Jake Aaron Villarreal: I'm your host Jake Aaron Villarreal, and here with us today we have Daniel Marashlian who's the co-founder and CTO of Drata, who's raised $328 million in the last two years. It's a fascinating story. Let me give uh just a little snapshot of Drata so the listeners know. So Drata is a startup that's raised 328 million in funding, it's valued at 2 billion as a company with unicorn status, and it's backed by investors, prominent investors that you may know like the CEO of Microsoft Satya Nadella, the CEO of LinkedIn Jeff Weiner and many others. Drata automates the compliance journey from start to audit. Um Daniel, before we dive in, in the company, walk us through you a little bit. How did you get into technology?
Daniel Marashlian: Yeah sure, that's a fun question. Um so, you know, always was good at STEM right, growing up and I didn't really... probably almost like every other 18-year-old in the world didn't know what they want to do with their life. And so this was, I graduated college in, sorry, high school in 2000. And the reason why I bring that up uh, for, for you know, you know uh, those that remember it, uh it was called the dot-com crash of 2001. And uh, and so while I was entering uh college in the dot-com boom, obviously all of the uh news and, and salaries and uh esteem of this industry was booming. And so, so I didn't know what I want to do and I said, "Hey look, that seems like a super fun career and field and I like video games and let's go make video games. I don't know, something like that." So, so that's, that's how I got into it. And there was a, you know, a, a good computer science program where I went to school and dove in and fell in love with it.
Jake Aaron Villarreal: You know, proximity is always something that helps you get into whatever you end up doing your life. Where, where did you grow up in?
Daniel Marashlian: Sedona, Arizona. A little you know, hippie tourist town.
Jake Aaron Villarreal: So at that time was technology pretty prevalent? I know STEM programs were all over the US, but for you how big was the engineering you know, buzz in that area?
Daniel Marashlian: Uh you know, uh in northern Arizona I grew up, not as big as you know Silicon Valley or whatever. It's a you know smaller community in northern Arizona uh area. But what was interesting in Sedona, I think Sedona actually had one of the first ISPs in the country uh, which was weird enough. It's like sedona.net or something, I don't remember. Uh so from a, from a early days of the internet you know 94, 95 somewhere there, um we were you know hacking around chat rooms. And so uh you know I just kind of in years, and as technology is starting to advance pretty fast, it was part of my growing up. And so it was always interesting to me. Um, actually always say you know, now that I've been doing this for so long, I can type extremely fast. But everyone you know like when you were young and you would take typing lessons, if you you know people remember that, I sucked. I think I probably got like a C or something in typing, whatever it was. And, and it was uh it was AOL Instant Messenger, AIM, that actually made me, forced me to type fast 'cause you would have these like 20 boxes open, open on your computer and you'd have to talk to all your friends at the same time and it made you start typing really fast. So...
Jake Aaron Villarreal: Yeah I remember those days. 100%. That's really cool. Um, Drata is a company that you've been building, you're the co-founder and CTO of, but prior to this you had eight startups. And uh in those eight startups I'm sure there's a lot that you've learned that you can apply to any new company you build in the future, and Drata currently. For those out there that they're on their first startup, what are some of the things that you learned in the first eight that have been valuable to apply today?
Daniel Marashlian: Well it was the first seven, this is the eighth company, but seven, eight, whatever, it's, let's see. Let's see. They're definitely right, there's probably some famous quote in there that I'm misquoting, but, but it's something about perseverance and practice makes perfect. And uh, and yeah, I think you go through lessons, you go through those journeys. I, I always use this um example when I talk about this stuff is I remember the night I was at this very small office uh. It was a, it was uh the second company I ever started was small team, it was two, me and my co-founder, and we actually had a remote team in India helping us build some of the extra code with me. And it was you know, I was more of a backend developer but then forced to also be front-end because I was you know the only one. And just spending till 3:00 a.m. trying to figure out how to vertically center this word to an image. And, and it wasn't so much the one pixel that was off, it was the research and fundamentally then understanding how CSS flow, CSS uh flows work uh you know from, from div blocks, spans, inline and, and, and knowing that you know I had the fundamentals wrong.
So, so that was just a, you know, a silly example of staying up till 3:00 a.m. to move a, a word up one pixel on a screen. But then uh in that forcible function like you, you start to understand the underlying uh architecture of certain things and therefore that stays with you for the rest of your career and how, how things are you know fundamentally work uh in you know uh underlying backend systems architectures and servers to the front end and CSS and job.
Jake Aaron Villarreal: So you understand the infrastructure behind the applications as well as the customer user interface that you're going to be typing into and, and, and looking at. Um, call it full stack engineer, call it architect. Um, in that process, you know, now that you're a CTO, um, what... I'm sure that's valuable stuff that you've learned. But in your role today, how, how is that experience helping you now [that] you have built teams?
