Appearance
Compliance Automation Vendor Evaluation
Status: Decision deferred. Effective 2026-05-11. Owner: Taha Abbasi (technical fit) + Asad Khalid (procurement + cost). Decision target: July 2026 (alongside funding close + SOC 2 evidence window start). Current lean: Vanta — faster, more AI-native posture, more predictable HIPAA bundle pricing. Drata is the close-second on white-glove support + on-prem feel.
Purpose
Capture the side-by-side evaluation of compliance-automation platforms so the procurement decision in July 2026 starts from a real artifact, not from scratch. Required because:
- SOC 2 Type II evidence collection without a platform is a meaningful manual burden — 100+ controls, weekly evidence pulls, per-control auditor handoffs.
- HIPAA continuous-compliance gets the same lift.
- CMS EDE Phase 3 / MARS-E 2.2 is NOT pre-mapped by either vendor — the underlying NIST 800-53 R4 Moderate baseline IS pre-mapped, which gives us ~70-80% inherited coverage.
Candidates evaluated
| Vendor | Considered | Why |
|---|---|---|
| Drata | Yes | Market leader; pre-positioned IAM role stubs in AWS; well-aligned with AWS-heavy stack |
| Vanta | Yes | Market co-leader; reportedly broader integration ecosystem + faster AI-native iteration |
| Sprinto | No — out of scope | Smaller US footprint; less proven on EDE / HIPAA scale |
| Secureframe | No — out of scope | Comparable feature set to Drata/Vanta but no compelling differentiator for this stack |
Side-by-side comparison
| Axis | Drata | Vanta |
|---|---|---|
| Startup-tier base price (1 framework, ~50 FTE cap) | $9-15K/yr (Foundation) | $10-15K/yr (Core) |
| SOC 2 + HIPAA bundle (AskFlorence Year 1) | $22-28K/yr | $15-25K/yr |
| HIPAA add-on volatility (reported) | Reports of 167% jump from SOC 2-only | More predictable bundle pricing |
| AWS connector | First-class, deep coverage | First-class, deep coverage |
| MongoDB Atlas connector | First-class | First-class |
| GitHub connector | First-class | First-class |
| Google Workspace connector | First-class | First-class |
| HubSpot connector | Standard CRM connector | Standard CRM connector |
| EDE Phase 3 / MARS-E 2.2 pre-mapping | NOT pre-mapped (manual either way) | NOT pre-mapped (manual either way) |
| NIST 800-53 R4 Moderate inheritance from AWS FedRAMP | Inherited via AWS connector evidence | Same |
| White-glove onboarding support | Strong (cited advantage for ≤5-person teams) | Lighter touch, broader UX strength |
| AI-native posture | Standard | Stronger — more agentic features, faster iteration cadence (user-cited criterion) |
| Audit-firm preference / familiarity | Both equally well-known to typical SOC 2 audit firms (Prescient Assurance, A-LIGN, Schellman) | Same |
| Pre-positioned AskFlorence assets | DrataAutopilotRole IAM role deployed in all 4 accounts (placeholder trust, never used) | None — would rename existing role at signing (15-min Terraform change) |
| Switching cost | None of consequence today; rename + trust-policy swap | Same (mirror cost if switching Drata→Vanta later) |
| Risk to AskFlorence specifically | Higher HIPAA-jump risk per reported customer experiences; needs negotiation for bundle pricing | Need to confirm AskFlorence-specific quote vs the bundled-startup tier |
Pricing in context (Year 1 = July 2026 → July 2027)
| Line item | Estimate | Notes |
|---|---|---|
| Platform subscription (Drata or Vanta) | $20-28K | SOC 2 + HIPAA bundle, startup tier (~50 FTE cap) — actual will land after both vendors quote against real scope |
| External pen test (Bishop Fox / Trail of Bits / NetSPI tier) | $15-40K one-time | Commissioned July 2026 alongside SOC 2 vendor sign; report by Q4 2026 |
| SOC 2 Type II audit fee (Prescient Assurance / A-LIGN / Schellman) | $5-15K | Audit fires at end of evidence window — Q3 2027 |
| Total Year 1 | ~$40-83K |
Year 2+ steady state: ~$30-50K/yr (platform + recurring audit fee + lighter pen test cadence — re-test on major architectural change rather than annual full re-test).
