Skip to main content
DrataCustomer feedback

A 30-person company perceives Drata as too expensive for their size while evaluating compliance management platforms.

What happened

Post: "Compliance Tracking"

Source

RedditSep 2, 2026By u/DamageLeading1341

r/Information_Security

Compliance Tracking

upvotes
8
comments
10

Post

Highlighted: the lines this signal was extracted from

How are you tracking compliance with evidence under 50 people??? I keep seeing tools like Vanta, Drata and OneTrust but they are to expensive for under 200+ people companies For a 30 people shop what do you do when you need to show a client/ auditor something A spreadsheet/ shared drive/ a consultant Genuinely curious

reddit.com/r/Information_Security/comments/1w5odgo/compliance_trackingRead the full source

Comments on the post

5 of 10 comments
  • “The question to ask is - where are you spending too much time, and then see what would actually help with saving time on that. Do you already have a security programme or are you looking to become compliant? If you're just 30 people and not compliant yet, then you probably don't have an experienced compliance person yet, and most of all you need someone to help you walk through the process. They”

    u/texmex52 points · Sep 3, 2026View

  • “u/Paul_Ashe's population point can go one step further: the SSO app list only shows apps that got properly onboarded to SSO. It misses the one someone signed up for with a work email that never got federated, exactly the surprise that shows up during an audit. Detecting signups by work-email usage (password resets, verification emails) catches that population independently of whether anyone rememb”

    u/materialsec2 points · Sep 7, 2026View

  • “At 30 people, a spreadsheet holds up fine as the tracker. What tends to fall over under questioning is the population it claims to cover. Someone will accept your list of twelve controls and then ask how you know the set of in-scope systems is complete, and there's no good answer if that set is maintained by hand and updated when a person remembers to. I ask that question for a living, so weigh th”

    u/Paul_Ashe1 points · Sep 3, 2026View

  • “If you mainly need a structured way to track controls, evidence, documents, owners, due dates and status, PHPRunner could be used to build a much smaller internal compliance application around that process. It wouldn't automatically collect evidence from every external system the way platforms like Vanta do, but if that isn't the part you need, it may be worth a look. I'm the author, so obviou”

    u/gammacoder1 points · Sep 3, 2026View

  • “I work at Insight Assurance, disclosure there, since we perform assessments across a few frameworks and see this exact situation a lot with smaller orgs. Spreadsheet/shared drive is genuinely common at that size, and it's not automatically a problem, what actually matters to an auditor isn't the tool, it's whether the evidence is organized, consistent, and traceable over time. A well-maintained”

    u/TheSamFromIA1 points · Sep 4, 2026View

Extracted by Autobound

From the Signal API record
Signal
Customer feedback

What this signalsUser posts often show product pain before it reaches reviews or churn.

Subreddit
r/Information_Security
Stage
Considering

Companies

  • VantaAlso named
  • OneTrustAlso named

The full record

From the Signal API record

Numbers

Mentions
1

Details

Timing
In progress
Category
Pricing
Virality
Medium
Post kind
Text
Prominence
Core
Company's role
Vendor

Topics and mentions

Topics

  • compliance
  • pricing
  • smb
  • grc

Extraction

Sentiment
Negative
Detected
Sep 2, 2026
signal_type
reddit-company
signal_subtype
customerFeedback

Use this data

Get every Reddit signal for Drata and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Drata this week?”

  2. Send it to your own tools

    The Signal API returns Reddit signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full reddit-company record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/099ca076-2621-5cff-ac7a-7cbccadb5ca4 returns this record as JSON. POST /v1/companies/enrich returns every signal for drata.com.

