Jellyfish Accelerates Security Reviews with Drata’s New Trust Center
Challenge
Because Jellyfish connects directly into customers’ core engineering systems, every security review needs to be fast and predictable, yet the team was relying on the legacy Drata Trust Center as a static repository.
Each access request required manual review and approval, with no connection to core sales systems and no way for prospects to view documents directly in the browser, slowing security reviews in high-velocity sales cycles.
Solution
Migrated from the legacy Drata Trust Center to the latest Drata Trust Center experience to create a premium, fully branded, self-serve destination that reflects Jellyfish’s security maturity.
Connected the new Trust Center to Salesforce so NDA checks and document access approvals are triggered by predefined CRM criteria, significantly reducing manual gatekeeping.
Continued to use Drata as the central source of truth for frameworks, policies, and controls so Trust Center content stays aligned with Jellyfish’s continuously monitored internal environment.
Results
Turnaround time for document access dropped from minutes or hours down to seconds as NDA checks and approval routing shifted into automated Salesforce-driven workflows.
Saved roughly 2–3 hours per week that previously went into manually filling out and processing inbound questionnaires, allowing the security team to focus more time on reviewing outputs and managing the broader program.
International prospects no longer have to wait for a security analyst to come online to get assurance documentation—they now receive instant access when their buying intent is highest.
Background
Jellyfish is an engineering intelligence platform that connects directly into customers’ core engineering systems, so trust, security, and privacy are fundamental to the product and to every enterprise relationship. As Senior Security Analyst at Jellyfish, James Richardson helps manage governance, risk, and compliance programs and gives prospects and customers clear insight into how Jellyfish protects their data.
As Jellyfish’s customer base and deal volume grew, security reviews became a standard part of enterprise opportunities. The team wanted a more repeatable, streamlined way to show buyers the controls, policies, and audit artifacts behind the product without pulling Security into every request. When Drata announced its acquisition of SafeBase and introduced the new Trust Center experience, the Jellyfish team saw a clear opportunity to modernize how they shared compliance evidence and partnered with Drata to make the move quickly.
“Trust isn't just a compliance checkbox for us, it’s a foundational pillar of our business model. Providing frictionless transparency into our security controls accelerates our sales cycles, protects our brand, and builds long-term, confident partnerships with enterprise organizations.”
From Manual Trust Requests to a Branded, Self-Serve Trust Center
Before the migration, Jellyfish’s trust-sharing process combined the legacy Drata Trust Center with manual workflows. When a prospect requested security documentation or audit reports, it kicked off a series of emails, NDA checks, and file-sharing steps that pulled Security into each interaction. The legacy Trust Center centralized artifacts but worked more like a static repository than an automated, customer-facing experience.
As Jellyfish’s sales motion grew more dynamic, the team wanted a Trust Center experience that matched their security maturity and enterprise buyers’ expectations. They needed a way to keep their security documentation centralized while adding modern, self-serve access and clear guardrails.
The new Drata Trust Center provided that next step. Jellyfish migrated from the legacy experience to a more customizable, branded Trust Center that organizes content in a way that reflects the Jellyfish brand and buyer expectations. Historical artifacts were imported quickly, and the transition did not disrupt active sales pipelines—a key requirement for the team.
Automating Approvals and Aligning Security and Sales
With the new Trust Center in place, Jellyfish focused on automation and alignment with Sales. The native Salesforce integration was a standout capability, allowing the team to drive access approvals based on predefined CRM criteria instead of reviewing each request manually.
“We saw value almost instantly. Within the first week of going live, automated approvals began routing automatically, immediately freeing up time usually spent manually vetting these requests.”
That shift removed the constant context-switching of manual document gatekeeping and helped reposition the security team as partners to Sales. Account Executives can now direct prospects to the Trust Center knowing that NDA workflows and document approvals will run in the background.
“Instead of Security acting as a perceived speed bump in the sales process, we have provided Sales with an automated, self-serve storefront that empowers them to close deals faster without waiting on manual security reviews in most cases.”
Day-to-day work has moved from reacting to ticket queues and access requests to focusing on the broader security program. Automation now carries the standard approval workflow, so the team can stay focused on higher-impact work instead of one-off document requests.
Turning Security Reviews into a Driver of Sales Velocity
As more activity moved through the new Trust Center, Jellyfish saw measurable impact on deal flow and customer experience. Prospects can now self-serve, sign necessary agreements, and access security documentation autonomously, which drastically reduces back-and-forth and keeps momentum high in active deals.
Jellyfish has also seen a clear improvement in standard security review turnaround times. Automating NDA and document-release workflows through Salesforce has reduced delays at the start of opportunities and removed a traditional bottleneck in the sales process. Questionnaire completion has also improved: Drata’s AI Questionnaire Assistance handles the repetitive work of filling in answers so the team can focus on reviewing outputs for accuracy.
“The move transformed compliance from a backend operational function into a direct driver of sales velocity. By removing manual friction from the security review process, we’ve successfully accelerated our deal cycles while protecting our team's internal bandwidth.”
What Drata Unlocked for the Team
Beyond the Trust Center migration, Drata underpins Jellyfish’s broader trust, compliance, and GRC program as the central source of truth for continuous compliance. The platform allows the team to manage frameworks, monitor controls in real time, and maintain continuous audit readiness instead of concentrating effort into a once-a-year sprint.
Centralized policy management and documentation workflows in Drata also help keep the Trust Center accurate and current. Policies and documentation live in a single, organized system with tracking, version control, and approvals, which eliminates the fragmentation of documents spread across multiple drives. Because Drata tests and verifies internal controls continuously, the security posture surfaced externally in the Trust Center stays aligned with live internal operations.
“Moving to the new Drata Trust Center helped our team eliminate manual bottlenecks, align more closely with our sales organization, and use compliance as a competitive advantage.”
Future Outlook
Looking ahead, Jellyfish plans to use the Trust Center as an even more dynamic security hub. The team is interested in supporting additional questionnaire formats, mapping more granular control data into the Trust Center, and exploring new AI capabilities that could further streamline assurance workflows.
Chart Your Course
Navigate to new worlds of trust with Drata.
Chart Your Course
Navigate to new worlds of trust with Drata.