Sign in
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Reviews from AWS customer

9 AWS reviews

External reviews

1,075 reviews
from and

External reviews are not included in the AWS star rating for the product.


5-star reviews ( Show all reviews )

    Kelsea Z.

Great Experience with Drata

  • September 23, 2024
  • Review provided by G2

What do you like best about the product?
I loved the personalized help we gained from our Drata Customer Success Manager, Craig. This journey was new to our organization and he helped us sort through what to prioritize.
What do you dislike about the product?
Our experience has been great - nothing comes to mind!
What problems is the product solving and how is that benefiting you?
We are looking to get SOC 2 and ISO 27001 certified


    Basharat K.

Drata: Streamlining Compliance with Exceptional Support

  • September 19, 2024
  • Review provided by G2

What do you like best about the product?
I absolutely love Drata's ISMS Dashboard view. It seamlessly connects our entire IT stack, providing real-time insights into areas or team members that might need attention. The latest Risk Management Module, aligned with ISO/IEC controls, is a game-changer—it has significantly streamlined our compliance processes. Additionally, the team at Drata is incredibly innovative, making security and compliance not just manageable but actually enjoyable.
What do you dislike about the product?
Nothing to disklike about Drata, even the pricing is very competitive!
What problems is the product solving and how is that benefiting you?
When we onboarded to Drata three years ago, we faced a tight five-month deadline to achieve ISO/IEC 27001 and 27701 certification. Thanks to Drata, we were able to meet this goal in just three months. Since then, we've smoothly navigated our annual audits, and both our security and privacy posture have significantly matured alongside Drata’s product. The platform’s continuous innovation and alignment with regulatory requirements have made compliance management much more efficient and effective for our organization.


    Matt N.

Excellent for startups

  • September 17, 2024
  • Review provided by G2

What do you like best about the product?
Drata acts as your virtual compliance officer. I'm really the last one to naturally be handling compliance- but as a startup we all have to branch out. Drata steps in to have my back and help me to be as conscientious as the product deserves.

Customer success management has been exemplary from Drata- in particular, working with Elizabeth John, whose patience, diligence, and industry knowledge have been mission-critical to our process. Drata is a great tool, don't get me wrong, but I still think my team and I would be coming up short without her.

When Drata was recommended to me, I was skeptical. I'd come from heavily regulated industries and just couldn't believe a tool could make compliance and certification very easy. It's a hard job, and it requires hard-headed persistent effort and rigor. While all that is still true, Drata made it so that a "cowboy" like me could get the job done.

I am in Drata almost every day. It integrated with our stack almost seamlesssly (we use Vercel, so that is still TBD for integration). Implementation was honestly a breeze once we got our IDP straightened out.
What do you dislike about the product?
Their onboarding partner system wasn't great- but my understanding is that they've done away with that pipeline and brought onboarding in-house. This was a brilliant move. Communication and accountability are so through the roof now that I am the the one letting THEM down more often than not.
What problems is the product solving and how is that benefiting you?
The entire certification process is being handled in Drata.


    Transportation/Trucking/Railroad

Drata at Intelcom

  • September 13, 2024
  • Review provided by G2

What do you like best about the product?
From the initial discovery call, throughout onboarding and continuing to biweekly calls with the different Drata representatives who've been assigned to the Intelcom account (all of whom are experienced and supportive) my experience has been excellent.
What do you dislike about the product?
I have nothing negative to say about Drata.
What problems is the product solving and how is that benefiting you?
Although my company has not fully onboarded all facets, the tool helped me to prepare for the company's SOC 2 Type 1 audit.


    Julian D.

Makes compliance more understandable

  • September 12, 2024
  • Review provided by G2

What do you like best about the product?
Pre-built policies are a great starting point and have extensive notes about what could change and which parts are critical and should not be removed. For someone who is not familiar with compliance there's a lot of guidance and features that help understand where you are and what still has to be done.
What do you dislike about the product?
Integrations help make the whole process easier, and they have built many for the tools with the most market share. If you use less common tools you'll have to do more manual work. I'm sure that they will continue to build more integrations over time.
What problems is the product solving and how is that benefiting you?
Our customers are asking about SOC 2 compliance more and more frequently. Without any personnel specifically to address this, we need a platform to help make it feasible.