Daniel Marashlian: Yeah, I would say for me, in my leadership style, I'm very uh on the battlefield with you. Uh, that doesn't mean that I'm you know coding 80% of my time. Um, to me sadly, I'm not coding enough at Drata with the 600 of us or so. It's uh, it's been a little you know chaotic and busy of, from hiring and strategy and organization. But uh I still find time to code, help resolve issues, things like that. But the point of that is I, in the interview process of, of hiring leaders, managers, um and obviously individual contributors you have... in the culture of the teams that I build uh uh you know I've, I've interviewed so many people that uh you know, and, and no fault to their own, their circumstance of their situation at companies you have all heard of uh, as a VP or someone like that, director, their, their role and responsibility drifted them away further and further from the keys uh and, and they had to take on bigger responsibilities and therefore their hardened skills softened.
And that's something that I shy away from uh in, in hiring and working with me is that every one of my leaders uh can be as technical as the contributors that they tell what to do or you know guide what to do. So uh and through those experiences of staying up till 3:00 a.m. to move a pixel one you know one up is uh when there's an actual fire on the you know in the software uh data um service that you're providing to paying customers and you're the one around, you're the one responsible for delivery and you don't know what it is, uh I, I find a flaw in that. So, so I think that's a big lesson that I learned in hiring over the years, is that make sure that people are competent um in technology as well as management leadership. So that's, I would say that's a big lesson I've learned and it's, it's suited me well uh. The people that have surrounded me, I, I feel like I completely then trust them on the um technical capability to deploy and own release, own, own delivery, versus obviously leading their team uh as well and making the right decision.
Jake Aaron Villarreal: You know, as a founder you always have that balance of doing it all and having control of it all, and at some point as you evolve as a company you have to evolve as a leader, you bring in more people, you have to let go. That might be as important as holding on to things. What's the process been like for you? You have 600 employees today at the company.
Daniel Marashlian: Yeah, you can't do it all.
Jake Aaron Villarreal: No.
Daniel Marashlian: Sadly, I wish I could uh, that's what eats me up every day is, is I wish I just had more, more time to be in the weeds as much as possible, say with the engineers on my side um, because there's things I see happening that you know, "Hey, this one I don't know, feature is taking a month where I feel like it should take two days uh and if I could get in there with them I could show them why it's two days." Uh but, but then you have to sacrifice that time and effort to you know uh zoom out a little bigger.
So I... the best way I heard about it and we sometimes talk about it at Drata, especially for the founding group but for all the execs, is you know, a lot of people expect us to you know uh how do you say it like um, I see things at 30,000 feet right, and you can see the landscape, but then you also immediately need to be able to jump down to 100 feet uh and, and sometimes on the ground uh with, with the, the troops that are, that are battling forward. And, and, and so I think that's been my job most recently in the past year is being able to change altitude uh from you know on ground to, to 30,000, 60,000 feet whatever you want to say uh almost within an instant.
And so that brain space of, I think that's where I've started to you know, if you think about like I don't know, from working out and training your muscles and, and, and learning how to do that is, that's what I've been training my brain to do for the past year plus is how you know, within this conversation I need to be 60,000 feet up and making a strategy decision for my whole org. And then the next call that I'm on or, or Slack message I'm on five minutes later, it's about like reviewing a line of code and telling someone why we should do X versus Y.
Jake Aaron Villarreal: Yeah, it's, you know, we, we, we've talked to a lot of founders and it seems the theme that we're starting to get a little bit more educated on is that you know, you have to evolve as a person. You know, when you stop learning, you stop leading and you stop inspiring. So it's a, it's a challenge, it's not like there's a teacher there to tell you how to do it. Sometimes you can get a coach, but at the end of the day you kind of learn as you go. Um, how big is the team, employees? How big is your engineering team?
Daniel Marashlian: Yeah, everyone that's in technology, which is like you know product, design, engineering, infrastructure, security, etc. uh, it's about 320. Um, so about 50-ish of that is product. I have a peer, same as Brian Elmi, he, he runs product here, and um, so he has you know product, design and um some, some uh research teams. And then everyone else reports up to me. So yeah, it's about... what's, what's that math? 280 something like that? 270 uh. Yeah, arithmetic maybe that's the thing I need to practice on.
Jake Aaron Villarreal: Yeah, that's a good size team. You know, we interact with 100,000 uh engineers a year, whether it's messaging or emailing or interviewing, and I'm sure you'll get people that hear this and want to learn more about what you do and, and your company and its growth and whatnot. Um let's dive in a little bit to, to the company. Data compliance is something that most companies fear, they have to go through, maybe they don't want to work through, but you've made it easy and you've made it automated. And for those out there that don't know, what are the areas that compliance really plays a part in as a SaaS company?
Daniel Marashlian: Yeah, uh people are afraid of what they don't know. And so I, I was in the same boat a decade ago uh. And I would say two aspects of compliance, let's just say, uh that, that really help a business. One is you're going, going to get inundated, especially in the SaaS world and B2B world um, you're going to go try to sell your services to, I don't know you know, go name your mid-market enterprise company, from Microsoft to HubSpot to GitHub or whatever. Um and, and those security, those buyers uh might love your service and then they're going to go through the procurement process and part of that is security uh, because the usually, it depends how deep your technology gets access to someone's uh data and systems, but you know you might be pulling in data from Salesforce or data from their database or something. And so now their private customers' PII or, or, or uh IP of their business is in your systems.
