The Arnica integration enables security and compliance teams to automatically sync vulnerability data from Arnica into Drata.
This integration helps automate evidence collection for the Vulnerability Scanning test, mapped to DCF-18 by default.
Key Capabilities
Automated Vulnerability Sync: Imports up to 1,000 new or updated vulnerabilities per day per connection.
Severity-Based Filtering: Allows selection of vulnerability levels such as Critical, High, or Medium.
Date Filtering: Syncs vulnerabilities detected on or after a specified “first seen” date for precise reporting.
Prerequisites & Data Access
Must have Admin, Information Security Lead, DevOps Engineer, or Workspace Manager roles in Drata.
Must have an active Arnica account.
Must create and copy the Arnica API token with the required scope:
risks:read
Ensure you have permission to generate and manage API tokens in Arnica.
Permissions & Data Table
Permission/Scope | Why It’s Needed | Data Accessed |
risks:read | Allows Drata to access and sync vulnerability data from Arnica. | Vulnerability and risk data (Read) |
Step-by-Step Setup
Step 1: Generate the Arnica API Token
Log in to your Arnica account.
Navigate to your API settings or Developer section (depending on your account setup).
Create a new API token.
Enable the following scope:
risks:read
Copy and securely store your Access Token. You’ll need it to connect Arnica to Drata.
Expected outcome: You now have a valid Arnica API token with the risks:read scope.
Step 2: Complete the Connection in Drata
In Drata, navigate to Connections → Available Connections.
Search for Arnica and select Connect.
Enter the following fields:
Drata Field | Arnica Value |
Severity | Select vulnerability levels to include (e.g., Critical, High, Medium). |
First Seen On | Select the date from which Drata should begin syncing vulnerabilities. |
Access Token | Paste your Arnica API token with the |
For steps on accessing and using the Connections page in Drata, refer to The Connections Page in Drata.
Once connected:
Drata imports up to 1,000 new or updated vulnerabilities per day per connection.
Imported vulnerabilities are prioritized from Critical → Low severity.
Your severity and first seen on filter selections are included in the test result report for visibility.
Step 3: Verify and View Results
Select View Findings after connecting Arnica, or
Navigate to the Vulnerabilities page via Drata’s left-side navigation menu.