Threat & Vulnerability · Integration

Drata

Add Drata to your product for your customers, and give your AI agents governed access to it.

Drata's public API sits at public-api.drata.com and is scoped to a single tenant workspace by the key you issue in the admin area, with regional hosts for accounts provisioned outside the default region. The objects that matter are monitors, which carry a pass or fail state and the evidence backing them, personnel with their onboarding and security training status, assets and devices, and vendors with their risk assessments. A failing monitor is the closest thing Drata has to a finding, and its failure is usually caused by a connected upstream system rather than by anything editable through the API, so remediation means fixing the source and waiting for the next monitor run. Much of the API is read-only by design because evidence integrity is the point, and personnel records are keyed to identities imported from the customer's identity provider, so writes there can be overwritten on the next sync. This is the least-wrong category available: Drata is compliance monitoring rather than vulnerability scanning, though its findings and asset objects line up. fastn holds each customer's key and region and keeps the integration current.

Start freeBook a demo

In your product

Embedded for your customers. Per-tenant auth, no per-customer code, maintained by fastn.

Let a customer connect their own Drata workspace and choose which monitors your product may read

Surface failing monitors and the controls they map to inside your own compliance view

Pull personnel security training and policy acceptance status to show onboarding gaps

Read asset and device inventory so your product can reconcile it against what it already knows

For your AI agents

Governed, audited access for the agents you build, through the MCP server.

Let an agent list failing monitors, name the upstream system causing each failure and draft the remediation note

Have an agent report personnel whose security training is overdue, without writing to identity-synced fields

Audit, per tenant, every Drata object an agent read and any evidence it exported

Example prompt

Which Drata monitors are failing right now, and which upstream system is causing each one?

Set up Drata in 4 steps

  1. 01Enable the Drata connector from your fastn dashboard.
  2. 02Have each customer authorise their own Drata account, so calls run under their credentials rather than a shared key.
  3. 03Decide which findings, detections and assets your product needs, map those fields, then enable the actions and triggers you want.
  4. 04Call it from your product and expose it to your agents through the same governed connection.

Why teams use the Drata integration

What you get by embedding it with fastn instead of building it yourself.

  • Ship a Drata integration without building it. Your customers connect their own Drata account inside your product and work their findings, detections and assets there, with no per-customer code on your side.
  • Handle the part that actually costs time: a rescan re-reports everything, so the same finding arriving twice must not read as two problems. fastn owns the auth, token refresh, rate limits, pagination and breaking-change fixes, so a Drata update is not your on-call problem.
  • One integration serves your product and your agents. The same governed Drata connection powers in-product features and gives AI agents scoped, audited access, so you get security findings in front of the people and systems that act on them without wiring it twice.

Used by these teams

Security & IT

Compare with

AWS Security HubMicrosoft SentinelCrowdStrike Falcon

Often used alongside

Tools the same teams tend to run next to Drata, across other categories.

ServiceNowOktaDatadogMicrosoft Entra ID

Drata integration FAQ

How do I add a Drata integration to my product?

Enable the Drata connector in your fastn dashboard, then let each customer authenticate their own Drata account. fastn handles the OAuth flow, token storage and refresh per tenant, so there is no Drata client code in your app and no per-customer branch in your codebase. Setup is 4 steps.

Do my customers each connect their own Drata account?

Yes. Every connection is scoped to the individual customer, so each authorises their own Drata account and only ever sees their own findings, detections and assets. That per-tenant isolation is the point of an embedded integration: you support the long tail of customer setups without maintaining an integration per customer.

Can AI agents use this Drata integration?

Yes. The same connection is exposed to your agents through the fastn MCP gateway, with permissions scoped per tenant and every call audited. Let an agent list failing monitors, name the upstream system causing each failure and draft the remediation note

Who maintains the Drata integration?

fastn does. When Drata changes an endpoint, deprecates a field or alters its auth, the fix lands in the connector rather than in your backlog, and your customers' connections keep working.

How does a new Drata finding reach my product?

Through event triggers rather than polling, delivered per tenant, so your product reacts when a finding is raised or its severity changes rather than on a schedule that is always slightly out of date.

How is Drata finding noise kept manageable?

Findings are deduplicated per asset so a rescan does not re-raise what you already have, and you can filter by severity and status before anything reaches your product. That matters more here than in most integrations, because the volume is what stops teams acting on any of it.

What can I build with the Drata integration?

A common starting point: let a customer connect their own Drata workspace and choose which monitors your product may read. Teams also use it for the other use cases listed above, and expose it to agents for governed reads and writes.

How much does the Drata integration cost?

It is included. Pricing is based on connected accounts, not on how many connectors you enable, so adding Drata does not change your per-connector cost. You can start free with 3 connected accounts.

Add Drata to your product

Start free with 3 connected accounts. No sales call required, and no per-customer integration code.

Start freeRead the docs
← All integrations