Vinkius
Drata

Drata MCP. Audit your entire compliance stack via chat.

Claude Claude
ChatGPT ChatGPT
Cursor Cursor
Gemini Gemini
Windsurf Windsurf
VS Code VS Code
JetBrains JetBrains
Vercel Vercel
See Vinkius in Action

Works with every AI agent you already use

…and any MCP-compatible client

Drata MCP on Cursor AI Code Editor MCP Client Drata MCP on Claude Desktop App MCP Integration Drata MCP on OpenAI Agents SDK MCP Compatible Drata MCP on Visual Studio Code MCP Extension Client Drata MCP on GitHub Copilot AI Agent MCP Integration Drata MCP on Google Gemini AI MCP Integration Drata MCP on Lovable AI Development MCP Client Drata MCP on Mistral AI Agents MCP Compatible Drata MCP on Amazon AWS Bedrock MCP Support

Just plug in your AI agents and start using Vinkius.

Drata MCP Server monitors compliance and security by giving your AI agent direct access to your entire governance stack. You can check if a specific employee is trained, list all failing controls, audit policies for renewal dates, or verify cloud asset encryption status—all without leaving your chat client.

This tool connects your AI agent to Drata's full risk and compliance record.

What your AI agents can do

Drata get control

Gets a specific control's pass/fail state, the automated test evidence, and the official risk language used by auditors.

Drata get person

Retrieves a person's full compliance status, including MDM enrollment, training completion, and background check clearance.

Drata get policy

Gets detailed status for one policy, including its renewal date, acknowledgment rates, and owner assignment.

+ 7 more capabilities included
Check compliance status of a specific control

You can run drata_get_control to get a control's pass/fail state, the evidence from automated tests, and the auditor language defining the risk.

Audit an employee's compliance profile

Use drata_get_person to check a specific person's onboarding status, including MDM enrollment, training dates, and background check clearance.

Get details on a security policy

Run drata_get_policy to find a policy's renewal date, who acknowledged it, and its version history.

List all cloud assets and their compliance status

Invoke drata_list_assets to list infrastructure like EC2 or S3 buckets, showing their compliance status and if they're encrypted.

View all technical compliance requirements

Execute drata_list_controls to list every compliance requirement, showing its status, mapped frameworks, and owner.

Summarize compliance readiness by framework

Call drata_list_frameworks to list active frameworks (SOC 2, HIPAA, etc.) and get their current readiness scores.

List all personnel and their security gaps

Use drata_list_personnel to get a full roster showing who is non-compliant, who has overdue training, and device compliance status.

Supported MCP Clients

OAuth 2.0 Compatible
Vinkius runs on Claude Claude
Vinkius runs on ChatGPT ChatGPT
Vinkius runs on Cursor Cursor
Vinkius runs on Gemini Gemini
Vinkius runs on VS Code VS Code
Vinkius runs on JetBrains JetBrains
Vinkius runs on Vercel Vercel
Vinkius runs on Zendesk Zendesk
+ other MCP clients
Free for Subscribers

Waiting for input…

AI Agent

Drata MCP Server: 10 Tools for Compliance & Audit

Use these tools to query, list, and audit every aspect of your organization's compliance posture, from cloud assets to individual employee training records.

Make your AI actually useful.

Add this MCP to Claude, Cursor, or Windsurf and your AI stops guessing. It gets real tools to look things up, take action, and handle the stuff you keep doing by hand.

Start using Drata on Vinkius
drata019d7589

drata get control

Gets a specific control's pass/fail state, the automated test evidence, and the official risk language used by auditors.

drata019d7589

drata get person

Retrieves a person's full compliance status, including MDM enrollment, training completion, and background check clearance.

drata019d7589

drata get policy

Gets detailed status for one policy, including its renewal date, acknowledgment rates, and owner assignment.

drata019d7589

drata list assets

Lists all cloud infrastructure assets (EC2, S3, RDS) and shows their compliance status, encryption, and region.

drata019d7589

drata list controls

Lists every compliance control, showing its status, linked frameworks (SOC 2, HIPAA), and which owner is responsible.

drata019d7589

drata list frameworks

Lists active compliance frameworks (SOC 2, ISO 27001) and provides overall readiness scores and control completion percentages.

drata019d7589

drata list personnel

Lists all tracked personnel, showing security training status, device compliance, and policy acceptance rates.

drata019d7589

drata list policies

Lists all security policies in Drata, detailing the last review date, next review due, and acknowledgment completion rate.

drata019d7589

drata list tests

Lists automated compliance tests, showing which checks are failing, their associated controls, and the last time they ran.

drata019d7589

drata list vendors

Lists third-party vendors, showing their data risk classification, security questionnaire status, and SOC 2 report review status.

