Drata's platform helps companies build and maintain the trust of their users, customers, partners, and prospects. We believe the best way to earn trust is by being transparent and proving that we are doing what we're saying we're doing. That’s why we take a security-first approach to everything we do. From building our infrastructure as code to monitoring our environment with anomaly detection and automated remediation, security is a core value that drives our business forward. This Trust Center provides you with artifacts to help show how we walk-the-walk when it comes to our own security, compliance, and privacy programs. Please reach out to our compliance team with any questions not answered here.
Documents
Drata Not Impacted by Salesloft-Drift Incident
Drata became aware of the Salesloft-Drift security incident shortly after news reports were released regarding the compromise.
Threat intelligence sources and news outlets reported that this incident impacted customers of the Drift product, produced by Salesloft, who had the Drift integration enabled within Salesforce.
- Recommended: Widespread Data Theft Targets Salesforce Instances via Salesloft Drift, Google Threat Intelligence Group
We want our customers to know that Drata is not impacted by the Salesloft-Drift incident.
We do not leverage this software and therefore the confidentiality, integrity, and availability of our systems remain unharmed.
- Will my data be transferred or shared with any third parties?
- Are all personnel required to use Multi Factor Authentication (MFA) to access the production cloud environment?
- What is Drata's tenancy model and how is customer data segregated?
- What physical security controls are in place to protect data and systems?
- Do all users have unique ID's for access to production systems and data?





