# Drata MCP for AI Agents AI Agent Connect

> Drata MCP. Automate your compliance and security monitoring. Track personnel onboarding, audit security policies, and verify cloud asset security across AWS, GCP, and Azure using your AI agent. Stay audit-ready without the manual heavy lifting. Get real-time visibility into SOC 2, ISO 27001, and HIPAA readiness scores, vendor risk classifications, and automated security test failures directly from your chat interface.

## Overview
- **Category:** fort-knox
- **Price:** Free
- **Endpoint:** https://edge.vinkius.com/vk_preview_PzLzOl3HLkJesBjwyD5imrFDq8jv3nHRncdwM61V/ai-agent-connect
- **Tags:** compliance-automation, security-audits, evidence-collection, soc2, iso27001, risk-management

## Description

Connect your Drata account to any AI agent and take full control of your continuous compliance and automated security monitoring through natural conversation. This Connector lets you handle the heavy lifting of compliance without digging through endless dashboards to see if your SOC 2 controls are passing or if your new hires finished their security training. You'll get a clear picture of your security posture, from cloud asset encryption to vendor risk classifications. It turns a manual, spreadsheet-heavy process into a conversation. By using this through the Vinkius catalog, you get a central way to keep your security posture tight without having to jump between different tabs and tools every time an auditor asks a question. It's about moving from reactive firefighting to proactive monitoring, making sure your team stays compliant as your infrastructure grows. Instead of chasing down engineers for screenshots or manually verifying that your RDS databases are encrypted, you can just ask your agent to pull a report. It helps you stay ahead of your audit dates and ensures that your security policies are actually being acknowledged by the team. This is about making compliance a background process rather than a constant hurdle for your security and ops teams.

## Tools

### drata_get_person
Get the compliance onboarding state of a specific employee including MDM enrollment and training milestones. Use this to investigate individual compliance issues or check if a new hire is ready to access systems.

### drata_get_policy
Get detailed status of a specific Drata policy including renewal dates and acknowledgment rates. This helps you assess audit readiness regarding mandatory annual document refreshes.

### drata_list_tests
List Drata automated continuous compliance tests for AWS, GitHub, and Okta. This allows you to monitor real-time security deviations and see which specific checks are failing.

### drata_list_assets
List cloud infrastructure assets monitored by Drata including EC2 instances, RDS databases, and S3 buckets. This helps you quickly identify unencrypted resources or verify compliance status for audit evidence.

### drata_list_controls
List all compliance controls in Drata mapped to frameworks like SOC 2, ISO 27001, and HIPAA. You can use this to identify specific technical or administrative requirements that are currently failing.

### drata_list_frameworks
List active compliance frameworks and their current readiness scores. This gives you a high-level view of your multi-framework posture for board-level reporting or audit planning.

### drata_list_personnel
List all tracked personnel with their security training status, device compliance, and background check clearance. Use this to find out which employees have overdue training or are missing security clearances.

### drata_list_policies
List all security and compliance policies in Drata including Information Security and Data Classification. This is useful for checking which policies need a review or tracking employee acknowledgment rates.

### drata_list_vendors
List third-party vendors in your risk inventory including risk classifications and questionnaire status. Use this to evaluate the security posture of your supply chain and track subprocessor audits.

### drata_get_control
Get the detailed status of a specific Drata control including pass/fail state and automated test evidence. This is helpful for investigating why a control failed or preparing for specific auditor questions.

## Prompt Examples

**Prompt:** 
```
Show me all failing compliance controls
```

**Response:** 
```
Retrieving control statuses... I found 3 failing controls:

| Control Name | Status | Associated Framework |
| :--- | :--- | :--- |
| MFA for IdP Users | **FAILING** | SOC 2 |
| Encrypted Backups | **FAILING** | ISO 27001 |
| Vulnerability Scanning | **FAILING** | HIPAA |

Would you like to see the automated test results for any of these?
```

**Prompt:** 
```
What is the compliance onboarding status for employee John Doe?
```

**Response:** 
```
John Doe's status:

*   **Background Check:** Cleared ✅
*   **Security Training:** Completed ✅
*   **MDM Enrollment:** Enrolled ✅
*   **Policy Acknowledgment:** Pending ⚠️ (Acceptable Use Policy still needs signature)

I can send him a reminder if you'd like.
```

