Full-Time
Posted on 8/27/2025
Automates continuous security compliance monitoring
$171k - $264k/yr
Remote in USA
Remote
Drata automates security and regulatory compliance for fast-growing technology and SaaS companies. It helps achieve and maintain continuous compliance with standards such as SOC 2, ISO 27001, and HIPAA. The platform works by continuously monitoring a company’s security posture and automatically collecting audit evidence. It integrates with over 75 technologies to provide a unified view of compliance status, streamline workflows, and replace manual tasks (like screenshots and spreadsheets) with automated evidence gathering. Compared with competitors, Drata emphasizes continuous, end-to-end automation across a wide range of tools to keep organizations audit-ready as they scale. The company’s goal is to save time and resources for its customers while building and demonstrating trust through ongoing compliance, supported by a subscription business model with recurring revenue.
Company Size
501-1,000
Company Stage
Series C
Total Funding
$328.2M
Headquarters
San Diego, California
Founded
2020
Help us improve and share your feedback! Did you find this helpful?
Health benefits
Learning enrichment stipends
Flexible PTO
Work from home stipend
401k
Parental leave
From spend request to security approved: how Ramp and Drata automate vendor reviews. Drata and Ramp now integrate to automate vendor security reviews from spend requests, closing the loop between procurement, security, and compliance. Every time someone adds a new vendor in Ramp, security or GRC needs to get involved, a review has to start, and the decision needs to find its way back to procurement before the purchase moves forward. That manual handoff is one of the most persistent points of friction between finance and security. It slows down purchasing, adds back-and-forth over email and tickets, and makes it harder to prove that every vendor was actually reviewed. The Drata and Ramp integration closes that gap. The challenge: procurement and compliance live in different systems. Most companies manage vendor spend and vendor security in separate tools. Ramp owns spend requests, approvals, and budget controls. Drata owns vendor security reviews, evidence collection, and control monitoring. The connection between them is usually email, tickets, and spreadsheets. It starts when someone on the finance team adds a vendor in Ramp and emails security. Then, the security team creates the vendor in their own system and kicks off a review. Eventually, someone sends an approval back so the request can move forward. The whole process can take days or weeks and depends on both teams staying perfectly in sync across systems that don't actually talk to each other. For companies working toward SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, or any framework that requires vendor due diligence, this isn't just an efficiency problem. It creates real risk when vendors are approved for spend before a security review is complete. The solution: The Ramp x Drata integration. Drata now integrates directly with Ramp to connect spend management with vendor security compliance. When a team member submits a spend request in Ramp that includes a new vendor, Drata detects it automatically and: * Creates the vendor record in Drata - no redundant data entry. * Maps any configured custom fields from the Ramp form directly to the Drata vendor record, so context carries through. * Kicks off a vendor security review based on your Drata program configuration. When the review is complete and approved in Drata, the status syncs back to Ramp automatically - every hour by default, or immediately via manual sync. Finance sees when a vendor is cleared, and procurement keeps moving without tracking down status over email or Slack. No email chains. No copy-paste. No vendors slipping through the gap between procurement and security. How the integration works. Here's what happens behind the scenes once Ramp and Drata are connected: * A team member submits a spend request in Ramp and selects a new vendor. * Ramp detects that the vendor is new and triggers the Drata integration. * Drata automatically creates the vendor record and starts a security review based on your program configuration (review type, deadline, and required fields). * The security team completes and approves the review in Drata. * Drata syncs the approval back to Ramp automatically every hour, or immediately via manual sync. * The Ramp request is cleared for approval with a documented security review on record. From the requester's perspective, they stay in their existing Ramp workflow. From the security team's perspective, every new vendor appears in Drata with the right details and a linked review, without manual intake work. How finance and security teams benefit. The Ramp x Drata integration is designed for companies where finance and security need to stay aligned - without turning every new vendor into a multi-week project. Finance and procurement teams can eliminate manual notifications to security every time you add a vendor. Instead, Drata picks up new vendors from