Choose How to Get Started

Build a custom MCP for your own tools, or connect a ready-made integration from our catalog.

Build Your Own

Turn any API into an MCP. Import a spec, define Agent Skills, or deploy with MCPFusion.

  • Import from OpenAPI, Swagger, or YAML specs
  • Create Agent Skills with progressive disclosure
  • Deploy to edge with MCPFusion framework
  • Built in DLP, auth, and compliance on every call
  • Real time usage dashboard and cost metering
  • Publish to catalog or keep private
Start building

Make Your AI Do More

Start with Drata, then connect any of our 4,800+ other servers whenever your AI needs more. One click, no limits.

  • Use this MCP plus 4,800+ others, all in one place
  • Add new capabilities to your AI anytime you want
  • Every connection is secured and compliant automatically
  • Track usage and costs across all your servers
  • Works with Claude, ChatGPT, Cursor, and more
  • New servers added to the catalog every week
Drata MCP server cover

Independent Platform Disclaimer: Vinkius is an independent platform and is not affiliated with, endorsed by, sponsored by, verified by, or otherwise authorized by Drata. All third-party trademarks, logos, and brand names are the property of their respective owners. Their use on this website is strictly for informational purposes to identify service compatibility and interoperability.

VINKIUS INFRASTRUCTURE

Cloud Hosted

Managed infra

V8 Isolated

Sandboxed per request

Zero-Trust Proxy

No stored credentials

DLP Enforced

Policy on every call

GDPR Compliant

EU data residency

Token Compression

~60% cost reduction

Your data is protected. See how we built it.

Works with Claude, ChatGPT, Cursor, and more

The Model Context Protocol standardizes how applications expose capabilities to LLMs. Instead of operating in isolation, your AI gains direct access to external platforms, live data, and real-world actions through secure, standardized connections.

This server provides 10 capabilities that interface natively with Claude, ChatGPT, Cursor, and any MCP client. No middleware. No custom integration required.

Gathering compliance evidence used to be a nightmare of logins and spreadsheets.

Before this, auditing a single policy failure meant a journey across five different platforms: the AWS console for asset details, the HR system for employee status, the ticketing system for remediation tickets, the policy wiki for the rule text, and a spreadsheet to track ownership. You spent half the day just gathering the data, not analyzing it.

Now, your agent runs the required tools—like `drata_get_control` or `drata_list_assets`—and delivers the full context: the failure, the evidence, and the policy definition, all in one response. You get the answer, not the data dump.

Drata MCP Server: Audit Compliance & Security

You no longer need to manually pull reports on personnel training status, policy renewal dates, and cloud asset compliance. The agent runs `drata_list_personnel` and `drata_list_policies` to give you a consolidated view of who needs training and what needs review.

What's different now is the shift from reactive reporting to conversational auditing. You ask a question, and the agent executes the complex, multi-step checks necessary to give you a definitive, actionable answer.

What you can do with this MCP connector

Drata MCP Server gives your AI agent direct access to your whole governance stack. You can check if an employee's training is up to date, list every failing control, audit policies for renewal dates, or verify if a cloud asset is encrypted—all without leaving your chat client. This tool connects your agent straight to Drata's full risk and compliance record.

drata_list_frameworks lists active compliance frameworks like SOC 2 or ISO 27001, giving you overall readiness scores and control completion percentages. drata_list_controls lists every compliance requirement, showing its status, mapped frameworks, and the owner responsible. drata_get_control checks a specific control's pass/fail status, the evidence from automated tests, and the official risk language auditors use.

drata_list_personnel gives you a full roster of personnel, showing who's non-compliant, who has overdue training, and device compliance status. drata_get_person audits a specific person's profile, checking their onboarding status, MDM enrollment, training dates, and background check clearance. drata_list_policies lists all security policies in Drata, detailing the last review date, next review due, and acknowledgment completion rate. drata_get_policy finds a policy's renewal date, who acknowledged it, and its version history.

drata_list_assets lists all cloud infrastructure assets—like EC2 or S3 buckets—showing their compliance status, encryption status, and region. drata_list_vendors lists third-party vendors, detailing their data risk classification, security questionnaire status, and SOC 2 report review status. drata_list_tests lists automated compliance tests, showing which checks are failing, their associated controls, and the last time they ran.

