3 ms·
Hi, Adam here, CEO at Drata. While I don’t know all the details about this specific case, I want to clearly lay out and address some of the concerns and misinf
by adamdrata 5y ago
Hi, Adam here, CEO at Drata.
While I don’t know all the details about this specific case, I want to clearly lay out and address some of the concerns and misinformation in your post. We believe trust is the most important aspect of any business, and it’s why we’ve ALWAYS made a point to be very transparent. As a company, we would never develop any software that does what you are claiming. In fact, Drata does just the opposite, by helping companies protect data.
First, we should address the WHY. In order to be SOC 2 compliant, one thing businesses need to do is ensure their employees’ and contractors’ computers are configured securely. The “agent” is one way Drata efficiently does this, especially for teams with remote employees.
Now, let’s look at the HOW:
- The Drata agent is a lightweight, read-only osquery based agent that reads system information such as hard-drive encryption, screen lock timeout, firewall status, etc. Drata collects that information to ensure companies are meeting their security/compliance requirements and so that these companies can prove their SOC2 obligations are being met during audits.
- Regarding the TOS, there is no monitoring or selling of your personal information. That is unequivocally false.
The question you asked Drata about over email was directly related to the TOS, and not the agent (though we’ve explained what the agent does above). As we stated, we don’t sell customer data. We never have and we never will.
I would be happy to chat more to address any concerns you have. You can reach out to me at adam [at] drata.com to chat anytime.
- deleted 5y ago[deleted]
- illud_tempus 5y agoHi Adam. I appreciate that this issue caught your attention. Question: If Drata is nice, why do you portrait yourself as evil in your TOS?