StackGen has partnered with Google Cloud Platform (GCP) to bring its platform to the Google Cloud Marketplace.
Drata has acquired oak9, a cloud native security platform, and released a new capability in beta to seamlessly bring continuous compliance into the software development lifecycle.
The acquisition enables Drata to monitor compliance both before and after code is deployed to production. This capability, called Compliance as Code, will be demonstrated at RSA, May 6-9 in San Francisco.
Acquiring oak9 and launching Compliance as Code in Drata now equips thousands of DevSecOps, GRC, and engineering teams with the power to identify and remediate potential compliance violations as code is developed, instead of after it's deployed. GRC teams are routinely challenged to address compliance issues after changes are already in Production, creating a backlog of issues to address after deployment. As DevOps teams grow bigger and more complex, the need to "shift left", to address these compliance gaps earlier in the SDLC, has significantly increased in order to maintain compliance standards without sacrificing speed of development. Oak9 specialized in infrastructure-as-code to build security and compliance into cloud native applications as they are developed, and offered a catalog of out-of-the-box blueprints that ensured that customers can meet their security and compliance objectives for any architecture on any cloud provider.
"It's time to break down infrastructure and GRC silos to stop the cycle of costly and repetitive compliance remediation work. This is the future of compliance automation and GRC and it's here now," said Adam Markowitz, Drata Co-Founder and CEO. "Drata Compliance as Code empowers developers, engineers, and GRC teams to save countless hours by shifting compliance left in the SDLC, collectively improving security and code quality while fostering a culture of continuous compliance."
Integrating oak9's software brings Drata into crucial areas of the SDLC where changes happen, including the code repository, and the continuous integration and continuous delivery/deployment (CI/CD) pipeline. Pre-built tests map to an organization's compliance requirements by scanning their infrastructure code and flag gaps and anomalies with key details for the GRC team to resolve. Now, GRC teams will have shared visibility into their cloud infrastructure and be able to identify failing controls within the code before it ever makes it into production, creating more efficiency and confidence leading up to an audit.
"Oak9's mission from day one has been to address critical security gaps throughout the software development lifecycle, including gaps with compliance, which is all too often viewed as an afterthought. That mindset can be costly for the entire organization," said Om Vyas, Co-Founder and CEO of oak9. "Being integrated into Drata's platform is exceptional validation of our team's commitment to realizing this mission. This sets a new standard in how teams tackle cloud native security and compliance."
Industry News
Tricentis announced its spring release of new cloud capabilities for the company’s AI-powered, model-based test automation solution, Tricentis Tosca.
Lucid Software has acquired airfocus, an AI-powered product management and roadmapping platform designed to help teams prioritize and build the right products faster.
AutonomyAI announced its launch from stealth with $4 million in pre-seed funding.
Kong announced the launch of the latest version of Kong AI Gateway, which introduces new features to provide the AI security and governance guardrails needed to make GenAI and Agentic AI production-ready.
Traefik Labs announced significant enhancements to its AI Gateway platform along with new developer tools designed to streamline enterprise AI adoption and API development.
Zencoder released its next-generation AI coding and unit testing agents, designed to accelerate software development for professional engineers.
Windsurf (formerly Codeium) and Netlify announced a new technology partnership that brings seamless, one-click deployment directly into the developer's integrated development environment (IDE.)
The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native software, is making significant updates to its certification offerings.
The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native software, announced the Golden Kubestronaut program, a distinguished recognition for professionals who have demonstrated the highest level of expertise in Kubernetes, cloud native technologies, and Linux administration.
Red Hat announced new capabilities and enhancements for Red Hat Developer Hub, Red Hat’s enterprise-grade internal developer portal based on the Backstage project.
Platform9 announced that Private Cloud Director Community Edition is generally available.
Sonatype expanded support for software development in Rust via the Cargo registry to the entire Sonatype product suite.
CloudBolt Software announced its acquisition of StormForge, a provider of machine learning-powered Kubernetes resource optimization.