Ramp automatically and starts the review. They can also see review status without leaving Ramp, so they know exactly when a vendor is ready for approval. It helps keep spend moving without waiting on email threads or chasing approvers. For security and compliance teams, they see every new vendor requested in Ramp in the Drata vendor security review queue automatically. They can stop chasing procurement for vendor details or re-entering the same information in multiple systems. Plus they can configure review types, deadlines, and required fields once in Drata - the integration applies those settings every time. Get set up in under 10 minutes. Connecting Ramp and Drata does not require engineering work in most environments. You can get up and running in a few steps: * In Ramp, go Company > Integrations and select for Drata * Select Connect and follow instructions to create an OAuth application in Drata. * In Drata, go to Settings | Integrations and select Ramp. * Create an application in Drata with the required API scopes: Events, VendorCreate, VendorCreateUpdate, VendorCreateAndRead, and VendorSecurityReviews. * Copy the application credentials into Ramp. The integration pulls the required data from Drata automatically. * Configure a Drata Program with your review type, deadline, and any field mappings from your Ramp forms. Once live, the integration runs in the background. You manage your vendor security reviews in Drata; Ramp reflects the latest status automatically. Who this is for. The Ramp x Drata integration is built for teams that want procurement and compliance to move in lockstep from the start. For instance, organizations building or maturing a compliance program toward SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, or similar frameworks with vendor due diligence requirements will also see value. If you're scaling procurement and expecting vendor reviews to happen automatically, not through ad hoc email, or if you want to cut the back-and-forth between procurement and security on every new vendor, this integration is designed with your needs in mind. It removes friction without forcing teams to abandon their existing workflows. Common questions, answered. Does this work with existing vendors in Ramp? The integration triggers for new vendors that Ramp hasn't seen before. Requests for existing vendors continue to follow your current workflow. What if I need the sync to happen immediately? Drata syncs vendor review status back to Ramp automatically every hour. If you need an immediate update, you can trigger a manual sync from the integration flow. Can I control which fields carry over from Ramp to Drata? Yes. When you configure a Drata Program, you define which Ramp form fields - including custom fields - map to which Drata vendor fields. The information entered in Ramp carries through to Drata according to those mappings. What compliance frameworks does this support? Vendor security reviews completed in Drata through the Ramp integration support Drata's framework library, including SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and others, and can be used as evidence across applicable frameworks. Getting started. The Ramp x Drata integration is available today. If you already use both Ramp and Drata, open Settings | Integrations in your Drata account and select Ramp to connect the integration. Not using Drata or Ramp yet? See how Drata connects to your existing stack and book a demo to explore how Ramp and Drata can help you automate vendor security reviews end to end. Monica Olmsted is Group Lead of Partner Marketing at Drata, where she leads revenue-generating co-marketing strategies with strategic partners - especially cloud service providers - and helps scale Drata's partner ecosystem. Before Drata, she held partner marketing roles at Seismic and led partner communications and marketing communications at Sesame Software, bringing a strong blend of partnership strategy, multi-channel marketing, and storytelling to every program. She holds a BFA in Visual & Performing Arts from Cornish College of the Arts (cum laude). Get biweekly expert insights so you never miss what's next. Chart your course. Navigate to new worlds of trust with Drata.
Drata, a trust management platform, has unveiled agentic AI capabilities designed to automate enterprise trust workflows. The company is addressing third-party risk management and customer assurance with AI agents that autonomously handle security assessments and questionnaires. The Agentic TPRM Assessment, now available to all customers, automates vendor security reviews by accessing live trust data and eliminating manual evidence collection. Agentic Questionnaire Response, currently in beta, orchestrates the complete security questionnaire lifecycle whilst maintaining human oversight. Drata also introduced AI Trust Center Setup, which reduces initial build time from months to hours by automatically generating complete trust centres from existing artifacts. The company appointed Bharat Guruprakash as Chief Product and Technology Officer to advance its platform, which serves 8,000 organisations worldwide.