And those security teams want to understand how do you protect my data? And a lot of times the CISOs of you know, those Chief Information Security Officers, maybe they'll have a conversation with, with, with you and your company or your security leaders. A lot of times what they want to see is some sort of third-party attested report or certificate. And a lot of times that comes through a form of a SOC 2 report or maybe it's International Sister One report uh. They want to understand around privacy laws, like in Europe GDPR or in the states kind of California is leading the way with the CCPA or I think they've renamed it now to like CPRA, it's you know, it's acronym soup uh. And uh you know there's others from government, from the NIST standards, and I can keep going on and on with acronyms, but the point of all of this is "Hey, I want to sell you my services and here's the key to the door." Right? If you don't, if you... so here's a good example, if you want to sell your services to Drata, uh we won't even talk to you unless you have a SOC 2 or ISO. Uh it's, it's, it's the key to the party. And then from there you know we'll understand how you operate your security compliance program and if there's further questions we'll send you like a questionnaire or we'll get on the phone with you. So in a way it accelerates your sales cycles, it will, it'll be an arrow in your sales team's quiver uh to go get the deal done and just move past it as a non-point. It's like, "Of course we care about security, your customer data." Uh so that's one layer.
The other layer is the process of running uh through compliance. I'll be the first to say uh me running a security compliance company uh or product for that, it's no fun. It's kind of sucks. Uh the process of doing it, it's like gathering evidence, screenshots, meetings, Jira tickets uh... stuff you don't want to do. You'd rather focus on hardening and locking down your perimeter, your you know systems, building better product uh etc. But how are you going to help the, this third-party auditor assert everything that you're doing here? So that's kind of been the trend, call it over the past 15 years, is to do it by hand and gather information, organize it for them. The end result of, of compliance is maybe this artifact like a certificate or this PDF report um, that's great and that really helps the sales side like I said, it's just key to the door. But I think more than that it makes you run a better company. It makes you... your, your people uh care about security. It makes your company care about uh your customers better. And the, the, the uh it's almost like the lubricant, call it, of your engine. It just helps you run a lot smoother.
So, so that's I think the end result of compliance is really positive, which again is a big reason why we started this is to make this process effortless and easy for companies alike. From small, tiny one, two person startups to large enterprises of you know, 50,000 plus employees is how can we make the process of compliance easier so that these companies can run smoother, safer, secure, and we can build this larger uh web on the internet of, of safe company harboring and data harboring.
Jake Aaron Villarreal: When you have clients like Calendly that a lot of us use, and Notion, and some of these marquee brands and they're using your product, you know, you start to think, "Okay, well if they're that big and they're doing that well, what are they having to do when it comes to security or compliance?" And you know, I've heard, and you probably, you've really defined it here too, is that if you're a company that sells your service, a subscription of your platform, and you want to partner with another company or integrate with another software for a company, or maybe utilize you know your product within a bank or something and you can't get past compliance, um you're not going to sell your service or your product. We've heard so many companies that get to the final one-yard line of actually getting a million dollar deal done and then they're stuck in six months of trying to get their product compliant.
Daniel Marashlian: Yep. And you don't have the team to do it, you don't have the time to do it. As a small company the costs go up, you don't know who to use, who's going to be your auditor. And a lot of times it's not even about the one-time act, I mean that might close the deal, but then you want to renew them a year later and you need to maintain that compliance. That's where actually the burden comes in, not the, you know... I, I always kind of say it's like uh cramming for your SATs or something like that uh. But then imagine like refreshing and taking an SAT every six months. It's, it's maintaining that knowledge and uh process in your business, not just this one-time thing you do.
Jake Aaron Villarreal: So for the listeners that might be building a product or just on the outside listening to what this really all means. When it comes to compliance you have to make sure that you have all your data secure and in order and reportable so that you can show proof that you're in a good position to engage with your product or service, is that accurate?
Daniel Marashlian: Yeah, that's, that's pretty good. Um a lot of times it comes down to security controls, and then you know you might say, "Daniel, what's a security control? I don't, I don't, I know what you're saying right?" And so think of a control as just a rule. Um, we always, I always like to use this example. You know, what if uh your employees uh in a world where we have offices anymore, are using their bike to drive you know, to, to ride into work. And so they're ride- all these employees are starting to ride their bicycles into your, into your office every day. And as a, as the security and maybe risk officer, you're going, "Okay, like that's, that's cool, people aren't you know, they're, they're being green, but no one's wearing helmets and that's dangerous. Um so I'm going to implement a control, a rule, that if you ride your bike into work you have to wear a helmet."
And so that's great. How do you prove that? So if that's a control to your company and you want to show to the board, to an auditor that that is you know a measure you're putting in as, as an employer, how do you prove that? Well one could say, "Well I could like have someone stand at the front door and mark if Bob wore his helmet or not when I came in." Uh, the other one is we could have people you know in the bushes taking pictures of everyone or screenshots, right, to say... uh the other way could be I can put a sensor maybe on the helmet and uh and it would automatically report in that Bob was wearing their helmet. That sounds like a much better way to do it, reducing human time to track proof. Uh so, so that's how I think about Drata is, there's this security control in place and, and I could uh let's say maybe something that people could relate to like um uh uh "did your new employee do security training?"
