Drivetrain

Drivetrain publicly advertises 4 compliance frameworks through a trust center hosted by Vanta.

Fintech & Financial Services

4

Advertised frameworks

Vanta

Trust center platform

First observed

Founding to trust center

AI-native FP&A software for finance teams who've outgrown spreadsheets and rigid tools. Build forecasts, budgets, headcount plans, and scenarios in minutes. Let AI handle the busywork, while you focus on the strategic work.

Summary from the company’s website.

Publicly advertised compliance posture

As observed on September 8, 2026 on the organization’s public trust center.

  • SOC 1

    Publicly advertised on the organization’s trust center.

  • SOC 2

    Independent CPA audit of controls for security, availability, and confidentiality.

  • GDPR

    Public claim of alignment with the EU General Data Protection Regulation.

  • ISO 27001

    International standard for an information security management system, certified by accredited bodies.

Compliance timeline

  1. September 8, 2026

    Posture last observed by Trust Index

Subprocessors

Third parties Drivetrain discloses on its trust center. Linked entries have their own profile in the Trust Index.

68% chain trust: 15 of 22 disclosed subprocessors are themselves in the Trust Index.

  • Amazon Web Services Cloud provider
  • Google Cloud Platform Cloud provider
  • Microsoft Azure Cloud provider
  • Okta Identity provider
  • 1Password Identity provider
  • Datadog Cloud monitoring
  • ClickHouse Database, Analytics, Data Storage
  • OpenAI LLM Provider
  • Anthropic LLM Provider
  • LangChain AI pipeline
  • TurboPuffer Vector DB for AI
  • Fivetran Data storage and processing
  • Stitch Data storage and processing
  • HotGlue Data storage and processing
  • Skyvia Data storage and processing
  • Merge Data storage and processing
  • DBT Data transformation
  • Temporal Workflow orchestration
  • SendGrid Transactional email
  • Sentry Error monitoring
  • Snowflake Data storage
  • Mixpanel Product behavioral analytics

About this data

The Trust Index reports only what organizations publicly advertise. A missing framework here means no public claim was observed as of September 8, 2026; it never means an organization is non-compliant. HIPAA entries reflect a public claim of compliance; no HIPAA certification exists. Corrections are welcome and verified against public evidence. Read the full methodology.

More in Fintech & Financial Services

How can we work together

Schedule a discovery session

A complimentary, exploratory meeting to discuss your business goals and challenges, identify potential solutions, and determine if our services align with your needs.

Hire us for a project

Augmenting a specific initiative or project, leveraging our expertise and resources to deliver a defined outcome.

Retain us long term

Ongoing collaboration and support through regular meetings, check-ins, and access to our team's collective knowledge and experience, empowering you to make informed decisions and drive sustained growth.