Overview
Drata watches your stack all day and tells you what fails: a repository without branch protection, a laptop without disk encryption, a person who has not accepted a policy. Then someone has to open each test, read the findings, decide what is real and what is out of scope, and act. That is the part that waits.
Why it's hard
Failing tests are spread over many pages, each with its own list of resources. An exclusion needs the right resource, picked in the test's findings, and a reason good enough for an auditor. Checking whether a leaver is still a Drata user is another trip to the settings. None of it is hard, but all of it is manual, and it comes back every week.
How Reduck does it
Reduck is an MCP server whose Drata scripts run in your own Chrome, signed in as you. Your agent reads what you see in Drata and acts only when you ask. The Reduck team runs its own compliance in Drata with these scripts.
A typical weekly review, in one request:
- List failing tests returns every test that fails in production, with its failing resources or people.
- The agent groups them by owner and proposes what to fix and what is out of scope.
- You approve. Exclude a finding records each exclusion with the reason you agreed on.
- List platform users confirms that people who left are no longer in Drata.
What your agent does
- List the monitoring tests that fail in production, with each finding and its severity
- Group findings by owner and propose the next step
- Exclude a resource from a test with the justification auditors read
- List your Drata users with roles, date added and last login, or check one email
- Read an employee's own compliance checks and policy acceptances
Who it's for
- Startups going through SOC 2 or ISO 27001 with Drata
- Founders and ops leads who own compliance without a GRC team
- Anyone who wants a weekly Drata digest in their AI assistant