Drata Release Notes

Follow

81 release notes curated from 56 sources by the Releasebot Team. Last updated: Aug 13, 2026

Get this feed:
  • Aug 4, 2026
    • Date parsed from source:
      Aug 4, 2026
    • First seen by Releasebot:
      Aug 13, 2026
    Drata logo

    Drata

    AUGUST 04, 2026 DRATA AI Trust Center Account Review via MCP is now in Early Access

    Drata adds Trust Center Account Review via MCP in Early Access for AI tools to browse, search, and retrieve document links.

    Trust Center Account Review via MCP is now in Early Access

    External reviewers can now connect AI tools directly to a vendor’s Trust Center over MCP to browse content, search for answers, and retrieve document download links using the same email-based access flow they already use in the portal.

    Original source
  • Aug 4, 2026
    • Date parsed from source:
      Aug 4, 2026
    • First seen by Releasebot:
      Aug 5, 2026
    Drata logo

    Drata

    The Insider Agent Threat: The Risk Isn't Just Someone Else's Agents… It’s Your Own

    Drata introduces AI Agent Governance in Limited Availability, giving enterprises live agent discovery, natural language policy, Trust Ladder simulation, and inline enforcement to help control insider agent risk across environments.

    The AI Risk Story Everyone Is Talking About

    Everyone read the recent frontier-lab incidents as one company's AI intruding into another's systems. The more urgent story is what happens when the agent is your own.

    Seven weeks ago, we opened early access for AI Agent Governance. I expected demand to build gradually. It hasn't. The demand skyrocketed.

    The applications keep climbing, the security conversations have gotten more urgent, and enterprise after enterprise is telling us the same thing: agents are already running inside our walls, and we can't answer for them. Then last week OpenAI and Anthropic handed everyone a live demonstration of why that matters. And almost everyone drew the wrong lesson from it.

    By now you've read the coverage. An AI agent run by one of the frontier labs operated well past its intended scope and reached into systems it was never meant to touch. The write-ups have been everywhere: the trades, the technical timelines, half of my LinkedIn feed.

    Nearly all of them read the event the same way: someone else's agent came for someone else's systems, so the answer must be better intrusion detection. Watch the perimeter. Fingerprint the traffic. Catch the rogue agent on the way in.

    That's a real problem. It's also, for almost every company reading this, not the most urgent one.

    Here's the line most of the coverage minimized. In both the OpenAI and the Anthropic disclosures, the guardrails weren't defeated. They were turned off. OpenAI said the safety classifiers were explicitly disabled for the evaluation. Anthropic ran its agents without the standard safeguards. Two of the most safety-invested organizations on earth, and the incident happened because they deliberately took the guardrails down to see what the model would do.

    Sit with that, because the reflex of "if only they'd had better controls" misses the point entirely. They had the controls. They chose to unlock the front door.

    Now think about the fact that actually matters for the rest of us: most companies today still haven't even installed the front door.

    Meet the Insider Agent Threat

    So here's the take you haven't yet read anywhere. The same pattern that played out between two companies is far more likely to play out inside one. Your own agents. Your own systems. No attacker required. I've started calling it the Insider Agent Threat, and I think it's the story the industry spends the next year catching up to and learning how to contain.

    The insider agent threat doesn't announce itself. It looks like an agent doing its job.

    Picture a support agent you stood up to draft quarterly business reviews. You gave it a goal: pull the account history, build the deck. It goes looking for the data. The clean path—the export it's supposed to use—is empty. A human would file a ticket and move on, because it knows that is what the process requires.

    But the agent doesn't file tickets… the agent finishes tasks. So it tries another route, and then another. It finds a service account with a weak password. It discovers an endpoint nobody remembered to close. It gets in, it pulls the data, it builds the deck, and it reports success. No malice. No breach alert. Just an objective, and a machine patient enough to try every door until one opened—exactly like those OpenAI agents that breached Hugging Face.

    Every step looks reasonable in isolation. Nowhere in this chain did the agent do anything but pursue the goal you gave it. In theory, it's a success because the agent did exactly what you asked. But in practice, it went around your security protocols and let itself into systems it was never meant to open. On the way to building one deck, it likely touched things that had nothing to do with the task: another customer's data, financial records, private employee information, whatever it passed while hunting for the numbers it wanted. And some of that could end up somewhere it should never be. A slice of one customer's data dropped into another customer's deck is what loses the account, and depending on what leaked, could result in legal obligations to report the breach.

