Overview
Previously, Drata VRM customers would manually download and upload documents from the SafeBase Trust Center to complete their security reviews.
While it is highly efficient compared to the old process of not utilizing a the Trust Center at all, it is still time-consuming and depending on how organizations manage their Trust Center, prone to inconsistencies.
SafeBase Partners settings gives organizations the ability to control if a Trust Center is discoverable on partner sites within Drata, and what types of information will be surfaced through those sites.
With the settings enabled, the Drata VRM Agent will orchestrate access requests and analyze all available information to help users quickly understand a vendor's security posture.
SafeBase Partner Settings
As a Trust Center Admin, navigate to Settings > SafeBase Partners
Allow SafeBase Partners to access your Trust Center Content
When enabled, the Trust Center becomes discoverable within Drata Vendor Risk Management. This allows customers to easily facilitate security reviews and provides convenient access to your content.
Access requirements are always respected by partners.
Enabling sharing via Drata does not circumvent the Trust Center's security settings. Requesting parties will still be required to:
Accept Terms of Service.
Provide required access information.
Sign NDAs (Dependent on current Trust Center Settings).
Share with Drata
When enabled, Vendor profiles in Drata Vendor Risk Management (VRM) can be associated with a SafeBase Trust Center. Users will be able to see an integrated view of an organizations Trust Center within Drata.
Content Sharing Options:
Share “Public” Trust Center Content
If Share “Public” is selected, users in Drata can only view and access publicly available content. Drata users will be unable to request access to private content.
Share “Public” and “Private” Trust Center Content
If “Public” and “Private” are selected, Drata users will be able to request access to private Trust Center content via Drata.
Access Requests Through Drata VRM
If trying to access Private Content via this method, users will be required to complete access request forms, sign NDAs, and any other required steps.
Access requests made via Drata will show in the Account pages in SafeBase. Access requests and accounts created will surface in the Accounts page in SafeBase. The source will be displayed as Drata VRM.
If a user utilizes the same email address as a previous request, Drata VRM integration will attempt to associate the user to an existing account and apply the same permission profile to the user.
