Responsible AI at Drata
How Drata develops and uses AI responsibly
Last Updated: September 17, 2026
Purpose and Scope
Drata is committed to developing and using artificial intelligence responsibly across our products and services. Our approach is grounded in privacy, security, fairness, reliability, transparency, human oversight, customer control, and accountability.
This statement describes Drata’s general approach to AI systems that we develop, deploy, or integrate into our products and services. Specific functionality and controls may vary by service, configuration, and region. Service-specific commitments are described in the applicable customer agreement and product documentation.
Customers remain responsible for determining whether and how to use Drata’s AI features and for governing AI systems that they connect to or manage through Drata.
1. Responsible AI Principles
Drata applies the following principles throughout the AI lifecycle:
Privacy and security. We design AI systems to protect Customer Data and limit unnecessary collection, use, retention, and disclosure.
Fairness and reliability. We evaluate AI systems for harmful bias and fairness risks where relevant to their intended use, affected individuals, and reasonably foreseeable impacts.
Transparency. We provide information designed to help customers understand when AI is being used and how relevant outputs are generated.
Human oversight and customer control. We design AI to support human judgment and provide customers with controls to manage supported AI features.
Accountability. We establish ownership, review, documentation, monitoring, and escalation processes for AI systems throughout their lifecycle.
2. Customer Data and Model Training
“Customer Data” has the meaning provided in the applicable customer agreement.
Drata processes Customer Data through AI features only as permitted by the applicable agreement and customer instructions. By default, Drata does not use Customer Data to train shared or general-purpose AI models or models used to provide services to other customers. If a customer expressly authorizes Drata to use its Customer Data to train or customize a tenant-specific model, Drata limits that use to the customer’s authorized purpose and applies appropriate safeguards, which may include data minimization, access restrictions, data sanitization, and technical and organizational controls designed to protect the data. Drata may use aggregated or deidentified data derived from Customer Data to train and improve models, provided the data has been stripped of personal information and is not reasonably capable of being used to identify or reidentify the Customer, any user, or any individual.
Drata designs AI features to use only the Customer Data reasonably necessary for the applicable functionality. Available controls may allow customers to limit data sources, manage access, apply filtering or redaction, and configure retention-related settings.
3. Third-Party Models
Drata may integrate vetted third-party models, including large language models, into certain products and services. Before approving a model for use, Drata evaluates its security and privacy practices, performance, reliability, safety, data-use terms, and suitability for the proposed use.
Drata uses contractual and technical safeguards designed to prevent third-party model providers from using Customer Data to train their general-purpose models and to limit processing and retention to what is necessary to provide the relevant functionality.
The models, providers, data flows, and controls applicable to a feature may vary. Additional information is provided through applicable customer agreements, product documentation, and customer assurance materials.
4. Testing, Monitoring, and Human Oversight
Drata reviews AI systems before production deployment using processes appropriate to the system’s intended purpose and risk. Testing may address accuracy, reliability, security, privacy, safety, and the quality and integrity of generated outputs.
Drata monitors deployed AI systems for material performance issues or unexpected behavior where appropriate. Identified issues are evaluated and addressed through applicable escalation and remediation processes.
Drata incorporates human oversight into the design, review, and operation of its AI systems. Depending on the feature, customers may be able to review, approve, reject, correct, or override AI-generated outputs. Drata’s AI features are designed to support, not replace, human judgment. Customers should review AI-generated outputs before using them in decisions that may materially affect an individual or carry legal or regulatory consequences.
5. Transparency and Customer Controls
Drata provides information designed to help customers understand when and how AI is used within its products and services, This may include notices or other indicators when users interact directly with an AI agent.
Depending on the feature and configuration, customers may be able to enable or disable AI functionality, restrict data sources, manage access, review AI-generated content or actions, and provide corrections or feedback.
6. Security and Privacy
Drata applies security and privacy review processes to AI systems throughout their lifecycle. These processes may include secure development practices, privacy and security assessments, access controls, encryption, logging and monitoring, incident response, third-party risk management, and retention and deletion controls.
Drata applies privacy-by-design principles to AI development, including data minimization, purpose limitation, transparency, and appropriate safeguards for personal data. Additional information is available through Drata’s Security and Compliance resources, Privacy Notice, Trust Center, customer agreements, and product documentation.
7. Governance, Accountability, and Regulatory Alignment
Drata maintains a company-wide AI governance program with participation from engineering, data science, security, privacy, legal, compliance, and business leadership. Its AI management system is certified to ISO/IEC 42001. The program includes assigned ownership, AI system documentation, risk and impact assessments, predeployment review, third-party oversight, monitoring, training, and defined escalation and remediation processes.
Drata monitors developments in applicable AI, privacy, and security laws and evaluates its obligations based on the intended purpose, capabilities, and context of each AI system.
Drata periodically reviews this statement and may update it as its products, practices, technology, and applicable requirements evolve. Questions about these practices may be directed to [email protected].