Drata Not Impacted by Axios npm Supply Chain Attack

Trust Center

Start your security review
View & download sensitive information
ControlK

SafeBase helps B2B SaaS companies close enterprise deals faster by streamlining the security assessment process. We take security seriously and have a dedicated internal security team. Our security team's controls and policies are detailed in this Trust Center. If you have any additional questions or concerns, please email us at security@drata.com.

OpenAI-company-logoOpenAI
LinkedIn-company-logoLinkedIn
Abnormal Security-company-logoAbnormal Security
Asana-company-logoAsana
Wiz-company-logoWiz
Instacart-company-logoInstacart
ClickUp-company-logoClickUp
Zoom-company-logoZoom
Ramp-company-logoRamp
Crossbeam-company-logoCrossbeam
GitLab-company-logoGitLab
T-Mobile-company-logoT-Mobile
Jamf-company-logoJamf
Palantir-company-logoPalantir

Documents

REPORTSISO Statement of Applicability
Status Monitoring
DDoS Protections
Business Continuity & Disaster Recovery
View more
Knowledge Base (FAQ)
  • Is sensitive data encrypted at rest and in transit?
  • Will my data be transferred or shared with any third parties?
  • What is Drata's tenancy model and how is customer data segregated?
  • Are all personnel required to use Multi Factor Authentication (MFA) to access the production cloud environment?
  • Are there any web facing application protection mechanisms?
View more
Trust Center Updates

Drata Not Impacted by Axios npm Supply Chain Attack

Copy link
Incidents

On March 30, 2026, Drata became aware of the Axios npm supply chain attack security incident.

Threat intelligence sources have reported that this incident introduced a malicious dependency into specific npm releases of the widely used HTTP client Axios, specifically axios@1.14.1 and axios@0.30.4.

-Recommended: Supply Chain Attack on Axios Pulls Malicious Dependency from npm, Socket Research Team
-Recommended: Hidden Blast Radius of the Axios Compromise, Socket Research Team


We want our customers to know that Drata is not impacted by this threat.


We do not leverage the affected versions of this software (axios@1.14.1 or axios@0.30.4) within our product and therefore the confidentiality, integrity, and availability of our systems remain unharmed.

If you need help using this Trust Center, please contact us.
Contact support
If you think you may have discovered a vulnerability, please send us a note.
Report issue
Built onSafeBase by Drata Logo