and patiently, and ensure we were (and felt) prepared to our SOC 2 audit.
What do you dislike about the product?
There are some instances when the automated controls in Drata are insufficient for what an auditor will request. For this reason, we had to upload some evidence manually. However, there is a method to create custom controls, to make delivery to the auditor easier.
What problems is the product solving and how is that benefiting you?
There are so many moving parts in a SOC 2 audit/report, and Drata helped us prepare and maintain our security posture. The automated controls take out the guesswork.
This is an essential tool for us in starting off our Audit process!
What do you like best about the product?
Honestly the service itself is great, there are some integrations we'd like to add, but our environment is very unique so we don't count that against Drata. All along the way we have made extensive use of the "Help" system which connects us to the live help team. They have all been very friendly and helpful. Quite refreshing!
What do you dislike about the product?
We wish there was a more extensive API for us to write our own customizations against. They are working on this
What problems is the product solving and how is that benefiting you?
The biggest thing for me is giving us a roadmap of sorts to fulfilling our compliance. We have a fairly robust development team, so the automations we could have eventually created on our own. The thing we lack, that Drata gives us, is that institutional knowledges of the SOC 2 requirements and what data we need to provide to fulfill them
showing 461 - 470