This article covers the file formats supported in Evidence Library, Controls, and Risk Management, and how Drata scans uploaded files for malicious content.
Here's why
Uploading evidence to Drata is a key part of maintaining your compliance posture.
We want to ensure certain file types uploaded to your account do not contain malicious content that could affect Drata or your account.
Supported file formats
The following file formats are scanned for malicious content:
Scan and save:
.zip,.txt,.json,.markdown,.md,.csvScan and save (download-only, not previewed in browser):
.msg,.mp4,.log,.html
These file formats are supported in Evidence Library, Miscellaneous evidence for a control, and supporting documents for a risk in Risk Management.
These file types won't be saved in Drata until after we've scanned them.
The Drata Open API does not support these file formats.
File size limits
Individual files: 50 MB maximum per file
Zip files: Up to 100 MB total (unzipped). Each individual file inside the zip must be under 50 MB.
Zip file details
A ZIP file may include:
One additional ZIP file inside, or
Files with the listed extensions above (
.txt,.json,.markdown,.md,.csv)
If a zip file is scanned and rejected due to potentially malicious content, the event tracking details will include which file in the zip was identified as potentially malicious.
Uploading a file that needs to be scanned
Select the file you want to upload.
Drata will scan the file.
If the file is safe, Drata will save it.
If potentially malicious content is detected, Drata will reject the file and create an event in Event Tracking.
An email will be sent to the user who tried to upload the file, notifying them it was rejected along with a link to the event tracking details.
If the file is a required step
If the file is required at a step in Drata, you will have to wait until after the scan is complete to continue.
For example, if you are uploading miscellaneous evidence to a control, the file is required. If you select Save File before scanning is complete, there will be an error.
You can always close the modal by selecting Cancel at any time. Once the file is saved, you can select Save File and continue.
