Does compliance automation make us SOC 2 or GDPR compliant?
+
No. Whether your controls meet a framework is a judgement your auditor or regulator makes. Automation makes the controls run on time, removes what a review says should go, and keeps the evidence, which is usually the part an audit finds missing.
How is this different from a compliance tool like Drata?
+
A compliance tool tracks your controls, reads settings from connected systems and holds the evidence. Tray.ai runs the work around it that a settings check can't do, such as removing access after a review, searching every system for a data subject request and deleting records past their date, and sends the evidence back to the compliance tool.
Which systems does Tray.ai connect in compliance automation?
+
Compliance and ticketing (Drata, Jira, ServiceNow), identity and HR (Okta, Azure Active Directory, JumpCloud, Workday, BambooHR), the apps that hold personal data (Salesforce, HubSpot, Zendesk, Marketo, Outreach, Braze, NetSuite), engineering and cloud (GitHub, GitLab, Azure DevOps, Datadog, Splunk), and the document stores, chat and warehouse around them. Anything without a connector connects through its API.
Is Tray.ai itself audited?
+
Yes. Tray.ai is audited for SOC 1 and SOC 2 Type 2 every year, and both reports cover the whole platform on every plan. The reports are available through the Tray.ai trust center. They cover Tray.ai's own controls. Your controls are still yours, and your auditor still tests them.
Can compliance and privacy teams run this without engineering?
+
Yes. The apps in scope, review rules, retention schedule and control map open in Tray Build, the visual canvas, so compliance and privacy change them as policy changes. IT governs the credentials and who can change what.
Where do AI agents fit in compliance automation?
+
In the reading and the sorting. Agents can find personal data in free-text support tickets during a request, summarize why a change skipped review, and draft the explanation for an evidence gap for its owner to check. Removing access and deleting records run on fixed rules, with a person approving where the guide says so.
Do we have to replace our compliance tool or identity provider?
+
No. Tray.ai connects the systems you already run and carries the data between them. The stages above describe the work and the evidence, not which tools you use.