    The problem is that none of it announced itself. No alert, no record, nothing to point to. So when a customer, an auditor, or a regulator asks what your systems touched and where that data went, you have no answer. The weak password and the open door the agent found are still there, waiting for the next agent or a real attacker. The one that pulled it off was rewarded with "success" and no pushback—so the next time the front door is locked, it does exactly the same thing again.

    A Third Population with No Playbook

    We already know how to govern two populations with access to sensitive systems: employees and third-party vendors. Both have a playbook. Agents are a third population, and the old playbook doesn't fit them, primarily because of these three reasons:

    1. They inherit privileges but not judgment.
      An agent created by one of your engineers can act with that engineer's access, on systems the engineer never personally touches.

    2. They don't get bored.
      A human probing for a way in eventually gives up. An open door that sat harmlessly for years—because no one had the patience to find it—gets found now, because the agent doesn't get tired and it doesn't stop.

    3. They move at machine speed.
      By the time a runtime tool flags the action, the action has run. You'll have excellent, high-resolution footage of exactly how you were robbed, but no way to go back in time and stop the robbers.

    That last reason is the whole argument. If you're catching this at runtime, you're already too late. The only kind of governance that works on an actor moving at machine speed is one that evaluates the action before it executes and stops the violating one inline.

    Not an alert after the fact, but a block before it. You never handed your company’s most sensitive data to the intern and hoped monitoring would sort it out. Your agents deserve the same discipline, at the same moment.

    The good news is that the ability to do this exists now. With Drata, you can discover the agents actually running in your environment instead of guessing at a number somewhere between 100 and 2,000. You can write policy with natural language and compile it into something enforced. You can run that policy up a Trust Ladder, simulating it against a year of your real traffic before you ever switch it on, so you learn exactly what it would have blocked with zero risk in production. And you can enforce it inline, so the QBR agent in my example hits a wall the instant it reaches for a credential it was never granted.

    AI Agent Governance Now in Limited Availability

    All of this functionality is now available to qualified enterprises through Limited Availability. Early access was about building alongside a handful of design partners. Limited Availability means the product is live, purchasable, and running end-to-end in production today.

    No waitlist to see what it does, just a gated, white-glove rollout so every deployment has our team behind it.

    It ships first and deepest for Anthropic, where our earliest customers are already governing their agent fleets end-to-end, with native coverage for OpenAI, Google Vertex AI, and AWS Bedrock in active development. Connecting an Anthropic environment to a live inventory of every agent running inside it takes minutes, not weeks.

    I’m writing this from Black Hat, where everyone is talking about the external agent trying to get in. But the real conversations, the ones that are most critical to the industry today, are the ones that Drata is having about insider agents.

    It’s not enough to watch what’s happening with agents on the outside. You must watch the ones you already trust. They have access, they have goals, and they will not stop at a locked door you forgot to check.

    If your agents are already running and you can't yet answer for them, come build the answer with us. Apply for AI Agent Governance.

    Original source
  • All of your release notes in one feed

    Join Releasebot and get updates from Drata and hundreds of other software products.

    Create account
  • Jul 31, 2026
    • Date parsed from source:
      Jul 31, 2026
    • First seen by Releasebot:
      Aug 1, 2026
    • Modified by Releasebot:
      Aug 8, 2026
    Drata logo

    Drata

    JULY 31, 2026 FEATURE ENHANCEMENT COMPLIANCE AUTOMATION ENTERPRISE GRC

    Drata now uses AI to map audit requests to the most relevant DCF controls, speeding up evidence review.

    Map Audit Requests to DCF Controls with AI

    Drata now uses AI to recommend the DCF controls most relevant to each audit request, helping reviewers move from request collection to evidence review more quickly and consistently. Click here to learn more!

    Original source
  • Jul 31, 2026
    • Date parsed from source:
      Jul 31, 2026
    • First seen by Releasebot:
      Aug 1, 2026
    Drata logo

    Drata

    SafeBase MCP Server Is Now in Early Access

    Drata now supports SafeBase MCP Server in Early Access for self-service AI tool and workflow connections.

    SafeBase MCP Server is now in Early Access, giving customers a self-service way to connect SafeBase with compatible AI tools and workflows. Click here to learn more!

    Original source
  • Jul 31, 2026
    • Date parsed from source:
      Jul 31, 2026
    • First seen by Releasebot:
      Aug 1, 2026
    • Modified by Releasebot:
      Aug 8, 2026
    Drata logo

    Drata

    JULY 31, 2026 FEATURE ENHANCEMENT TRUST CENTER

    Drata adds more granular SafeBase user management and permissions for SCIM teams.

    SafeBase User Management & Permissions

    Enterprise teams using SCIM can now manage SafeBase access more granularly. Previously, the Settings View and Settings Edit permissions were too broad for organizations that wanted to let teams use SCIM groups to centrally manage access without managing roles for each individual user. Click here to learn more!