Built · Hosted · Managed by Vinkius Drata MCP Server - Automated Compliance & Security Audits Server ID 019d7589-3177-720b-b01d-9e9226361495
Vinkius Inspector
Compliance Grade A+
Score 100/100
Vinkius Inspector Badge — Score 100/100

Common Questions About Drata MCP

How do I use `drata_list_controls` to find out what controls are failing? +

The agent runs drata_list_controls and returns a list of all requirements. You can then ask the agent to filter that list by 'failing' status, and it will provide the names and associated frameworks.

Can `drata_get_person` tell me if an employee is compliant? +

Yes. drata_get_person checks multiple sources—MDM enrollment, background checks, and training completion—and reports back a single, clear compliance status for that employee.

What is the difference between `drata_list_assets` and `drata_list_controls`? +

drata_list_assets shows the current state of your infrastructure (e.g., 'S3 bucket is unencrypted'). drata_list_controls shows the required rule (e.g., 'Encryption at rest is required').

How do I check if a policy is due for renewal using `drata_get_policy`? +

Just ask the agent to check a specific policy. The tool will return the policy's renewal date and the acknowledgment completion rate, letting you know exactly when to act.

Does `drata_list_vendors` track vendor risk? +

Yes, drata_list_vendors lists third-party vendors and includes their data risk classification, security questionnaire status, and SOC 2 report review status.

How do I use `drata_list_frameworks` to see our overall compliance readiness? +

The tool provides a high-level view of your compliance posture. It lists active frameworks (like SOC 2 or ISO 27001) and gives you a readiness score and the percentage of controls that are passing.

What information does `drata_get_control` give me about a specific failing control? +

It gives you the pass/fail status, the automated test evidence, and the explicit auditor language. This helps you understand exactly why a control is failing and what evidence is required.

When should I use `drata_list_tests` versus `drata_list_controls`? +

Use drata_list_tests for real-time automated monitoring. It shows specific checks failing across services like AWS or Okta. Use drata_list_controls for the defined technical and administrative requirements themselves.

Can my agent check if specific employees have finished their security training? +

Yes. Use the 'list_personnel' or 'get_personnel_status' tools. The agent retrieves the onboarding state, including Security Awareness Training completion and background check clearance for any tracked individual.

How do I monitor which compliance controls are currently failing? +

Use the 'list_controls' tool to see all controls and 'get_control' for specific details. The agent will fetch exact evaluation states and automated test results to identify failing requirements and their risk logic.

Can I see my SOC 2 readiness score through natural conversation? +

Absolutely. Use the 'list_frameworks' tool. Your agent will pull the top-level standard boundaries and provide overall readiness scores and aggregated control completion percentages for frameworks like SOC 2.

Built & Managed by Vinkius 30s setup 10 tools

We've already built the connector for Drata. Just plug in your AI agents and start using Vinkius.

No hosting. No infrastructure. No complex setup.
All 10 tools are live and waiting. You're up and running in seconds.

Vinkius runs on Claude Claude
Vinkius runs on ChatGPT ChatGPT
Vinkius runs on Cursor Cursor
Vinkius runs on Gemini Gemini
Vinkius runs on Windsurf Windsurf
Vinkius runs on VS Code VS Code
Vinkius runs on JetBrains JetBrains
Vinkius runs on Vercel Vercel
+ other MCP clients

Vinkius gives your AI agents access to the full catalog of app connectors, all fully managed, secure, and enterprise-ready. One subscription, every tool you need.

Zero hosting required Full MCP catalog included Enterprise-grade security Auto-updated by Vinkius

Built, hosted, and secured by Vinkius. You just connect and go.