Trust Center

background-image
Start your security review
View & download sensitive information
ControlK

Drata's platform helps companies build and maintain the trust of their users, customers, partners, and prospects. We believe the best way to earn trust is by being transparent and proving that we are doing what we're saying we're doing. That’s why we take a security-first approach to everything we do. From building our infrastructure as code to monitoring our environment with anomaly detection and automated remediation, security is a core value that drives our business forward. This Trust Center provides you with artifacts to help show how we walk-the-walk when it comes to our own security, compliance, and privacy programs. Please reach out to our compliance team with any questions not answered here.

Capital One-company-logoCapital One
Vercel-company-logoVercel
Tenable-company-logoTenable
Okta-company-logoOkta
Zscaler-company-logoZscaler
LinkedIn-company-logoLinkedIn
T-Mobile-company-logoT-Mobile
OpenAI-company-logoOpenAI
Brex-company-logoBrex
Xerox-company-logoXerox
Wiz-company-logoWiz

Documents

Featured Documents

REPORTSExternal Penetration Test Report
Trust Center Updates

Drata Not Impacted by Axios npm Supply Chain Attack

Copy link
Incidents

On March 30, 2026, Drata became aware of the Axios npm supply chain attack security incident.

Threat intelligence sources have reported that this incident introduced a malicious dependency into specific npm releases of the widely used HTTP client Axios, specifically axios@1.14.1 and axios@0.30.4.

-Recommended: Supply Chain Attack on Axios Pulls Malicious Dependency from npm, Socket Research Team
-Recommended: Hidden Blast Radius of the Axios Compromise, Socket Research Team


We want our customers to know that Drata is not impacted by this threat.


We do not leverage the affected versions of this software (axios@1.14.1 or axios@0.30.4) within our product and therefore the confidentiality, integrity, and availability of our systems remain unharmed.

Knowledge Base (FAQ)
  • Is sensitive data encrypted at rest and in transit?
  • Will my data be transferred or shared with any third parties?
  • What is Drata's tenancy model and how is customer data segregated?
  • Are all personnel required to use Multi Factor Authentication (MFA) to access the production cloud environment?
  • Are there any web facing application protection mechanisms?
View more
If you need help using this Trust Center, please contact us.
Contact support
If you think you may have discovered a vulnerability, please send us a note.
Report issue