So, so you can deliver, so a-, as someone that owns the security training has to deliver that invite to that person, that person needs to do it, and then have like this certificate that they did it and then turn it in and then we need to record it somewhere in Google Drive or wherever you record those, and then eventually organize it and report it up to the auditor. But if Drata integrates into your security training provider and can match your identities of your staff to the deliv-, delivery of who's taking security and automatically pull in the certificates, no longer does the compliance and security team need to like go hunt people down if they're doing things. And if a system can remind that new employee based on the SLAs in your policy of, of you know, "within three days or seven days or a month of starting you need to do this." Uh all the automatic notifications and reminders to the individual, to their managers can all you know, can all be done.
So all of this you know workflow and, and human process that if you did it by hand, we're trying to eliminate all of that. So that's, that's a tangible example of one of a hundred uh there plus uh tests that we, that we implement and integrate with all of your systems that you work. So from your identity provider, infrastructure, version control, background checks, HRIS, observability... the list goes on, I'm sure I'm missing 10 or plus. Uh but, but you know, out of the hundreds of integrations um to all these common tools that all of us use, from AWS to Okta to Google to, you know, GitHub, um uh Notion and uh you know, the list goes on and on and on, is how do you uh uh all these tools we use to run our business and, and however uh you know whatever vertical the piece is, Drata will go connect to them and automatically pull in the appropriate evidence to ensure you're following your company's controls and then automatically gather that evidence and organize it so when it comes time for audit uh it's already there.
And, and you know even though I think the auditing community is great, it's kind of like, "Hey, here you go auditors. Like I don't want to talk to you. It's all perfectly organized, do your job, ask me questions if you need it, but it's all ready to go." Right? And, and as you were building up that year into audit season, a lot of people call it, you know, you were getting maybe tapped on the shoulder and saying, "Hey uh, uh something's wrong here with compliance you know, maybe I'll mark a little ding on you, but, but go talk to the engineer that just spun up a database that's opened up to the world, right? Right." Uh and so, so we kind of try to tap you on your shoulder uh you know maybe you need to pay attention a few minutes every week to it, but otherwise it should be automated for the rest of...
Jake Aaron Villarreal: So if you've never gone through the audit process and you have to at some point traditionally, what's the time it takes to get compliant if you're not using your technology? If you're just using an auditor, yeah, you're trying to follow the rules, the 500 questions you might get from a bank or from whatever third party is asking you to collect. What's that timeline and, and cost typically look like? I'm not sure if you can put a cost, but if you could, and then what's yours look like now?
Daniel Marashlian: Obviously it's, it's a variety of answers based on the framework you're going after, whether it's a custom one from Goldman Sachs or it's a standard security framework like SOC 2 or, or something like that. Uh and then, and then also the complexity of your company. If you have two employees or 2,000 employees. But you know let's just average things out. Um, on... I'll just use SOC 2 as an example, it's kind of starting to become the industry standard for cloud-hosted data, um which most of us use nowadays. And so on average, what we're seeing across our thousands of customers and, and surveys and, and everything we did uh to, before we even started the company, it's about 500 human hours to maintain your SOC 2 Type 2. Uh so real quick, a SOC 2 Type 1 is a moment in time, usually people start there. It's like "Okay, I have all my you know ducks in order and everything's good," and then you have this period of time. And then eventually a SOC 2 Type 2 is that uh audit and that check over that period, which is standard a year. Uh so over that next year, "Did I do what I said I was going to do?" So in that SOC 2 Type 2 period over a year, it's usually around 500 hours of human labor uh to maintain and, and organize and work with the auditors and, and, and get that refreshed report every year.
Uh we, we try to achieve to reduce that to you know between 30 and 50 hours. Like roughly an hour a week, hopefully less. Uh and just kind of again, like I say, tap you on your shoulder once when something's going wrong. Um, the audit process itself, it depends on your auditor, it depends on the software, maybe perhaps they use. Hopefully they just use Drata. We, we actually have a whole Auditor Alliance team on our side that works with hundreds of auditing firms around the world to, to train and certify them on Drata to help and uh save them time as well. You know, so if, let's... I, I actually don't know off the top of my head... let's say um an audit firm is going to engage with you and they estimate it'll take 100 hours uh to do this, you know, of, of um like maybe three people on the team to do your audit. You know, we want to reduce their billing rate down to like 20, 30 hours, and therefore passing those savings on to you.
So where you're maybe uh you know, you go to a, if you go to a top you know, top 50 firm, that SOC 2 audit might cost you I don't know 15, $20,000 depending on your size and complexity. Um you know we even have like preferred pricing, we try to get that as low as possible. And again depends on the size and complexity of your company, but maybe to you know 12,000 or 15,000 something like that. Um you know if you're a really small company and uh you, you uh you know you want to... you're okay, and all audit firms I mean they're all certified by the AICPA, the American Institute of Certified Professional Accountants. Uh same as like EY and Deloitte, down to you know your, your maybe like a a two-person audit firm. Uh they're all certified by the same process. And so you know if you choose to go with a smaller firm, you know maybe you can actually get it for you know I don't know 5, 10 grand, um versus you know you go with like a EY, Deloitte, someone like that, it might cost you 100,000. Uh but they're going to you know uh in a way have a, have a bigger stamp and thorough process is, is my guess. But um yeah I don't think there's anything wrong with, with using those you know top 100 firms, uh Schneider Downs, SSF, Moss Adams, like they're all great, and so are the top ones.