These are reference ranges from 2026 public data (Vendr marketplace, PriceLevel, Sprinto cost guides, Cavanex SOC 2 cost report). Actual quotes will vary 20-40% based on real scope and negotiation; we should expect bundle discount of 30-40% for SOC 2 + HIPAA together vs separately per the public benchmarks.
Decision criteria (weighted)
| Criterion | Weight | Drata | Vanta | Notes |
|---|---|---|---|---|
| EDE Phase 3 coverage | 25% | Equal (manual) | Equal (manual) | Neither pre-maps EDE; both inherit AWS FedRAMP evidence |
| AWS + Atlas + GitHub + Google Workspace connector quality | 20% | Equal | Equal | Both are first-class on all four |
| Total Year 1 cost | 20% | Higher (reported $22-28K) | Lower (reported $15-25K) | Bundle-discount negotiation matters more than published tier |
| AI-native / iteration cadence | 15% | Standard | Stronger (per user-stated criterion) | Long-term operating ergonomics |
| White-glove onboarding support for a 3-person team | 10% | Stronger | Lighter touch | Important for first audit; less important Year 2+ |
| Switching cost from pre-positioned IAM role | 5% | Zero (already named for it) | 15 min (rename DrataAutopilotRole → ComplianceAutopilotRole or VantaConnectorRole) | Not load-bearing on the decision |
| Audit-firm familiarity | 5% | Equal | Equal | Both well-known to typical SOC 2 firms |
Current lean
Vanta based on:
- Lower expected Year 1 spend at typical AskFlorence size — $15-25K vs Drata's $22-28K for the SOC 2 + HIPAA bundle, and more predictable bundle pricing (less HIPAA-jump volatility).
- AI-native posture per user-stated criterion — faster iteration cadence + more agentic features matter more than white-glove for a team operating with AI-assisted compliance practice.
- No meaningful switching cost from the Drata-named IAM stub (15-minute rename).
Drata stays as a close second because:
- White-glove support is real for a 3-person team's first SOC 2 audit
- The Drata-named IAM role is already deployed and provisioned
- If Vanta's actual quote comes in materially higher than reference range, Drata snaps in cleanly
Procurement plan (July 2026)
When funding closes and the procurement conversation opens:
- Both quotes — request from Drata + Vanta against AskFlorence's actual scope (FTE count, framework list, integration list, evidence-window timing). Reference ranges above are starting points, not commitments.
- Negotiate the bundle — SOC 2 + HIPAA together gets 30-40% off vs separate per public benchmarks. Make the bundle explicit in the quote ask.
- Confirm EDE-mapping support — neither vendor pre-maps EDE Phase 3, but ask each how their platform supports manual mapping. The answer affects practical Year 1 operating cost.
- Confirm AWS connector depth — specifically: does the connector evidence (a) IAM roles + permission sets, (b) KMS CMK rotation, (c) Secrets Manager encryption, (d) CloudTrail org-trail, (e) Security Hub findings, (f) Config snapshots, (g) GuardDuty findings? Both should be yes; verify.
- Confirm MongoDB Atlas connector depth — specifically: does it evidence both project IDs (prod + staging)? Both should, but the cross-cluster posture is unusual enough to verify.
- Sign one — commitment around July 2026 post-funding close.
At signing:
- File the signed contract in
docs/infrastructure/evidence/per vendor register discipline - Update
compliance-automation-integration.mdto reflect connected state - If Vanta: rename
DrataAutopilotRole→ComplianceAutopilotRole(orVantaConnectorRole), update trust-policy + ExternalId, commit Terraform change. Re-import to state if Phase 3b has completed. - Configure connectors in priority order per compliance automation integration
- Begin populating the automated-vs-manual control register
Revisit triggers
Re-open this evaluation if:
- Vanta quote comes in materially worse than reference (e.g. >40% above the $25K Year 1 ceiling) — pivot to Drata
- Drata releases AI-native parity with Vanta — re-weight the AI criterion
- Either vendor adds EDE Phase 3 / MARS-E 2.2 pre-mapping — re-weight EDE criterion significantly (current 25% is treated as equal because both are manual)
- AWS adds a first-party compliance-automation service that meaningfully covers SOC 2 + HIPAA + EDE in the AWS-native stack — re-evaluate whole landscape
Reference
- Compliance Automation Integration — connector list + onboarding plan
- Vendor / Subprocessor Register — vendor BAA discipline (applies once vendor signed)
- Public pricing references (2026): Vendr / PriceLevel marketplace benchmarks, Cavanex SOC 2 cost report, Sprinto vendor pricing comparisons