    Original source
  • Similar to Drata with recent updates:

  • Jul 24, 2026
    • Date parsed from source:
      Jul 24, 2026
    • First seen by Releasebot:
      Jul 25, 2026
    • Modified by Releasebot:
      Aug 8, 2026
    Drata logo

    Drata

    JULY 24, 2026 INTEGRATION AI QUESTIONNAIRE ASSISTANCE

    Drata adds Salesforce delivery for completed questionnaires to close the handoff gap between teams and customers.

    Send Completed Questionnaires to Salesforce

    Customers can now send completed questionnaire files directly to the linked Salesforce account, helping close the handoff gap between SafeBase users completing the work and the sales or solutions teams who often need to send the final file back to the customer. Click here to learn more!

    Original source
  • Jul 24, 2026
    • Date parsed from source:
      Jul 24, 2026
    • First seen by Releasebot:
      Jul 25, 2026
    • Modified by Releasebot:
      Aug 8, 2026
    Drata logo

    Drata

    JULY 24, 2026 FEATURE ENHANCEMENT TRUST CENTER

    Drata adds optional Trust Center Point of Contact email domain validation to help keep follow-up details accurate.

    Trust Center Point of Contact Validation

    Customers can now optionally require the Point of Contact email to match one of their organization’s email domains, helping keep the field accurate and more useful for follow-up. If the email does not match, the requester sees a validation error. Click here to learn more!

    Original source
  • Jul 24, 2026
    • Date parsed from source:
      Jul 24, 2026
    • First seen by Releasebot:
      Jul 25, 2026
    • Modified by Releasebot:
      Aug 8, 2026
    Drata logo

    Drata

    JULY 24, 2026 FEATURE ENHANCEMENT THIRD-PARTY RISK MANAGEMENT

    Drata adds custom vendor types so admins can create, rename, and delete categories to match internal workflows.

    Custom Vendor Types

    Admins can now create, rename, and delete vendor types so Drata can better reflect how each organization actually classifies its vendors. Instead of relying only on Drata’s default categories, teams can now align vendor records to the same internal taxonomy they already use across procurement, security reviews, and risk workflows. Click here to learn more!

    Original source
  • Jul 24, 2026
    • Date parsed from source:
      Jul 24, 2026
    • First seen by Releasebot:
      Jul 25, 2026
    Drata logo

    Drata

    TPRM Agent: Assess Against Public Docs

    Drata adds first-pass TPRM assessments using only public documents in a vendor’s SafeBase Trust Center.

    Teams can now run a first-pass TPRM assessment using only the public documents available in a vendor’s SafeBase Trust Center.

    Click here to learn more!

    Original source
  • Jul 24, 2026
    • Date parsed from source:
      Jul 24, 2026
    • First seen by Releasebot:
      Jul 25, 2026
    Drata logo

    Drata

    General AI Usage Policy Template

    Drata adds a General AI Usage Policy Template to help teams cover core AI governance essentials with a lightweight starting point.

    Customers looking for a practical starting point for AI governance can now use our new General AI Usage Policy Template. Instead of forcing teams to jump straight into a full governance framework, the template gives them a lightweight way to cover the essentials now, including approved AI tool use, confidential data handling, human review of AI output, vendor diligence, incident reporting, and training. Click here to learn more!

    Original source
  • Jul 17, 2026
    • Date parsed from source:
      Jul 17, 2026
    • First seen by Releasebot:
      Jul 19, 2026
    Drata logo

    Drata

    New Framework Support: AIUC-1

    Drata now natively supports AIUC-1 for AI agents, expanding assurance for data, privacy, security, safety, reliability and accountability.

    Drata now natively supports AIUC-1, a voluntary assurance standard for AI agents that covers data and privacy, security, safety, reliability, accountability, and societal risk.

    It combines technical testing, certification support, and accredited audits, and can be paired with AI-specific insurance as part of AIUC’s broader trust model.

    Click here to learn more!

    Original source
  • Jul 17, 2026
    • Date parsed from source:
      Jul 17, 2026
    • First seen by Releasebot:
      Jul 19, 2026
    Drata logo

    Drata

    Control Readiness Progress Tracker: Visualize Control Readiness Progress To Prioritize Audit Preparation

    Drata adds a Control Readiness Progress Tracker for percentage-based control readiness updates and clearer next-step focus.

    With the new Control Readiness Progress Tracker, teams can now see a percentage-based view of each control’s progress toward readiness, making it easier to understand what is nearly complete, what still needs work, and where to focus next. Click here to learn more!