Jake Aaron Villarreal: And so you have the platform that you can track the data in and automate the process. But in addition to that, you need an auditor who's going to come in and kind of help...
Daniel Marashlian: Yeah, the, the big, big piece is like if you had nothing, right, and you said, "Hey Daniel, I need to get a SOC 2 report tomorrow because I'm trying to close this million-dollar deal with Bank of America," right? Uh, we would probably cram, we would, we would stat a, our, our team and, and your, your designated CSM would work with you and help project manage it a little bit internally with you. We have expert auditors on staff, if you have complex, unique compliance questions that you can just hit up in chat, they're there for you. And you know, we would probably target a Type 1, so kind of that moment in time. And then hopefully you would negotiate with Bank of America in this case that says, "We're going to get that as fast as possible, and then continued on that period of time to go get a Type 2 later," and usually the security teams at those companies would be okay with that. Uh you know, it's around what are your policies, the governance of your, of your program? Drata comes with uh, and I apologize I should know this, I think it's 22 policies at the gate. I forget if it's uh 20 or 22, um I should know that. Uh so it's 22 policy templates out the gate. Now you shouldn't just take them as is, you should read them and make them your own, but they're 80 plus percent ready for you and your company is what I would say. Uh so you get your policies figured out, from your policies you would determine the controls.
Now you can bring your own controls in, you can use a standard set from, from some you know um organizations' standards. Like there's NIST CSF, there's a lot of acronyms, we don't need to go into that. Or Drata has our own, through a lot of experience, our, our advisors, our CISO advisors, as well as actually our auditing partners in collaboration, we've all made our own, the Drata Control Framework um, that a lot of again startups and, and even companies that have had well-established security programs, they've abandoned their own controls and have used ours. Um they're a little bit more... Have you ever like read a legal document and you're kind of like "what the hell is this?" Yeah. You know we've kind of distilled some of that down to make it more legible and understandable uh for the controls. So you know we, we've done that.
And so you would have your controls and then through these third-party connections, Drata automates the evidence of those controls and uh you would then invite your employees in uh, you know they might have to review and accept those policies. Um they, you would uh let's see what would be next, maybe do uh ensure you have background checks organized for your employees and uh uh they, your employees do your security training. Uh and then maybe after that is you would, you would do like a pen test on your, on your software if you've never done one before. And we have partners uh and great preferred pricing with pentesting companies. And you would kind of be ready to go in that phase so... and then you know, you would engage an auditing partner that, that aligns to your needs of the business, which we have great partnerships with and can make introductions to. And they would do that and that would you know I think if you were doing a Type 1 and it was uh pretty organized, it could take you know three weeks probably, three, four weeks, and then uh you know maybe, maybe a week to finalize up, and they even do their own internal audits on every report. So you know, I think you could probably get it like as quick as you know four to six weeks if you really were grinding and, and doing all of the steps and you had a small company and you can corral everyone to do everything. Um what we're seeing on average though for even people that are like on it in like a 100, 200 person company is you know, maybe, maybe three months uh around there. Um yeah it really just depends how much time and effort that you're putting, putting towards it. I've seen people do it as quick as two weeks, uh but, but uh you know I think it's, it's like three to six months just based on the resources you dedicate yourself to it. But once you do it, then the notifications are kicking in and then it's auto on auto basically as you go forward, so that's great.
Jake Aaron Villarreal: Yeah, I, I just, it's unbelievable to me that that's something that you really should be thinking about. I say unbelievable just because it's not the first thing you think about when you're starting to build a product. You don't think about, "Let me build a product, let me find a market fit, let me get funding, let me hire people, let me go to market, let's hope it works. Oh, and by the way, it's working, but now we got to take 10 steps back to make sure we've got everything in order so that we are compliant, so that the companies we're working with and integrating with um feel like, you know, I..."
Daniel Marashlian: At the level, I mean again, eighth company, I totally sympathize with the founders out there of "You got to find product-market fit, don't over-engineer, don't over-architect things like that." Whole MVP or lean startup, like iterate, advance, like try to get something that shows value. If you spend all your time over-architecting a solution and getting compliance from literally day zero, as you're like even pre-day zero like in R&D phase, um maybe it's taking too much time, right? And, and it's too much expense because what if that product doesn't work? And you know, when I say I've had eight companies, that doesn't mean all eight were successful. And a lot of them we had a uh you know I, I'll uh quote Kevin O'Leary here, "Take it behind the barn and shoot it in the head," uh is, is uh... yeah, they, they didn't work after dedicating six or 12 months to it. And, and we were uh you know, me and my teams were, were well you know self-aware enough that like, "Yeah, this market doesn't need this" or "we're not the right team to do this" or "let's onto the next idea," right? "Let's not dedicate five, 10 years of our lives to something maybe isn't going to work."
