Compliance platform

TrustVendor + Drata

Drata provides continuous compliance monitoring for SOC 2, ISO 27001, HIPAA, and more. The TrustVendor integration enriches Drata's vendor risk management module with evidence-grade data from continuously monitored vendor documents.

How data flows

TrustVendor sends structured vendor risk data to Drata's API on a scheduled basis and via webhook on material events. Drata maps this data to vendor risk controls, reducing manual review effort.

How to set up

  1. 1 In Drata, navigate to Integrations and search for TrustVendor.
  2. 2 Authorize the connection using your TrustVendor workspace API key.
  3. 3 Import your Drata vendor list into TrustVendor for monitoring.
  4. 4 Configure alert thresholds for certification expiry, evidence decay, and signal severity.
  5. 5 Review the vendor risk control mapping in Drata and enable automated evidence collection.

Common questions

How often does TrustVendor update Drata?
Certifications and scores sync daily. Material events — new signals, subprocessor changes, SOC 2 exceptions — trigger immediate webhooks.
Does this work for all Drata compliance frameworks?
Yes. TrustVendor's vendor risk data is framework-agnostic. Drata maps the data into whichever frameworks you are pursuing.
How does entity resolution handle vendors whose names differ between my Drata vendor list and TrustVendor?
TrustVendor resolves against primary domain, legal name from RDAP and GLEIF, and known aliases rather than display name. Matches above 0.9 confidence auto-link; matches between 0.7 and 0.9 surface in a review queue in your TrustVendor workspace before they appear in Drata, so no mis-linked vendor risk data ever enters your audit trail.
What Drata vendor risk fields does TrustVendor populate automatically?
TrustVendor writes posture score, assurance score, active certifications with expiry dates, open signal count by severity, and subprocessor count. It also sets the evidence-last-refreshed timestamp so your auditor can confirm the data is not stale — this is the field Drata auditors check most often during vendor risk control review.
Does the TrustVendor integration work with Drata's multi-workspace enterprise accounts?
Each Drata workspace connects to a distinct TrustVendor tenant, so vendor data and alert rules are scoped correctly. If your organization runs separate Drata workspaces for production and staging programs, you configure a separate TrustVendor API key per workspace.
What happens in Drata when a vendor's SOC 2 certificate is approaching expiry?
TrustVendor fires a certification.expiring webhook at 90, 60, 30, and 7 days before the detected expiry date. Each event updates the certification status in Drata and can trigger a Drata task or notification so your team has time to obtain the renewed report before auditors flag the gap.
Book a demo See API pricing