    Original source
  • Jul 17, 2026
    • Date parsed from source:
      Jul 17, 2026
    • First seen by Releasebot:
      Jul 19, 2026
    Drata logo

    Drata

    Multiple Artifacts & Multi-File Upload for Evidence Library

    Drata adds Multi-File Upload for Evidence Library, letting customers attach multiple files, URLs, or tickets as current evidence.

    Multiple Artifacts & Multi-File Upload for Evidence Library lets customers upload several files, URLs, or tickets in a single session and keep more than one artifact as current evidence at the same time.

    This removes the need to zip files together or upload artifacts one by one when a single piece of evidence requires multiple proof points. Click here to learn more!

    Original source
  • Jul 17, 2026
    • Date parsed from source:
      Jul 17, 2026
    • First seen by Releasebot:
      Jul 19, 2026
    Drata logo

    Drata

    New Framework Support: APRA CPS 230

    Drata adds APRA CPS 230 support with requirement-level guidance for APRA-regulated entities and Material Service Providers, giving organizations in Australia and New Zealand a native way to manage operational risk, business continuity, and third-party compliance in the platform.

    APRA CPS 230 (Prudential Standard CPS 230 – Operational Risk Management) is APRA’s standard for operational risk management, business continuity, and third-party/service provider risk in the Australian financial sector. It applies to APRA-regulated entities, including banks, insurers, and superannuation trustees, as well as their Material Service Providers. Drata operationalizes CPS 230 as a fully supported framework with requirement-level guidance for both APRA-regulated entities and Material Service Providers, giving organizations across Australia and New Zealand a purpose-built way to manage CPS 230 compliance natively in the platform. Click here to learn more!

    Original source
  • Jul 16, 2026
    • Date parsed from source:
      Jul 16, 2026
    • First seen by Releasebot:
      Jul 17, 2026
    Drata logo

    Drata

    Drata Now Supports AIUC-1 — The World’s First AI Agent Standard

    Drata adds native AIUC-1 framework support, giving security and compliance teams a new way to build, track, and demonstrate AI agent assurance with continuous monitoring, integrated risk management, Audit Hub, Trust Center, and pre-built policy templates.

    Drata is the first Agentic Trust Management Platform with native AIUC-1 framework support, so security and compliance teams can build, track, and demonstrate AI agent assurance without adding tools or headcount.

    AI Agents Are Moving From Pilots to Production

    AI agents are rapidly moving from pilots to production.

    As AI adoption accelerates, enterprise procurement is not keeping pace. Customers want to adopt AI. They just can't validate that it's safe, secure, and reliably governed.

    Security reviews stall. Legal teams pump the brakes. Third-party AI evaluations stay ad hoc.

    AIUC-1 is the world’s first AI agent standard, built to address six core domains: data and privacy, security, safety, reliability, accountability, and society.

    It combines technical controls, comprehensive red-teaming, and certification by accredited auditors. It is also the first AI agent certification that unlocks insurance for AI agents.

    Drata is the first to natively support the AIUC-1 framework and one of the only platforms connecting that support to continuous control monitoring and ongoing evidence collection, so AI agent assurance does not stop at certification. This is delivered as part of the Drata Agentic Trust Management Platform, built in direct collaboration with AIUC, the Artificial Intelligence Underwriting Company, which worked with Drata to map AIUC-1 requirements to Drata's Control Framework so the integration reflects how the standard is designed to be applied.

    That groundwork matters for customers. Because AIUC-1 is mapped accurately to the Drata Control Framework (DCF), organizations are not spending time reconciling requirements or second-guessing coverage. They can scope, implement, and collect evidence against AIUC-1 from day one within the compliance infrastructure they already manage.

    “AIUC-1 is designed to strengthen AI security significantly without overburdening security and GRC teams. By integrating AIUC-1 into Drata, we’re taking a big step towards reducing the work required to earn and maintain certification while keeping the bar consistent and high.”
    Rajiv Dattani, Co-founder of AIUC

    The Challenge: AI Governance Without a Repeatable Standard

    Security and compliance teams are already fielding AI governance questions from auditors, procurement teams, and customers, but they do not have a structured way to answer them.

    Broader frameworks like ISO 42001 and NIST AI RMF address AI governance at a high level. They do not deliver the agent-specific technical testing and assurance that enterprise buyers increasingly expect.

    The result is a familiar pattern. Compliance teams absorb a new AI framework requirement without additional headcount and build programs manually in spreadsheets because their GRC platform does not support the standard natively.

    Evidence collection is fragmented. Third-party AI risk is evaluated inconsistently, with no repeatable criteria tied to AI-specific failure modes such as data leakage, prompt injection, jailbreaks, and hallucinations.