So um, so in that process, I get it. On the other side of building this company now, I've seen the value to, to doing it from day one. Not so much that output of this report, which again is useful if you're trying to go sell to Bank of America, but let's be real, you're probably not selling to Bank of America in month one of your company. So, so it's more about the building the process of it to, to instill these uh institutions of security within your company. Uh to make it not this thing in the corner that everyone's scared of or don't know, they don't know how to do it. And I've seen this type, which I, one of the most proud things I've, I've noticed in building this company, especially with all the startups that use us, is they, they had that sense, they finally got that deal that forced them you know to go get their SOC 2 or ISO or, or GDPR compliant, something like that. And they go through the process and, and with Drata as it shepherds them through it and makes it easy, it, they go, "Oh, that wasn't too bad. Oh, that actually was kind of fun. Oh, it's kind of like a little bit of a game and when, when we fall off track it's, it's, it's uh, it's fun to collaborate and push each other to get back on track." And all of a sudden in their like company values and their core values, even publicly on their website, security starts to pop up where it wasn't there before. So by, by showing them an easy way to do something, it starts making them think about uh their own you know, the security of their business and most importantly the security of their, of their customers' data. I mean you and me are, are users of those tools, Notion, Calendly, whatnot. I want my data to be safe and secure. And, and you know, go name your thousands of other companies that we use. And um, wouldn't it be nice if there were no more breaches? So you know, that's, that's kind of a mission we're on.
Jake Aaron Villarreal: I love it. Um, as a company you've raised a lot of money and you have a lot of employees today. When, when, when did you know that the product itself really had legs that you could say, "We know the demand is there, we got to build something they're going to want." But how big were you when you thought, "You know, I think we could actually take this and raise some capital and really blow it up"?
Daniel Marashlian: Yeah. Yeah, that's uh, you definitely need to find that right uh product-market fit moment to then take on that risk of taking in millions of dollars from someone that you're uh responsible to. Um, I've uh built companies where I've taken venture in and we didn't get an exit and it fizzled. And I still have a you know big gut ball in my stomach of, of losing uh friends now of mine that I've lost like half a million dollars up theirs, right, as angel investors. That's horrible, I don't want to lose a half million. So um, that sucks. Uh, and now go to these big institutions that have connections to people like everyone and, and losing their money would be even worse, right? And so you better make sure that what you're doing, there's a viable market to grow it and then obviously it's your responsibility to make that a reality. But until you can find that point, um yeah, I, I suggest continue to bootstrap it.
So in our story, uh we started in the middle of July of 20... is that right? Yeah. Um is that right? Yeah, yeah. And uh, so it was in the right height of COVID. Uh and it was like, alright, we had this idea. Me and the founders did a big product roadshow and talked to tons of customers or, or potential customers about how they're solving this problem, uh what, maybe what tools they're using to solve this problem in the market um, etc., etc. And we, we landed on what we built on based on all that research. And from there it was R&D mode, you know we had to build the product uh till the end of the year. So for five, five and a half months or so. And then we used it as our... we were the first customer. We used it to get our own SOC 2 report. And we wouldn't launch the product until we had our own SOC 2 report uh, because we felt that that would be I don't know just weird. Uh like, we're selling uh compliant software yet we're not compliant ourselves. And so you know, surprisingly enough, all of our, all of our competitors launched the product without their own uh SOC reports.
Jake Aaron Villarreal: Oh wow. Really?
Daniel Marashlian: Yeah. So regardless of that, uh so you know, we waited. That you know, that process took about six weeks or so. It also was like over the holiday period and so people were off for Christmas and holidays and whatever. So you know we got it in the middle of January. And then the day after we got our SOC report in hand, we launched the company, which is, which was uh January 15th of, of 2021. And what we said was 2020 was a wash, we had some beta customers that maybe either were free or paid us $3,000 or something like that, like, but who cares? Uh, and, and the goal of 2021, uh, which was probably a solid goal of almost any SaaS business out there, we wanted to get a 100 customers and a million in ARR. That'd be a pretty successful year one. And that happened I think within like five or six weeks. And, and all of us were like, "Holy! Like we maybe hit the nail on the head." Wow. And, and so you know, through, through tons of iteration and communication with those early customers that we had direct Slack channels with, and, and wanting to you know just build and, and iterate as fast as possible for them, uh it continued to come.
And, and we said the goal, it was funny enough, the goal was to raise an A in uh like April of 2022. Uh you know, so build that million dollars, start the fundraising process, that takes three, four months, whatever. And uh yeah, so we did that in um, I forget the exact time, maybe April, March or April or something like that of 2021. And raised the A round of uh $25 million um. So it was pretty remarkable that you know uh uh in four-ish months or something like that since launching the business we, we uh the, the company was valued at uh 125 million I believe uh back then.
And uh the company prior that me and the same founding group, uh it was an ed-tech, it was a great company. Think of like LinkedIn for college kids. Uh we built it up, sold it to hundreds of universities and millions of students, and it was great. And after that seven, eight years, it, we ended up selling for 43 million to Instructure, the makers of Canvas. Uh so we worked with the Instructure and Canvas teams and integrated all that. And so it was, it was a you know, it was like interesting. It was like over seven years we, we built an amazing company and had a great, amazing exit. Uh and then, and then within a four-month window of launching our next product, it uh you know nearly tripled or tripled uh that, that value.
