APAC Kickoff Kitfor a Drata implementation
Independent work sample built for a job application. Not affiliated with or endorsed by Drata. The scan reads only public DNS, public HTTPS responses and public certificate logs. It never touches a customer system. Homework write-up ↗

What can we learn about a new customer before the kickoff call?

Enter the customer's domain. The scan runs live against public DNS, their website and the certificate transparency logs: SPF with its 10-lookup budget expanded, DMARC including report authorisation, DKIM selectors, MTA-STS policy, CAA, DNSSEC, security headers, security.txt, trust-center vendor, and the hosts holding public certificates. It infers the tools they run, maps each to a Drata connection, and exports a kickoff brief.

Kickoff to audit-ready: the implementation plan

Pick the customer's region, frameworks and stack (or prefill from the scan). The plan lists each Drata connection, the gaps that need a workaround, the regional requirements to raise, and a milestone schedule with risks.

Read-only Drata API console

For an SA, the API is how to check a tenant's state quickly and how to script bulk work. Paste a key from your own Drata workspace to run the reads below. The key goes to Drata for that one request and is never stored or logged.