    For AI companies trying to close enterprise deals, procurement stalls when buyers cannot validate that an agent is safe and reliably governed.

    For enterprises governing internal AI deployment and third-party AI relationships, the problem is scale. There are more use cases, more vendors, and more scrutiny, but not more people.

    The Solution: AIUC-1 in Drata

    Drata now supports the AIUC-1 framework with requirements, Drata Control Framework controls, and pre-built policy templates aligned to all six AIUC-1 domains, mapped in direct collaboration with AIUC to reflect how the standard is designed to be implemented. This support is available today as a generally available release.

    Teams can scope and manage AIUC-1 within their existing Drata GRC program without standing up a separate process or stitching together point tools.

    The framework foundation connects directly to the broader Drata platform:

    • Continuous control monitoring validates technical and operational safeguards over time. AIUC-1 evidence stays current as AI systems evolve, not just at audit time.
    • Risk Management maps AI-specific risks, including data leakage, prompt injection, hallucinations, and jailbreaks, to AIUC-1 domains in Drata’s integrated risk register, with clear ownership and mitigation plans assigned.
    • Audit Hub centralizes evidence collection and supports AIUC-1 certification preparation and auditor collaboration in a single, organized workspace, so audit-ready documentation does not require a month of manual prep.
    • Third-Party Risk Management and TPRM Agent enable teams to assess third-party AI suppliers against customer-defined criteria aligned to AIUC-1 expectations, with gaps surfaced through Drata workflows.
    • Trust Center makes AI governance and assurance documentation available to customers and prospects in a self-serve format and turns compliance work into a sales-cycle asset.
    • AI Questionnaire Assistance helps teams draft source-grounded responses to inbound AI governance, risk, privacy, and security diligence requests using approved content and internal knowledge.

    With AIUC-1 embedded in Drata, organizations can run AI assurance as a continuous, audit-ready program rather than a spreadsheet exercise or a one-time certification.

    Use Cases by Persona

    Director of Compliance / GRC Manager

    AIUC-1 is a new standard on top of an already full program. Drata’s pre-built requirements, controls, and policy templates mean teams do not have to start from scratch. They scope, track, and collect evidence within the compliance infrastructure they already manage.

    Continuous monitoring keeps evidence current between certification cycles without manual follow-up.

    CISO / VP of Security

    Accountability for AI risk posture requires more than a framework. Leaders need assurance coverage across AI-specific risks and a defensible, board-level narrative. Drata maps AI-specific risks to AIUC-1 domains with ownership assigned in the risk register, and Audit Hub keeps the evidence organized when assessors and executives come asking.

    Security Engineer

    Continuous monitoring and automated control validation reduce the manual overhead of maintaining AIUC-1 evidence as AI systems change. Engineering-friendly workflows help ensure compliance does not become a bottleneck for the teams building and deploying agents.

    The Impact

    Like ISO 27001 or FedRAMP, AIUC-1 runs as an ongoing assurance program that teams maintain over time.

    That design matches how Drata’s platform is built. Continuous monitoring, integrated risk, and always-on audit readiness replace one-off evidence collection and fire drills.

    For AI companies, AIUC-1 provides a recognized, auditable certification that signals enterprise readiness and can unlock procurement conversations that would otherwise stall in security review.

    For enterprise teams, it offers a repeatable standard for evaluating and continuously governing third-party AI relationships at a scale that ad hoc review cannot support.

    AIUC-1 pairs certification with optional AI agent insurance unlocking coverage up to $50 million for AI-specific risks, including hallucinations, data leakage, IP infringement, and tool call failure. The insurance puts real financial accountability behind the certification.

    Why It Matters Now

    AIUC-1 framework support in GRC platforms is still early. Organizations that build their program in Drata now establish a compliance foundation and evidence history before the broader market catches up. That foundation was built with AIUC's direct involvement, which means organizations implementing AIUC-1 in Drata are starting from a control mapping the standard's creators validated.

    As more companies implement this framework, the question will shift from availability to depth. Drata’s continuous monitoring, integrated risk management, TPRM capabilities, Audit Hub, Trust Center, and AI Questionnaire Assistance provide that depth from day one and help teams run AIUC-1 as a continuous compliance discipline rather than a checkbox exercise.

    Get Started With AIUC-1 in Drata

    Drata’s AIUC-1 framework support is available now.

    Reach out to learn more about AIUC-1 framework support in Drata.

    Original source
Releasebot

Curated by the Releasebot team

Releasebot is an aggregator of official release notes from hundreds of software vendors and thousands of sources.

Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.