Drata unveils industry-first Agentic AI capabilities to transform enterprise trust workflows. New capabilities across the Risk Management and Security Assurance categories enable Drata customers to reduce manual work, increase time to value, and prove trust at scale SAN FRANCISCO-(BUSINESS WIRE)-Drata, the leading agentic trust management platform, today unveiled an industry-first set of agentic AI capabilities designed to convert trust from reactive proof into proactive, always-on execution. The release speaks to two critical enterprise challenges at the center of trust management: third-party risk management, which enables buyers to assess and monitor vendors at scale, and customer assurance, which empowers vendors to demonstrate trust through Trust Centers and streamlined security questionnaires. "We're seeing a fundamental shift in how trust is proven and evaluated, with businesses worldwide now expected to continuously demonstrate trust at scale," states Adam Markowitz, co-founder and CEO of Drata. "With our latest agentic AI capabilities, Drata moves beyond AI for piecemeal tasks to fully agentic workflow ownership, enabling organizations to autonomously assess third-party risk, service questionnaires at speed, and dynamically deliver trust information. That's how trust becomes continuous, transparent, and autonomous." Releasing Agentic TPRM Assessment Third-party risk programs today are overwhelmed by manual evidence collection and repetitive cycles: teams email vendors, stitch together stale artifacts and perform subjective reviews that slow procurement. Agentic TPRM Assessment flips that model. Now available to all Drata customers, the agent automates criteria configuration and runs objective, criteria-driven security reviews that evaluate each control, provide reasoning and deep links to source evidence, and convert findings into follow-ups, tracked risks, and executive reports. Critically, the agent autonomously accesses vendor information hosted on Drata Trust Centers, automates access requests with explicit consent, ingests live trust artifacts and ensures assessments are based on current vendor evidence - not stale uploads. For security teams, this agent eliminates back and forth cycles with vendors, enables repeatable up-market decisioning, and provides the ability to scale vendor coverage without proportional headcount increases. "Agentic TPRM Assessment will transform how we run third-party reviews," stated Sheron Chakalakal, Head of GRC at UiPath. "By ingesting live Trust Center evidence and producing criteria based evaluations, Drata eliminates the tedious back-and-forth with vendors and lets our team focus only on real risk - ultimately accelerating reviews and giving our procurement team the confidence to move faster." "Third-party risk is one of the most pressing challenges for every CISO," said Scott Roberts, Chief Information Security Officer at UiPath. "Drata's Agentic TPRM Assessment will fundamentally change how organizations operationalize third-party risk management - bringing rigor, consistency, and scale. Using Agentic AI, security teams can run assessments in minutes, achieve a more accurate risk posture across the supply chain, and operate at AI speed." Announcing Agentic Questionnaire Response Traditionally, security questionnaires are a major bottleneck with messy spreadsheets, brittle mappings, and long subject matter expert handoffs causing a significant slowdown in deal velocity. Drata's existing AI Questionnaire Assistance automatically intakes questionnaires and drafts answers grounded in approved Knowledge Base content, with every response tied to clear provenance. Now, Agentic Questionnaire Response builds on that innovation by orchestrating the full security questionnaire response lifecycle. Currently available in beta access, Agentic Questionnaire Response streamlines and expedites answering, subject matter expert collaboration and reminders, review readiness, completion and final delivery - while keeping users firmly in control of all critical actions. Customers retain control of their questionnaire workflows by indicating how much the agent can do autonomously and maintaining key human-in-the-loop touchpoints. Introducing AI Trust Center Setup Building a Trust Center today is often a manual and slow process, requiring teams to write copy, attach artifacts, gather approvals for accuracy, and iterate for months before making it publicly available. AI Trust Center Setup will reduce this initial build time to hours. AI Trust Center Setup ingests a customer's artifacts and automatically generates a preview of the complete Trust Center in minutes, including mapped documentation and deep links. Customer assurance teams now act as editors-in-chief who review and publish - rather than spending time tracking down documents and waiting for approvals. New certifications and reports can be published with minimal effort, enabling companies to significantly reduce time to value and helping their buyers find trustworthy proof in seconds. Building the Leading Agentic Trust Management Platform Drata also announced the appointment of Bharat Guruprakash as Chief Product and Technology Officer. With more than 20 years of product and engineering leadership experience, Bharat joins Drata from Algolia, where as the Chief Product Officer, he led the company's global product organization and helped build a platform of APIs that powers real-time, personalized digital experiences for enterprises worldwide. Previously, Bharat served as Vice President and General Manager of Twilio's account security business and held leadership roles at Bitcasa, Samsung, and Digit International. At Drata, Bharat will lead the global product and engineering