So we knew we had... it was the right timing. Everyone in COVID was working remote, companies were freaking out about how to better control the security and perimeter of all these remote employees that aren't in office anymore. Uh the, the news was swarming with it from large companies to small, and, and so it was perfect timing, our team was relentless in execution, that was amazing. And uh I think we had you know the right founding team. Uh we all kind of... I think the founding group we all were all like yin and yangs of each other. Um just uh yeah, to, to storm and go as fast as possible. But it also like we started out this conversation, it wasn't a four-month you know lottery ticket that we hit. Uh for me I've been uh not only in the industry for, for two decades, but building companies since yeah I guess 2007, 8 or so. Um it was you know call it 20 years of, of work and, and staying up till 3:00 a.m. moving a pixel. Yeah. Yeah. Yeah. And spinning up servers and...
Um one of our, one of the... let me see, the third company I started uh with a group, it was called TweetPhoto in 2008. And uh that, if you, if you guys were ever early Twitter users, we were the ones that put photos and media onto Twitter. And back then it was just media. And so we partnered with all the uh application and third party developers and Twitter which drove the ecosystem in the early days. And you know, with it... I, I don't have stats anymore like I, I don't think, maybe people weren't tracking it, but we were probably one of the earliest companies ever um to hit, uh to grow as fast as, as we did. Within 10 months of like starting a company, to 10 months into the company we had about 17 million users, and that was unheard of in 2008. So uh that, that was like four engineers, uh four you know marketing, business, go-to-market people, eight guys in an office cranking out, supporting 17 million users 10 months after starting the company and just like melting the servers we were running on because of the CPU and always architecting it better. And yeah, that grew pretty big, so that grew eventually to 45 million users. And um, so that was super fun. So again, being inside of the data center and, and installing Fusion-io hard drives, which I think you know those are even obsolete nowadays, but those were like the Ferraris of hard drives back then. And um you know, just, just at the hardware all the way up to the delivery of JavaScript in the CDN, needing to understand and master it to, to uh deliver the service that you're...
Jake Aaron Villarreal: You know, a lot of companies try and build and grow and scale and there's a lot of different hacks and techniques and ways to do it. Sometimes it's about just hiring really good marketing marketers and a team and they, they know how to do it. Um, 17... you throw out some big numbers. 17 million users, 45 million users. Uh what are some of the things that you've learned around just growing your, your user base you know out of the gate?
Daniel Marashlian: Yeah, I would say, I mean, a direct sales team is great, especially with right, the right leaders and process. And I think in a B2B company that makes most sense, and a B2C maybe not. But um I think the number one thing I learned, and I'm no sales expert right, I mean I've learned through osmosis over two decades, but uh it's really I think the one-to-many, the channel sale, the business development. Um I love our BD leader at Drata, he's unbelievable. He's built an amazing team. And uh that's where I see... I, and I told him from day one when he started, I was like, "I think you and your small and mighty team will outpace revenue of our larger sales team one day." And, and he's on his way to doing that, which I love. And so it's about I think yeah, just leveraging partnerships in the ecosystem. I think especially in cybersecurity where there is this stigma of "security is smart and scary and it's in the corner and it's this thing that I have to do," they outsource it to integrate to MSSPs, these managed service security providers, and other people to take on these efforts. Like a lot of IT does that too, a lot of companies will outsource their IT. So uh how do we continue to partner with those and, and, and giant like uh cloud service providers like AWS? And um yeah, just really I think you know in uh uh the In- uh Venture Arm is an investor in our C round. And um you know uh continuing to partner with them and as you know they, they acquired MailChimp and, and you know companies like that to better serve the SMB. And so how can we uh piggyback, continue to piggyback off of that trendline and uh build software and integrations and automations for the, the, the you know small medium businesses that drive America.
Jake Aaron Villarreal: God, there's so much to learn from somebody like yourself and I feel like I could talk to you all day long. What uh, I want to go back to something you mentioned earlier in the very beginning. We talked a, you talked a little bit about hiring and you know, talking to people that you would bring on board. What's your, what's your position on remote versus on-site versus hybrid?