    Information Technology and Services

The Drata team was an essential part of our SOC2 certification.

  • September 05, 2024
  • Review provided by G2

What do you like best about the product?
We have recently completed our first SOC2 Audit, and I honestly do not think we could have done this successfully without the Drata framework and support from Elizabeth John and Courtney Barton. The Drata system is user friendly and comprehensive. The Live chat feature is exceptionally helpful to navigate questions about the platform itself and compliance. We had a series of meetings set up with Elizabeth who helped guide us through the initial set-up process, and adding evidence to our controls. Each meeting was an effective working session. Elizabeth was always prepared, kept us on task and an essential part of our SOC2 journey! I would also like to highlight our account manager, Courtney, for consistently checking in to make sure our current needs were met, where we may be heading in the future and how we might be able solve pain points for future audits. I would highly recommend Drata to other companies working to build a robust security platform.
What do you dislike about the product?
Sometimes new policy templates were released, causing monitored controls to fail. It would be helpful to have a heads up on this so we would know what the failure was related to and act quickly.
What problems is the product solving and how is that benefiting you?
Helping us maintain the required evidence, policies and processes to obtain and maintain SOC2 compliance.


    Anton G.

Great GRC platform to monitor all controls in one place and to establish a source of truth.

  • August 29, 2024
  • Review provided by G2

What do you like best about the product?
The interface is very friendly and the team keeps developing new features, and support is super fast.
What do you dislike about the product?
The Drata Agent needs more compatibility with UNIX systems.
What problems is the product solving and how is that benefiting you?
Monitors our SOC 2 Controls.


    murray m.

The software is intiive and they have exelcent support

  • August 21, 2024
  • Review provided by G2

What do you like best about the product?
Defaut policy are close to what we want and they are easy to edit.
What do you dislike about the product?
Sometimes the agent does not communicate wiht the server.
What problems is the product solving and how is that benefiting you?
Getting our company SOC 2 compliant.


    Information Technology and Services

Drata is the best in class tool for maintaining continuous compliance

  • August 15, 2024
  • Review provided by G2

What do you like best about the product?
Features I like most:
Connections to most every system we use
Real Time Monitoring of security controls
Evidence collection/managment
The ability to pose audit & compliance related questions to a team of experts.
Great support, especially from Tayler Gase and the team on chat.
Trust Center portal


You need a system like this to ease the impact of audit season.
What do you dislike about the product?
My particular auditor didn't seem to care that I'm using Drata and we still end up collaborating via spreadsheets.
What problems is the product solving and how is that benefiting you?
Drata makes audit season MUCH MUCH easier, especially year over year, as now you have an excellent way of organizing evidence over time.
Drata's Trust Center provides a great method for sharing our security posture and documents with our clients.


    Johnny Chen

Collects and stores compliance evidence and documentation for you using native integrations with your tech stack.

  • August 12, 2024
  • Review provided by PeerSpot

What is our primary use case?

We mainly use Drata as our GRC tool. Previously, we didn't have a GRC tool in-house. As a payment company, we must complete two annual audits: PCI for the payment card industry and SOC 2 Type 2, which most software companies also need. Without a GRC tool, we had separate contracts with each auditing firm, and they provided their tools for us to upload audit evidence. We had to produce the same evidence every year and manually upload it to these tools. If we changed auditors, we'd have to use new software each time, and our previous year's evidence stayed with the auditors. Now, with Data, we can store all our information in-house. Instead of auditors using their platforms, they come to Drata to access the evidence. Throughout the year, we upload and complete audit evidence in Drata, so during the audit period, auditors access what they need from the Drata platform. This means that when we change auditors, it doesn't matter who they are as long as they can access Drata.

How has it helped my organization?

Data contains evidence that InfoSec-related audits are often similar. About 30-40% of SOC 2 evidence can be used for PCI audits. Previously, we had to produce separate evidence for each audit and send it to different auditors. Everything lives in Drata, and we can use the sameevidence for PCI and SOC 2 audits. Drata’s cross-mapping between evidence and requirements makes this possible.

What is most valuable?

