PCI DSS is now live in Drata. Learn More

Authorized Sub-processors

Last Updated:
January 7, 2022


To support delivery of our Services, Drata may engage and use data processors with access to certain Customer Data (each, a “Subprocessor”). This page provides important information about the identity, location and role of each Subprocessor.

Drata currently uses third party Subprocessors to provide infrastructure services, and to help us provide customer support and email notifications. Prior to engaging any third party Subprocessor, Drata performs diligence to evaluate their privacy, security and confidentiality practices, and executes an agreement implementing its applicable obligations.

Infrastructure Sub-processors:

Drata may use the following Subprocessors to host Customer Data or provide other infrastructure that helps with delivery of our Services:

Sub-ProcessorPurposeData Location
Amazon Web Services, Inc.Hosting & InfrastructureUnited States
Cloudflare, Inc.Content delivery network & WAFUnited States
Netlify, Inc.Content delivery networkUnited States

Other Sub-processors:

Drata may use the following Subprocessors to perform other Service functions:

Sub-ProcessorPurposeData Location
CKSource sp. z o.o. sp.k.WYSIWYGUnited States
Datadog, Inc.Analytics on application and infrastructure logs for debugging, troubleshooting, auditing, and reportingUnited States
Functional Software, Inc.Client-side error tracking for debugging, troubleshooting, auditing, and reportingUnited States
Google, Inc.Cloud-based Email Service ProviderUnited States
HubSpot, Inc.CRMUnited States
Intercom, Inc.Cloud-based Customer Support ServicesUnited States
Merge API Inc.HRIS Integration ConnectorUnited States
MessageBird B.V.Socket Communication LayerNetherlands
Send Amply Inc.Cloud-based Email Delivery ServicesUnited States
Shiny Planes, Inc. (DBA LaunchNotes)Product Release UpdatesUnited States
Slack TechnologiesCloud-based Team Chat ServicesUnited States
TYPEFORM SLEmbedded FormsUnited States & Germany
Vitally, Inc.Customer journey analysis and user notificationsUnited States
WorkOS, Inc.SSO Integration ConnectorUnited States
Zapier Inc.Automation WorkflowUnited States


As our business grows and evolves, the Sub-processors we engage may also change. We will endeavor to provide the owner of Customer’s account with notice of any new Subprocessors to the extent required under the Agreement, along with posting such updates here. Please check back frequently for updates.

Case Study:

Learn how Iteratively used Drata to get their SOC 2 report faster than most thought possible, and now monitor their security & compliance posture…