Overview
Drata Autopilot is a security scanner from Drata used for security scanning, malware checks, vulnerability assessment, certificate review, and site-safety analysis.
Its primary user-agent pattern is Dratabot; a representative HTTP user-agent is Dratabot (+https://dratabot.com).
Drata Autopilot is verified with Medium confidence. The identity type is Verified Bot, and the evidence basis is a public crawler reference or source-linked documentation.
Drata Autopilot is marked as not reliably governed by robots.txt directives; use server-side rules if the traffic should be restricted.
Drata Autopilot can usually be allowed after confirming the source and monitoring request volume.
Identity
- User-Agent Pattern
-
Dratabot - HTTP Agent Examples
-
Dratabot (+https://dratabot.com) - Robots Token
- Dratabot
- Identity Type
- Verified bot
- Evidence Method
- Verify Drata Autopilot by matching `Dratabot` to Drata evidence, then checking reverse DNS, source-network ownership, signed request data, or published crawler documentation when available.
Classification
- Type
- Security
- Kind
- Scanner
- Family
- Drata
- Purpose
- Security
Behavior and handling
- Common Use
- Drata Autopilot is used for security scanning, malware checks, vulnerability assessment, certificate review, and site-safety analysis.
- Detection Notes
- Drata Autopilot traffic is primarily detected by the `Dratabot` user-agent pattern; a representative HTTP user-agent is `Dratabot (+https://dratabot.com)`. Compare source IPs, reverse DNS, request paths, and crawl cadence with Drata infrastructure before trusting the traffic.
- Respects robots.txt
- No
- Spoofing Risk
- Drata Autopilot has medium spoofing risk because user-agent strings can be copied; pair the match with DNS, IP, behavior, or operator evidence.
- Risk
- Safe
- Recommended Handling
- Do not block
Rules and controls
- Robots.txt Snippet
-
# This agent may ignore robots.txt. Use authenticated access controls or network policy when blocking is required.
Relationships
- Operator
- Drata Checked 2026-06-23
Relationships without an Evidence link are normalized from the canonical directory record. They should not be interpreted as independent proof of physical presence or request origin.