Company: Drata
Co-Founders: Adam Markowitz (CEO), Daniel Marashlian (CTO), Troy Markowitz (COO)
Website: https://drata.com/
![]()
About Drata
Drata was founded in 2020 with the mission to overhaul how governance, risk, and compliance (GRC) had operated for years. Before Drata, our CEO Adam Markowitz had co-founded edtech startup Portfolium, where he learned that earning trust in business is a process, not a pitch. Many organisations would not partner with them until they proved their data would be protected – through frameworks and certifications that required an ongoing, time-consuming manual slog of security questionnaires, audits, and reviews.
After Portfolium was acquired, Adam and his co-founders realised that organisations from enterprises to startups lacked the tools to automate their compliance journeys, which prevented GRC from becoming a business enabler instead of a check-box exercise. That insight led to Drata, and the team validated the problem by talking to dozens of companies and auditors before writing code. They then refused to sell until they used Drata to get SOC 2 compliant themselves.
Following its launch, Drata signed its first 100 customers in 45 days, and by the end of its first year, grew to 1,000 customers and $10 million in ARR. Companies were feeling the same pain that our co-founders experienced at Portfolium, and the need for an automated, continuous solution to prove trust was clear.
With Drata, GRC teams can spend less time on manual work and focus their efforts on understanding and mitigating risk, the type of work they entered the field to do. With the power of AI to assist in repetitive tasks – mapping controls, identifying gaps, collecting evidence – GRC teams of all sizes are able to scale without sacrificing quality.
That work led to Drata’s next era: Agentic Trust Management. Drata has evolved from focusing on automated compliance and control monitoring to a full AI-first trust platform dedicated to helping companies stay audit-ready and showcase their security posture to customers, partners, investors, and auditors continuously. The impact across the U.S. ecosystem is significant, as today Drata has over 8,500 customers from businesses of all sizes, helping them efficiently reach security and compliance standards that historically required large in-house teams and months of effort.
Drata is building what Adam calls the trust layer between great companies, and supports the real-world complexity of global organisations across teams, business units, frameworks, and evolving requirements. This is especially critical as new AI-specific compliance frameworks and regulations are emerging. Companies need assurance around AI adoption and every vendor introducing AI components creates new third-party risk criteria – exactly the problem Drata is solving.
But as AI is helping automate, improve, and support GRC workflows, it also creates pressure on the business – externally and internally. AI can introduce fresh concerns and shine a harsher light on issues like Shadow AI, weak controls, and data integrity. Drata overcomes this challenge through the Drata AI Tool Governance Framework, which establishes risk tiers, approval workflows, vendor assessments, approved-tools registry, and more. That way, Drata can support responsible AI adoption while protecting the data, systems, and customer trust that underpin the business.

Want to find out what TechRound can do for your business?