Drata keeps adding new features, allowing us to build our entire InfoSec program within it. Adding new components and evidence for different audits is easy. Drata also integrates with various software, like ticketing systems, source code control, and cloud platforms, continuously pulling evidence from these integrations. Without a GRC tool with these integrations, we used to gather evidence from different software during audits manually.

Drata has a significant impact on our security posture management. Previously, Drata had features for security posture management, primarily through integration with AWS. For example, it would scan AWS for specific security requirements, like ensuring all S3 buckets are private. It will be reported on the Drata platform if it finds a public bucket.

Recently, Drata introduced a new feature that uses an infrastructure-as-code approach. This feature detects issues and provides AI-generated suggestions for fixing them. If an organization uses infrastructure-as-code solutions like Terraform, Drata will suggest changes to the Terraform code to address the issues. You can then review and apply these changes to fix the problems. This is particularly useful when dealing with many topics, as it helps automate and speed up the process of implementing fixes. However, this AI-generated code feature is part of Drata’s upsell options. The basic version of Drata offers limited capabilities compared to the advanced features available with a paid upgrade.

Even without this new feature, Drata's security posture management is valuable, as it scans cloud environments for deviations from defined security baselines. Many tools offer similar capabilities, but Drata’s new feature that translates issues into actionable fixes is a notable advancement. This benefits teams with the capability and resources to use this tool effectively.

What needs improvement?

There is room for improvement in Drata. The core features are solid, but some new features are in a very MVP (Minimum Viable Product) stage. They work, but the user experience isn't always smooth. While the core features are well-developed compared to the market, the new features need more polish. They could benefit from more user feedback and iterations to make them more useful. Some of these new features look promising buthave flaws, so we can’t fully adopt them or justify paying extra for them now. The user interface is clean and intuitive. However, you'll need some specific knowledge if you're a security policy manager or need to set updifferent integrations.

For how long have I used the solution?

I have been using Drata for more than one year.

What do I think about the stability of the solution?

I've never noticed Drata having stability issues, like bugs or breakdowns. It doesn’t have high real-time availability requirements, so minor outages usually go unnoticed unless they last for a day or more. I've never seen latency or significant downtime.

What do I think about the scalability of the solution?

Regarding scalability, Drata works well for small to medium-sized businesses withfewer than 500 employees like ours. However, I can't speak to its performance for large enterprises with thousands of employees. For us, it handles our cloud footprint adequately, but there could be issues with some features at a larger scale. For example, its access management lacks batch review capabilities, which could be problematic for large organizations. Reviewing every software and access in a vast enterprise might become excessively complex without betterscaling solutions.

How are customer service and support?

The support team at Drata is top-notch, the best I’ve seen. They have two main types of support: technical support for software or integration issues and auditing support from experienced consultants for audit-related advice. Technical support is excellent, with quick response times. For auditing support, they handle more straightforward issues through live chat within the software, but for more complex problems, I reach out to our customer success manager. We can collaborate through meetings or document sharing; they’re always willing to discuss questions face-to-face if needed. Overall, I have nothing but praise for their support.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Compared to other tools we tried before adopting Drata, Drata stands out. Many tools either have fundamental features with a clean UI but limited functionality or offer similar features to Drata but with a complicated, hard-to-use interface. Drata has achieved a good balance between itsfeatures and usability. However, it could become problematic if they continue adding features without maintaining thisbalance. For now, Drata is in a good place regarding usability and complexity.

What's my experience with pricing, setup cost, and licensing?

Drata's pricing is quite reasonable. Compared to other tools in the market, including its biggest competitor, Vanta, Drata is much cheaper. Even compared to other tools like AuditBoard, which aren’t as good, Drata’s price remains competitive.

What other advice do I have?

Overall, I would rate Drata a ten. I would recommend it to others. For new users, I advise relying heavily on their support team, especially if you're not experienced in compliance. The support team is accommodating and reliable.

Regarding integration capabilities, I’d rate it an eight. Drata supports many primary software tools, but there are still some gaps. For example, they currently only support Salesforce for CRM and do not yet support HubSpot, which many people use. They’re good with the integrations they offer, but there’s room for improvement in coverage.