{
  "signal_id": "099ca076-2621-5cff-ac7a-7cbccadb5ca4",
  "signal_type": "reddit-company",
  "signal_subtype": "customerFeedback",
  "detected_at": "2026-09-02T21:50:10+00:00",
  "company": {
    "name": "Drata",
    "domain": "drata.com"
  },
  "data": {
    "nsfw": false,
    "stage": "considering",
    "awards": 0,
    "timing": "in_progress",
    "topics": [
      "compliance",
      "pricing",
      "smb",
      "grc"
    ],
    "post_id": "1w5odgo",
    "summary": "A 30-person company perceives Drata as too expensive for their size while evaluating compliance management platforms.",
    "category": "pricing",
    "comments": [
      {
        "url": "https://www.reddit.com/r/Information_Security/comments/1w5odgo/comment/p7kyzig/",
        "depth": 0,
        "score": 2,
        "author": "texmex5",
        "excerpt": "The question to ask is - where are you spending too much time, and then see what would actually help with saving time on that.\n\n Do you already have a security programme or are you looking to become compliant? If you're just 30 people and not compliant yet, then you probably don't have an experienced compliance person yet, and most of all you need someone to help you walk through the process. They",
        "posted_at": "2026-09-03T14:17:26.000Z",
        "author_url": "https://www.reddit.com/user/texmex5/"
      },
      {
        "url": "https://www.reddit.com/r/Information_Security/comments/1w5odgo/comment/p8eek2s/",
        "depth": 0,
        "score": 2,
        "author": "materialsec",
        "excerpt": "u/Paul_Ashe's population point can go one step further: the SSO app list only shows apps that got properly onboarded to SSO. It misses the one someone signed up for with a work email that never got federated, exactly the surprise that shows up during an audit. Detecting signups by work-email usage (password resets, verification emails) catches that population independently of whether anyone rememb",
        "posted_at": "2026-09-07T18:25:52.000Z",
        "author_url": "https://www.reddit.com/user/materialsec/"
      },
      {
        "url": "https://www.reddit.com/r/Information_Security/comments/1w5odgo/comment/p7n1lgs/",
        "depth": 0,
        "score": 1,
        "author": "Paul_Ashe",
        "excerpt": "At 30 people, a spreadsheet holds up fine as the tracker. What tends to fall over under questioning is the population it claims to cover. Someone will accept your list of twelve controls and then ask how you know the set of in-scope systems is complete, and there's no good answer if that set is maintained by hand and updated when a person remembers to. I ask that question for a living, so weigh th",
        "posted_at": "2026-09-03T19:34:39.000Z",
        "author_url": "https://www.reddit.com/user/Paul_Ashe/"
      },
      {
        "url": "https://www.reddit.com/r/Information_Security/comments/1w5odgo/comment/p7nlmjc/",
        "depth": 0,
        "score": 1,
        "author": "gammacoder",
        "excerpt": "If you mainly need a structured way to track controls, evidence, documents, owners, due dates and status, PHPRunner could be used to build a much smaller internal compliance application around that process.\n\n It wouldn't automatically collect evidence from every external system the way platforms like Vanta do, but if that isn't the part you need, it may be worth a look.\n\n I'm the author, so obviou",
        "posted_at": "2026-09-03T21:02:31.000Z",
        "author_url": "https://www.reddit.com/user/gammacoder/"
      },
      {
        "url": "https://www.reddit.com/r/Information_Security/comments/1w5odgo/comment/p7ug72d/",
        "depth": 0,
        "score": 1,
        "author": "TheSamFromIA",
        "excerpt": "I work at Insight Assurance, disclosure there, since we perform assessments across a few frameworks and see this exact situation a lot with smaller orgs.\n\n Spreadsheet/shared drive is genuinely common at that size, and it's not automatically a problem, what actually matters to an auditor isn't the tool, it's whether the evidence is organized, consistent, and traceable over time. A well-maintained",
        "posted_at": "2026-09-04T20:05:08.000Z",
        "author_url": "https://www.reddit.com/user/TheSamFromIA/"
      },
      {
        "url": "https://www.reddit.com/r/Information_Security/comments/1w5odgo/comment/p7uk6fn/",
        "depth": 0,
        "score": 1,
        "author": "TechnicalDefense",
        "excerpt": "I have alot of clients in the financial services sector and they have the same compliance issues and need the data available for auditors. If i was you i would look for an inexpensive CRM that has good history tracking, automatic email history logging and solid reporting. I had a client last month that went through an audit and they just used their Act! CRM to pull up a history report and all thei",
        "posted_at": "2026-09-04T20:23:09.000Z",
        "author_url": "https://www.reddit.com/user/TechnicalDefense/"
      },
      {
        "url": "https://www.reddit.com/r/Information_Security/comments/1w5odgo/comment/p7vv86v/",
        "depth": 0,
        "score": 1,
        "author": "ItinerantFella",
        "excerpt": "We use Drata. 50 person company. iSO27001 certified, going for SOC2.",
        "posted_at": "2026-09-05T00:23:57.000Z",
        "author_url": "https://www.reddit.com/user/ItinerantFella/"
      },
      {
        "url": "https://www.reddit.com/r/Information_Security/comments/1w5odgo/comment/p8da6ez/",
        "depth": 0,
        "score": 1,
        "author": "PrivacyEngine",
        "excerpt": "Have you considered exploring PrivacyEngine? https://www.privacyengine.io/onetrust-best-alternative/",
        "posted_at": "2026-09-07T15:28:02.000Z",
        "author_url": "https://www.reddit.com/user/PrivacyEngine/"
      }
    ],
    "evidence": [
      "[post] How are you tracking compliance with evidence under 50 people???",
      "[post] I keep seeing tools like Vanta, Drata and OneTrust but they are to expensive for under 200+ people companies"
    ],
    "virality": "medium",
    "post_date": "2026-09-02T21:50:10.000Z",
    "post_kind": "text",
    "post_text": "How are you tracking compliance with evidence under 50 people???\n\nI keep seeing tools like Vanta, Drata and OneTrust but they are to expensive for under 200+ people companies\n\nFor a 30 people shop what do you do when you need to show a client/ auditor something\n\nA spreadsheet/ shared drive/ a consultant\n\nGenuinely curious",
    "sentiment": "negative",
    "subreddit": "Information_Security",
    "post_title": "Compliance Tracking",
    "prominence": "core",
    "source_url": "https://www.reddit.com/r/Information_Security/comments/1w5odgo/compliance_tracking/",
    "entity_role": "vendor",
    "post_author": "DamageLeading1341",
    "upvote_ratio": 0.9,
    "mention_count": 1,
    "mention_surge": false,
    "subreddit_url": "https://www.reddit.com/r/Information_Security/",
    "total_upvotes": 8,
    "comments_total": 10,
    "total_comments": 10,
    "other_companies": [
      {
        "name": "Vanta",
        "role": "competitor",
        "domain": "vanta.com"
      },
      {
        "name": "OneTrust",
        "role": "competitor",
        "domain": "onetrust.com"
      }
    ],
    "post_author_url": "https://www.reddit.com/user/DamageLeading1341/",
    "signal_category": "feedback",
    "comments_included": 8
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.