teams to advance the company's agentic trust management platform. See Drata's Agentic AI in Action Together, these agentic AI capabilities empower organizations to act on live evidence, automate governance-safe decisioning, and scale trust. To see these agentic AI capabilities live, stop by Booth #934 at the RSA Conference this week in San Francisco. Request a demo with Drata today to discover more about these features. About Drata Drata provides the trust network that enables businesses to operate, scale, and partner with confidence. Powered by AI and designed to operationalize trust, the Drata Agentic Trust Management Platform continuously interprets controls, risk, and assurance signals - reducing repetitive manual work while improving visibility into internal and third-party risk, enabling always-on audit readiness across compliance frameworks, and accelerating security reviews. Purpose-built for enterprise complexity, Drata unifies governance, risk, compliance, and assurance to deliver faster time-to-value, reduce operational overhead, and enable continuous trust for 8,000+ organizations worldwide. For more information, visit drata.com. More News From Drata SAN FRANCISCO-( BUSINESS WIRE )-Drata has announced the opening of its new San Francisco headquarters, signaling a long-term investment in customers, talent, and the trust ecosystem... Drata. Release Summary Drata has unveiled industry-first agentic AI capabilities designed to convert trust from reactive proof into proactive, always-on execution. Release Versions
Best GRC tool Cyprus: powering 2026 digital transformation. Cyprus is undergoing a "Digital Metamorphosis." As banks in Nicosia and shipping giants in Limassol move to the cloud, the risk landscape has shifted. A 2026 GRC tool must do more than store files; it must be the engine of your digital growth. * NIS2 and DORA Readiness: With the full enforcement of the NIS2 Directive and DORA, Cypriot critical entities and financial firms must prove operational resilience. * The M&A Wave: Following the 2025 consolidation in retail and banking, 2026 is the year of integration. Enactia helps merged entities unify their risk posture across legacy systems. * Fintech & Forex: For the massive CIF (Cyprus Investment Firm) sector, CySEC compliance and AML/KYC risk management are now automated within Enactia. The Enactia Edge: As a Nicosia-founded company, Enactia Ltd provide on-the-ground support that global competitors like Vanta or Drata cannot match. Its platform is the preferred choice for Cyprus firms transitioning from manual spreadsheets to automated governance. FAQ: GRC tools in Cyprus. * Why does a Cyprus company need a GRC tool? To centralize ISO 27001, GDPR, and local CySEC/FCA requirements into a single "Source of Truth." * Can Enactia host data in Cyprus? Yes. Enactia Ltd understand the local need for data sovereignty and offer hosting options that satisfy Cypriot regulators. * Does Enactia support local frameworks? Yes, including specific templates for the Cyprus Digital Strategy and local cybersecurity standards.
Coalfire announces strategic partnership with Drata to deliver continuous trust. Mar 10, 2026, 08:03 ET CHICAGO, March 10, 2026 /PRNewswire/ - Coalfire Systems, Inc. today announced a strategic partnership with Drata, the leading agentic trust management platform, to help organizations operationalize trust through enterprise-grade GRC, always-on assurance and independent validation. This partnership combines Coalfire's experience delivering coordinated assessments across more than 100 frameworks with Drata's agentic trust management platform for continuous control monitoring, automated evidence collection, centralized GRC workflows, and ongoing trust assurance. Coalfire translates Drata's AI-native insights into independent assessments, certifications and assurance outcomes. Coalfire's Compliance Essentials is embedded as a structured delivery layer to guide readiness, validate controls and align audit evidence. Adam Shnider, executive vice president of assessment services, Coalfire, said: "Organizations want compliance to move as fast as their technology. By combining continuous monitoring from Drata with Coalfire's independent assessment expertise, we help clients move from readiness to assurance with greater efficiency and confidence." Kevin Kriebel, senior vice president of business development, Drata, said: "Trust is no longer a point-in-time milestone; it's an always-on expectation. By partnering with Coalfire, we're strengthening the bridge between continuous trust management and independent assurance. Together, we're helping organizations operationalize governance, risk and controls in a way that builds real confidence with customers, partners and regulators. This collaboration reinforces our commitment to delivering the trust network that enables businesses to operate, scale and partner with confidence." This partnership moves compliance from periodic, manual work to a continuous model that reduces evidence collection time while delivering the independent assurance stakeholders require. About Coalfire: Coalfire, headquartered in Chicago, Ill., is a global services and solutions company that specializes in cyber advisory, assessment, and security. The company also develops cutting-edge technology platforms that automate defenses against security threats for the world's leading enterprises, cloud providers, and SaaS companies. Coalfire is the foremost provider of FedRAMP compliance assessments and penetration testing services in the United States. For more information, visit www.coalfire.com and follow LinkedIn, Twitter, and Facebook. Media Contact Corey Eldridge Force4 Technology Communications [email protected] SOURCE Coalfire