Drata
Continuous compliance automation.
Scorecard from 1 structured review
Exposure signal
LowAn objective, third-party reading of this vendor's own credential hygiene. It is not part of the community scorecard and does not affect any rating on DBSE.
Credentials belonging to 0 of this vendor's own staff appear in infostealer logs, and no date is recorded for the most recent staff credential. Their staff hold credentials for 1 distinct external services, which is the surface a successful attack on this vendor could reach. This says nothing about how well the product works.
Customer-side infections: 1 (not counted in the band)
These are infections on the machines of people who log in to this vendor's service. They reflect those users' own endpoint hygiene, and a vendor with a large consumer or partner login footprint will always show more of them. Counting that against the vendor would penalise popularity, so this platform does not.
Which third-party services appear
| Service | In our directory | Community rating | Occurrences |
|---|---|---|---|
| nitropack.io | Not listed | – | 1 |
If your own organisation depends on any of these, a successful attack on this vendor and an attack on you share a blast radius. That is worth a question in the security review, not a reason to walk away. Where a service is itself a vendor in our directory it is named and linked, with whatever the community has scored it, so you can read both sides of the dependency in one place. The rating shown is the community's own; it is not derived from this exposure data.
Source: FireIntel (xti.fireintel.net), public domain summary. Source: Hudson Rock (hudsonrock.com), free infostealer intelligence API. About this data. Read 18 hours ago. DBSE does not collect, hold, or sell this data.
Discussions about Drata
-
3 replies
1 month ago