**Prompt:** 
```
List my active compliance frameworks and readiness scores
```

**Response:** 
```
You have 2 active frameworks:

*   **SOC 2 Type II:** 85% Ready
*   **ISO 27001:** 72% Ready

I can provide a breakdown of the remaining controls for either framework.
```

## Capabilities

### Check cloud asset compliance
See the encryption and network status of your AWS, GCP, and Azure resources instantly.

### Track employee security training
Monitor which staff members have completed mandatory training or background checks.

### Monitor real-time test failures
Get alerted on automated security deviations across GitHub, Okta, and cloud providers.

### Review vendor risk scores
Access your third-party risk inventory and questionnaire completion statuses.

### Audit policy acknowledgment
Verify that your team has signed off on required security and data classification policies.

### Get framework readiness scores
Pull high-level readiness percentages for SOC 2, ISO 27001, and HIPAA audits.

## Use Cases

### Audit Evidence Collection
A compliance officer needs to know which controls are failing. They ask the agent to list all failing controls and get the automated test evidence for each one.

### New Hire Onboarding Check
HR needs to know if a new hire is ready to join the team. They ask for the onboarding state of a specific person to check background checks and MDM status.

### Cloud Security Audit
A security engineer wants to find unencrypted databases. They ask the agent to list all assets with a failing encryption status to prioritize remediation.

### Vendor Risk Assessment
A procurement lead needs to see which vendors have high risk. They ask the agent to list all vendors with a Critical risk classification for a report.

## Benefits

- Stop manual data entry by using drata_list_assets to automatically inventory cloud resources and verify encryption status.
- Identify non-compliant staff instantly with drata_list_personnel to ensure everyone completes mandatory security training.
- Spot security gaps early using drata_list_tests to see real-time failures in AWS, GCP, and Azure environments.
- Simplify vendor audits by pulling risk classifications and questionnaire statuses via drata_list_vendors.
- Prepare for audits faster by checking policy acknowledgment rates with drata_list_policies for your whole team.
- Get high-level executive summaries of your audit readiness using drata_list_frameworks for SOC 2 and ISO 27001.

## How It Works

The bottom line is you get a conversational interface for your entire Drata compliance environment.

1. Subscribe to the Drata MCP via the Vinkius marketplace.
2. Enter your Drata Public API Key from your dashboard settings.
3. Ask your agent to list failing controls, check employee status, or audit cloud assets.

## Frequently Asked Questions

**Can the Drata MCP help with my SOC 2 audit?**
Yes, it helps you manage SOC 2 requirements by listing controls, checking framework readiness, and pulling evidence for specific requirements through your AI agent.

**How do I check if my employees finished their security training?**
You can ask your agent to list all personnel and their training status. It will show you who is completed and who is overdue so you can follow up quickly.

**Can I use this to see my cloud security status?**
Yes, it connects to your cloud assets to show you compliance status, encryption verification, and network boundary adherence across major providers.

**How does this help with vendor risk management?**
It allows you to query your vendor risk inventory to see risk classifications, questionnaire statuses, and SOC 2 report reviews for your third-party partners.

**Can I get a summary of my security policies?**
You can ask your agent to list all policies, which includes their current version, review dates, and how many employees have acknowledged them.

**Does this work for ISO 27001 compliance?**
Yes, it tracks ISO 27001 frameworks, specific controls, and the automated tests that provide evidence for those requirements.

**Can my agent check if specific employees have finished their security training?**
Yes. Use the 'list_personnel' or 'get_personnel_status' tools. The agent retrieves the onboarding state, including Security Awareness Training completion and background check clearance for any tracked individual.

**How do I monitor which compliance controls are currently failing?**
Use the 'list_controls' tool to see all controls and 'get_control' for specific details. The agent will fetch exact evaluation states and automated test results to identify failing requirements and their risk logic.

**Can I see my SOC 2 readiness score through natural conversation?**
Absolutely. Use the 'list_frameworks' tool. Your agent will pull the top-level standard boundaries and provide overall readiness scores and aggregated control completion percentages for frameworks like SOC 2.