Daniel Marashlian: Yeah, that is a hot topic nowadays. I will say, we would not have the success that we are in without a remote environment. So Drata is a remote company. We started, like I said, in July of 2020 in the height of the coronavirus pandemic. And we couldn't even you know, me and the founders that were, you know, built a company with each other for seven years probably couldn't even see each other. So uh you know, thankfully to the technologies like Slack and Zoom we were able to do all that stuff. But uh it's interesting because I, I value it so much, and the culture and the tool sets and the process that Drata is remote. But now three years into it and 600 employees later, I strive for human connection. And being in a room not only with my fellow engineers, but with product and design and QA and "Let's figure this out together, there's this product we're trying to do or this issue like let's whiteboard, let's solution." There's nothing that beats in-person and a whiteboard. Doesn't matter how much cool technology there is, from Miro to Figma to Zoom, I love all you guys and all your amazing technology, but nothing beats a whiteboard and being in the same room. So, so I, I don't have an answer. Like I, I wish I could, I could... What I wish I could do is invent a teleportation machine and just teleport people into office and then let them walk through a portal and go back home wherever they're at every day. That's what I wish I could do. Uh but, so I think though hybrids, and I think hybrid's probably going to be the future. But it still is going to be weird because it'll limit you on your hiring ability. So I think we, we have been able to open our gates around the world. We have engineers in Cambodia, Poland, Mexico, America, Canada, and it's, it's allowed us to uh, I mean I think even Uruguay and other spots. But um it's allowed us to hire the best of the best around the world that, that, that uh want to join our rocket ship and continue to build it. Uh which is amazing. But to then mandate all of them move to San Diego, that wouldn't be fair. Um to get an office in San Diego for the roughly 70 of us of the, out of the 600, and then they get all the 70 people get the perks and benefits and executive time that the others don't, that's maybe not fair to the others just because they happen to live in Montana, wherever they're at. Um so it's, it's a tricky, it's a tricky topic. Um I do, I do like being in person and so you know, if Drata ever does get a, an HQ, um you know maybe it's a spot where then we need to just figure out the budget uh where, where you, you come in and you fly in once a month or once a quarter and um you get you know scheduled time with certain teams and people. That's I think what probably it's going to be in the future uh for, for a lot of companies is um you know you in a way reduce your large you know, especially as companies get really big like 5,000 plus and you need giant campuses and you know... so maybe no longer do you need these giant campuses, but you get an office big enough for 200, 300 people, but then you just allocate that budget differently to fly people in once a quarter, something like that.
Jake Aaron Villarreal: That's great. Yeah, there we're seeing a lot of different responses of you know, hybrid, remote, moving back to on-site. Uh I don't know if there is a right answer we're talking. It's some you know we actually have a Chief People Officer service where you know a lot of companies don't, they can't afford a Chief People Officer, so they'll bring in one of our consultants like a fractural um. And, and the question is you know, what should we do? Should we go remote, should we stay remote, should we go on-site? And ultimately the responses we're getting are all over the map. But I think at some point you got to draw the line and say, "This is what we're doing, whether the industry is doing it or not. This is, this is how we're going about it," and, and make that decision. Uh that seems to have worked for a lot of companies from what we've seen so far. Uh in terms of going forward, what's next for Drata? I mean you've got sounds like a really good company, a rocket ship. You're holding on, you're building, you're scaling. Yeah. Where, what's next for, for Drata?
Daniel Marashlian: Yeah, for sure. It's continual um expansion to, to new customers, to new verticals. Uh the team has been building, building a, building a, building more features for the larger companies. While we love our, our SMBs and uh startups and, and um yeah I mean that's the world I came from, so that was the product we built from day one. Uh the you know, if you have 10 people in your company is, whether you're in the office or you're on Slack or something, it's easy to say, you know, "Hey Jake, go do your cyber training or whatever," right? "Go, go bark and yell at you for that." But uh if you have, if you have 500 Jakes, uh it's hard to corral that. So and the, the workflows you need to build to better support your thousand-person company, so we've been really focusing on how do you uh make it even easier for the CISOs and GRC teams at larger companies. And those are u- from the tool sets and the integrations and the workflows, uh we've been building a lot of that and continue to. Um so I think that's, that's a path forward. And I think just expanding uh uh and really making Drata um just world class. And even more world, world class I guess than what we have in, in uh automation. Like my end goal is to make this 100% automated. I will never get... it, will it will be a asymptote is how I view it for all you math nerds out there. It'll be this you know exponential curve that we will never achieve, but how close can I get to the line is my goal. And so um, in that, it's uh more integrations with you know the more and more popular tools that not only start every day, but gain popularity every day. To um different ways to manage not only your compliance, but your risk, privacy, um security.
Jake Aaron Villarreal: Got it. Really cool, Daniel. Anything I haven't asked you that you want to share or you want to talk about? Have we covered everything you got in your mind today?
Daniel Marashlian: Yeah, we covered a lot. Uh I would say uh you know, to all the founders uh of starting [a] company, there, the, the only way to understand if your idea is going to work is to do it. Um so figure out um your personal life, finances, time allocation, family, and uh jump into the deep end with both feet. That's what I would say.
Jake Aaron Villarreal: I love that. Daniel, thanks so much for your time today. I really appreciate you. And, and a big shout-out to the listeners that are listening for taking your time to spend with us. I know you could spend it in a lot of different areas, but appreciate you joining. Uh and again, my name is Jake Aaron Villarreal, the host of this podcast from the ground up, and I hope to talk with you again soon Daniel in the future. And for all listeners we'll catch up with you on the next episode. Before we wrap up I want to give a big shout out to all the entrepreneurs that have joined to make this podcast possible, and for all the listeners for listening. It means the world to me that you chose to spend your time with us today. I'm your host Jake Aaron Villarreal signing off for now. We can't wait to connect with you all soon on the next episode. Take care.
This show is sponsored by Match Relevant, a company that helps venture-backed startups find the best people in the market, and they do it in three simple steps. First, they sit down with founders to understand their story. Second, they tell their story into multiple candidate channels. And third, they schedule interviews within 48 hours. Find us at matchrelevant.com to learn more about how we do it.