How pairing Drata's continuous control monitoring with Aikido Security's prioritized vulnerability management and on-demand AI pentesting closes the gap between monitoring controls in real time and keeping the evidence behind them just as current.
Drata's Partner POV series spotlights the leaders and teams in our partner ecosystem who are helping customers modernize security, compliance, and trust. In each installment, we share a partner's on-the-ground perspective on what they're seeing in the market—what's changing, what's proving difficult, and what's working, plus practical takeaways for building stronger, more resilient programs.
In this edition, we're joined by Eric Gallegos, Head of Tech Alliances at Aikido Security. He shares what he's hearing from teams in the middle of a SOC 2 or ISO 27001 audit, and why pairing Drata's continuous, evidence-backed control monitoring with Aikido's prioritized vulnerability management and on-demand penetration testing (pentesting) helps those teams walk into an audit with proof that's actually current.
Introducing Aikido Security
Security tooling has a sprawl problem. Most teams end up stitching together five or six point tools to cover code, cloud, and runtime, and then drowning in the alerts all of them generate. That's the problem Aikido was built to solve.
Aikido is a software security platform built for developers. It brings code, cloud, and runtime security into one place and auto-triages the results, cutting irrelevant alerts by around 85% so teams see the handful of issues that actually matter instead of hundreds of false positives.
What sets Aikido apart, Gallegos told us, is coverage that spans the full development lifecycle end to end, from code scanning (SAST), dynamic testing (DAST), and open-source dependency analysis (SCA) to cloud posture and now AI Pentesting, while still going deep in each category rather than making teams assemble and maintain a patchwork of separate products.
What Led Aikido to Partner With Drata
The partnership existed in how customers worked before it existed on paper. "Teams were already running Drata for governance and coming to us separately for technical vulnerability management and the pentest evidence auditors usually ask for," Gallegos said. As he describes it, the partnership was simply catching up to what shared customers were already doing.
From there, it grew deliberately, with each step aimed at simplifying the audit itself. Aikido and Drata started by closing the most obvious gap with a vulnerability data integration, so a finding in Aikido becomes audit evidence in Drata without a manual export. Then Aikido added AI Pentesting, so the report an auditor asks for is always up to date instead of months old. "Each step of the partnership was done to make the work of the audit easier for our customers," Gallegos said. The aim was always to ease the audit, not to add another tool to the stack.
Top of Mind Challenges
The pattern Gallegos sees most often: customers arrive already in the middle of an audit and discover their technical vulnerability management doesn't hold up to auditor scrutiny. "It's unpatched vulnerabilities, no current pentest evidence, or alerts nobody has triaged," he said. It surfaces at the worst possible moment, mid-audit.
Aikido's answer is to collapse two disconnected processes into one. Instead of running remediation in one place and assembling audit evidence in another, teams get a single feed of prioritized, verified vulnerabilities that maps to the controls Drata is already tracking. Remediation work and audit evidence come from the same source, so fixing an issue and proving it to an auditor are no longer separate jobs.
Security, Compliance, Risk, and Trust Trends
The clearest shift Gallegos and the Aikido team report is that pentesting is moving from an annual, weeks-long manual project to something continuous and on demand. "Auditors and customers increasingly expect current, tested evidence," he said. "Not a report from eight months ago."
Aikido built AI Pentesting specifically to make that expectation achievable: hundreds of autonomous agents test an environment and re-exploit every finding before it's reported, turning a pentest that traditionally takes weeks into a full, auditor-ready result in about a business day. The reason that matters: the evidence attached to a control can finally keep pace with the control itself.
The Underestimated Shift
The most underestimated shift, in Gallegos's view, is a gap hiding inside the phrase everyone already uses. "'Continuous compliance' has mostly come to mean monitoring controls in real time," he said, "but the evidence attached to those controls (a pentest report, a vulnerability scan) still gets refreshed on a slow, manual cadence." The monitoring went continuous; the proof didn't.
His recommendation is direct: organizations should push their vendors to close that gap. If the monitoring is continuous, the underlying proof should be too. The teams that get this right stop treating evidence as something they scramble to assemble before an assessment and start treating it as something that's simply always current, the same way their control monitoring already is.
How Drata and Aikido Work Together
Drata and Aikido cover two halves of the same audit. Drata handles governance and control automation, continuously monitoring where controls stand. Aikido supplies the technical depth beneath them, vulnerability management and now pentest evidence, and syncs that data into Drata automatically.
In practice, that means a vulnerability Aikido finds becomes audit evidence in Drata without a manual export. Teams run their audit cycle, control monitoring, technical vulnerability management, and pentest evidence inside one connected workflow instead of moving data between disconnected systems. And under the current offer, new Drata customers receive an agentic pentest worth up to $4,000, delivered in about a business day, so they walk into an audit with a current, auditor-ready report instead of scheduling a separate pentest and waiting weeks for it.
This is something neither product does as well alone. Control automation shows where you stand but not whether the technical evidence behind each control is current, and vulnerability and pentest data are far more valuable when they land directly where controls are already managed. Bring them together and a finding, a fix, and the proof an auditor needs all live in the same place.
Where Customers See the Biggest Gains
The combination pays off most for teams heading into a SOC 2 Type 2 or ISO 27001 audit who need both sides covered, and especially for lean security teams, where one or two people own compliance and can't absorb weeks of back-and-forth with a separate pentest vendor on top of everything else. A few workflows stand out:
- Evidence that assembles itself. The vulnerability data sync is the one customers mention first, because it removes a manual step they used to do by hand. A finding in Aikido becomes evidence in Drata without an export.
- Audit-ready pentest evidence on demand. The complimentary agentic pentest for new Drata customers has become a standout, unexpected win. "Customers are surprised that a pentest which traditionally takes weeks and costs thousands of dollars can come back in about a day," Gallegos said. "With every finding independently re-tested before it's included in the report."
- One workflow for lean teams. For the one- or two-person security function, running remediation and audit evidence from a single connected source is the difference between keeping up and falling behind.
Why the Pairing Clicks for GRC Teams
What resonates most is that the two tools remove work rather than add it. The vulnerability sync eliminates manual exports teams used to handle by hand, and the on-demand pentest removes a weeks-long dependency from the critical path to an audit. The reaction Gallegos hears most is relief: the evidence auditors ask for is already there, already current, and already where the team manages its controls.
What's Coming Next
The next step, and what Gallegos is most excited to bring to the partnership, is letting a Drata customer launch an Aikido pentest from inside Drata, see the result in Drata, and have the pentest report land in Drata as control evidence, with no switching tools and no manual upload.
Scope for the first version is small on purpose: one OAuth app, three API calls, and one existing integration. Fully hands-off pentesting is on Aikido's roadmap and isn't required for v1. The restraint is deliberate: a tight, useful first release rather than a sprawling one, aimed at the same goal that has shaped every step of the partnership, making the audit easier.
See what Aikido Security plus Drata can do for your organization today.

