Drata
Description
Drata is a compliance automation platform. It monitors the controls behind frameworks such as SOC 2, ISO 27001 and HIPAA, collects the evidence continuously, and tracks whether the people and devices in the organization meet what those frameworks require.
Connecting Drata to Improvado brings its personnel records — including compliance status and device information — into the same warehouse as the rest of your business data. Audit readiness then stops being a separate dashboard someone checks before a review, and becomes something you can report on alongside everything else.
Setup guide
Follow our setup guide to connect Drata to Improvado.
Click the Connections in the left navigation bar.
Categories on the Data sources page group all available platforms. Use a search to find the required one.
Click on the Drata tile.
Authorize your Drata account using the fields below:
- API Key — the key you create in Drata in the steps below.
- Organization Name — a label of your choice that identifies this connection.
In Drata, select your account at the bottom of the left navigation and choose Settings, then open API Keys.
Click Create API Key and fill in its details:
- Name — cannot be changed once the key is active.
- Expiration date — 12 months, Never, or a custom date. Drata preselects 12 months.
- Allowed IP Addresses — leave empty to accept traffic from anywhere, or see the note below.
Under Access, choose All read. Improvado never writes to Drata, so read and write scopes are not needed.
Save the key and copy it, then enter it into the Improvado authorization form.
If you fill in Allowed IP Addresses, add the Improvado addresses for your cluster, otherwise Drata will refuse our calls. If you do not know which cluster your workspace runs on, ask your Customer Success Manager — or add all of them, which is always safe.
- Main Cluster:
- US Cluster:
- EU Cluster:
Drata documents the same flow in Drata Public API.
After completing the connection process, the Drata connection will appear in your Connected sources list.
When the connection status is Active, and the account status column shows a number of accounts, you can move on to data extraction.
To extract data from the connected sources, check the instructions on how to set up data extraction.
Schema information
The schema information shows all report types you can use to extract data from Drata.
Troubleshooting
The connection stopped working on its own. The usual cause is the API key's expiration date, which Drata preselects at 12 months. Open Settings → API Keys and check the key's status: Expired and Revoked keys are permanent — create a new key and update the connection with it.
Drata rejects the calls but the key looks fine. Check the key's Allowed IP Addresses. If that field is not empty, it must list the Improvado addresses for the cluster your workspace runs on — see the list in the setup guide above.
The key works elsewhere but not here. Confirm its scopes cover reading. A key created with Custom access may carry scopes for other endpoints but not for personnel; All read avoids the question entirely.
Limits
Drata enforces a rate limit of 500 requests per minute per source IP address.
Release notes
You can find information about the latest API changes in the Drata API changelog.
Was this article helpful?
Thanks for the feedback!