Compliance Integrations / Drata
Push scan results to Drata's Evidence Library as structured compliance evidence. API key setup, per-scan sync, all Drata plans.
AttackerView connects to Drata to automatically push vulnerability evidence to your compliance controls. After each scan completes, AttackerView generates a structured evidence document and uploads it to the relevant controls in Drata's Evidence Library.
The integration works on all Drata plans and uses Drata's Evidence Library API. No custom connection setup or schema configuration required on Drata's side.
The setup uses an API key from Drata. The whole process takes about a minute.
Existing scan results are synced within a minute of connecting. After that, evidence is pushed automatically whenever findings change.
Drata operates in three regional data centers. Select the one that matches your Drata account:
| Region | Dashboard URL | Select in AttackerView |
|---|---|---|
| North America | app.drata.com | North America |
| Europe | app.eu.drata.com | Europe |
| Asia-Pacific | app.apac.drata.com | Asia-Pacific |
If you're not sure which region you're on, check the URL when you log into Drata.
After each scan completes, AttackerView generates a structured JSON evidence document for the scanned domain and uploads it to Drata. The document contains:
{
"source": "AttackerView",
"version": "1.0",
"generatedAt": "2026-02-28T12:00:00Z",
"domain": "example.com",
"scanId": "scan_abc123",
"scanCompletedAt": "2026-02-28T11:55:00Z",
"summary": {
"totalFindings": 12,
"bySeverity": { "critical": 1, "high": 3, "medium": 4, "low": 4 }
},
"findings": [
{
"id": "av:example.com:tls-cert-expiring",
"title": "TLS Certificate Expiring Soon",
"severity": "medium",
"status": "open",
"category": "TLS",
"target": "https://example.com",
"evidence": "Certificate expires in 12 days",
"firstSeenAt": "2026-02-01T00:00:00Z",
"lastSeenAt": "2026-02-28T11:55:00Z",
"compliance": {
"soc2": ["CC6.1"],
"iso27001": ["A.8.24"],
"pciDss": []
},
"remediationUrl": "https://app.attackerview.com/app/d/..."
}
]
}This document is uploaded to every Drata control tagged with a matching compliance framework. For example, a finding with SOC 2 compliance tags gets attached as evidence to all Drata controls tagged "SOC 2".
Drata evidence is synced in two ways:
When you first connect Drata, all existing open findings across your domains are pushed within a minute. You don't need to run a new scan to get your current results into Drata.
After the initial sync, evidence is pushed whenever findings change. This includes:
Each push is scoped to the domain that was scanned. Evidence accumulates in Drata's Evidence Library over time, giving auditors a history of scan results.
AttackerView tags each finding with compliance frameworks (SOC 2, ISO 27001, PCI DSS, HIPAA). For PCI DSS these are supporting evidence for your assessor, not an ASV scan. When evidence is pushed to Drata, it's attached to every Drata control tagged with the matching framework. For example, a finding tagged SOC 2 gets uploaded to all controls in your Drata workspace that carry the "SOC 2" framework tag. No manual mapping needed.
See the full framework and control reference for details.
Evidence appears in Drata's Evidence Library linked to the relevant DCF controls. Each uploaded document includes:
Over time, Drata accumulates a history of evidence uploads that demonstrates continuous monitoring and remediation to auditors.
Go to Settings and remove the Drata integration. This deletes the stored API key from AttackerView and stops all evidence pushes. Evidence already uploaded to Drata is retained per Drata's data retention policies.
If you need to change your API key or region, remove the integration and add it again with the new values.
Your API key may have been revoked or expired in Drata. Generate a new key in Drata's API settings and update it in AttackerView. If the error persists, verify you've selected the correct region.
Existing findings are synced within a minute of connecting. If nothing appeared, check Settings for any error messages on the integration. Common causes: wrong region selected, or API key was revoked.
If you selected the wrong region, evidence uploads will fail with connection errors. Remove the integration and re-add it with the correct region. Check your Drata dashboard URL to confirm which region you're on.
AttackerView maps findings to Drata controls based on compliance framework references. If a finding doesn't have compliance tags (e.g., informational findings), it won't be linked to specific controls. The evidence document will still be available in Drata's general Evidence Library.
Yes. The integration uses Drata's Evidence Library API, which is available on all plans. It does not require Drata's Advanced or Enterprise plan.
Yes. Each integration operates independently. The same findings appear in both platforms.
The integration is paused, not deleted. Evidence pushes stop until you re-upgrade. Data already in Drata is retained. Re-upgrading resumes automatic evidence pushes.
No. The integration is one-directional. AttackerView pushes evidence to Drata. Drata does not send webhooks or data back.
Vanta uses OAuth and syncs all findings every few minutes as structured vulnerability records. Drata uses an API key and receives evidence documents per-domain after each scan. Vanta auto-creates compliance tests; Drata maps evidence to existing controls. See the comparison table for a full breakdown.