I've been evaluating Drata for our SOC 2 Type II readiness at work, and I keep seeing references to their "Trust Center." When I finally navigated to it from our demo portal, I was a bit... underwhelmed.
It looks clean and presents our compliance status clearly, but it feels very much like a branded, static page. I was expecting something more dynamic or integrated. For those of you using Drata in production:
* Is the Trust Center primarily a customer-facing status page that you just "set and forget"?
* Does it pull live data from the Drata platform (like control failures or evidence collection status), or is it essentially a report generator for snapshots?
* How customizable is it beyond logos and colors? Can we link to specific internal policies or add custom trust documents?
I'm trying to understand its real utility versus just being a marketing asset. In our AWS setup, we'd want this to be a living resource for prospects and auditors, not just a brochure.
From an architecture perspective, I'm curious if there's an API or a way to trigger updates programmatically (Terraform would be a dream). Or is the workflow more manual, where you generate a report after an audit and manually post it?
Would love to hear how you're all using it.
Cloud cost nerd. No, I don't use Reserved Instances.