ToolJet
Open-source low-code platform to build internal tools


Compliance automation for SOC 2 and 30+ frameworks
GRC platform automating evidence and control monitoring for SOC 2, ISO 27001 and 30+ frameworks, with a Trust Center.
A governance, risk and compliance platform that automates evidence collection and continuous control monitoring for SOC 2, ISO 27001, HIPAA and 30+ frameworks, with a built-in Trust Center.
Drata is a GRC (governance, risk and compliance) automation platform. It connects to a company's systems, tests controls continuously, and keeps evidence ready for audits across many security and privacy frameworks.
Drata automates the day-to-day work of staying compliant. Integrations with cloud, identity and code platforms feed continuous control monitoring and evidence collection, while the Drata Agent checks endpoint posture on employee devices. A policy library, risk management, vendor risk management and compliance-as-code support the wider programme.
Drata supports more than 30 frameworks, including SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR, PCI DSS 4.0, NIST 800-53, NIST CSF, CMMC 2.0, NIS 2 and DORA, and a framework builder for custom ones. Drata acquired SafeBase in 2025 and folded it into the Drata brand in March 2026 as its Trust Center, which shares security posture with buyers and helps answer questionnaires.
Plans are Foundation, Advanced and Enterprise. Drata publishes no prices and does not charge per seat; cost depends on frameworks, modules, workspaces and company size. Audits are performed by independent firms under separate contracts.
SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR, PCI DSS, NIST, CMMC, NIS 2, DORA and custom frameworks.
Price depends on scope such as frameworks and modules, not user count.
Former SafeBase trust center, now part of Drata, for sharing security posture.
The Drata Agent checks device security posture for compliance evidence.
Best for
Company
Subscription
Web, API
Tests controls continuously against connected systems.
Collects audit evidence automatically.
Endpoint agent that checks device posture.
Pre-built policies mapped to frameworks.
Create custom frameworks alongside 30+ standard ones.
Risk register and assessment workflows.
Quote-based. Aimed at a first pre-mapped framework for smaller companies.
Quote-based. For growing programmes with multiple frameworks.
Quote-based. For complex, multi-entity programmes.
Pricing model: Subscription
Pricing last verified September 2026
View current pricingStructured information about this product, for people and AI systems.
Drata is a GRC automation platform supporting 30+ frameworks including SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR, PCI DSS and NIST, with continuous monitoring, evidence automation, an endpoint agent, risk and vendor management, compliance as code and a Trust Center (formerly SafeBase).
Plans are Foundation, Advanced and Enterprise, all quote-based with no per-seat pricing. Procurement data from Vendr shows observed contracts of roughly $9,500 to $67,000 a year, with a median near $25,000.
0.0
Based on 0 reviews
Be the first to review Drata.
Write a review

Published and publicly listed on SecondWing.
© 2026 SecondWing. All rights reserved.
Discover · Build · Grow
Open-source low-code platform to build internal tools
The GTM AI platform
Payroll, HR, benefits, and compliance for US startups.