User Reviews Overview
About Vanta
Whether you’re starting or scaling your company's security program, demonstrating top-notch security practices and establishing trust with your buyers and customers is more important than ever. Vanta’s Trust Management Platform...
Learn moreAll Vanta Reviews Apply filters
Browse Vanta Reviews
All Vanta Reviews Apply filters
- Industry: Financial Services
- Company size: 201–500 Employees
- Used Daily for 1+ year
-
Review Source
Great GRC instrument
Pros
Policy creation and management. Toons of integration and automated tests. Very cool integrated vulnerability management.
Cons
Risk management can be more flexible. We started the new approach to risk assessment and can’t use internal risk management instrument so we made it in excel :-)
- Industry: Financial Services
- Company size: 11–50 Employees
- Used Daily for 6-12 months
-
Review Source
Essential for Compliance
We needed to get SOC 2 audit ready and were only progressing slowly with the manual approach. As it turned out that manual preamble was useful because when we started using Vanta, we understood the terminology and understood what was wanted.
Pros
Vanta enabled us to move our compliance (SOC 2, and next PCI) projects forward in an organized and monitored manner. After struggling manually with SOC 2 requirements with a major accounting firm, we got to audit readiness in half a year and felt confident going into our audit.
Cons
There is definitely a learning curve, and I am sure the system has useful features that I have not encountered yet. That is not really a negative, though.
Reasons for Switching to Vanta
3 main reasons: 1. Vanta's integration with an audit firm. We could connect with an audit firm through Vanta, rather than just working from a list. 2. The price was actually the most reasonable. 3. They offer modules for other frameworks we want to work on going forward.- Industry: Information Technology & Services
- Company size: 2–10 Employees
- Used Daily for 6-12 months
-
Review Source
Awesome tool to make your company audit ready
Pros
The automation that Vanta offers, does get you really far on your path to become a certified company. The policy builder is one of the best features of the service. There is a wide variety of different frameworks to choose from.
Cons
The start can be a bit overwhelming because there is a lot to do but you will get forward quite fast.
Alternatives Considered
ISMS.onlineReasons for Switching to Vanta
Vanta offered better implementation support.Top Vanta Alternatives
- Industry: Accounting
- Company size: 2–10 Employees
- Used Monthly for 6-12 months
-
Review Source
BUYER BEWARE
This business charged my card for a second year without permission and after being told I would not renew. They took thousands of dollars. I needed to do a chargeback after they refused to return the money even though I notified them same day they were previously told I would not renew. It turns out they have a clause in their contact that says you need to notify them 30 days in advance of renewal. Well, guess what? I did! Still, it's a stupid clause that they use, clearly, to force clients to renew who don't realize such a clause exists. Buyer beware with this shady organization. I wouldn't recommend them to anyone, except maybe someone I didn't like.
Pros
The software seemed easy to use - at first, until some of my documents disappeared without explanation.
Cons
They lost documents, and weren't able to explain to me satisfactorily where they went. This caused me to question renewal. I notified them I wouldn't renew without a good explanation, which I never got. Also, they make very difficult to reach them when you have a problem. At the time of this writing, no phone numbers in any email signatures, not on the web site either. You're forced into their process, and if they choose not to answer you via their web form, good luck. It's a black box at that point.
- Industry: Marketing & Advertising
- Company size: 11–50 Employees
- Used Daily for 1+ year
-
Review Source
Compliance simplified
Very good. We have been able to formalize our internal security programs and successfully completed our SOC2 audit.
The Vanta team has always been very responsive to our needs, soliciting feedback and promptly answering questions (no matter how basic) and guiding is in the right direction.
Pros
We love that Vanta has made it easy for us to develop a comprehensive InfoSec program and helped us prepare for our SOC2 audit. Onboarding was straightforward and the continuous monitoring ensures ongoing compliance. The product integrates with most of the software we use day-to-day and has saved a lot of time.
Cons
There are some areas of the UI which are a bit rough around the edges and non-intuitive, I chalk this up to Vanta being a relatively new product. It has improved a lot since we became a customer and specific areas such as the employees onboarding/off-boarding flows show that the team is constantly iterating and responsive to user feedback.
In addition, I would love to see more automation in the product - we are a smaller company without a dedicated IT team. Vanta does a great job of alerting us to issues, but being able to help us take steps to remediate would be much appreciated.
Alternatives Considered
HyperproofReasons for Switching to Vanta
Vanta came up through a personal recommendation. We liked the team a lot and the sales process was simple and straightforward, it gave us a great view into the product and the thinking behind it.- Industry: Information Technology & Services
- Company size: 2–10 Employees
- Used Daily for 1-5 months
-
Review Source
Vanta works well for Compliance Management
Pros
Vanta is great at providing clients with a step-by-step guide on compliance. It gives the Trust center for free, which some competitors do not. They keep updating it because they listen to their customer's needs.
Cons
The templates for policies need a little update. Vendor assessment - a security questionnaire would be a nice-to-have as we'd like for our contractors to take a security awareness training, respond to some questions, and/or provide us with responses to a security questionnaire.
- Industry: Computer Software
- Company size: 51–200 Employees
- Used Daily for 1+ year
-
Review Source
Top-Tier Automated Compliance Tracking
Vanta has been great to work with, and continues to listen to feedback and implement fixes wherever possible. They make the audit process easy and preparation ahead of the audit simple.
Pros
Vanta is continually growing to provide its clients with top-tier compliance tracking. While some pieces are still managed manually, that number is dwindling as Vanta continue to expand on their already extensive automated services. Vanta support is outstanding. Vanta also makes understanding compliance targets and requirements easy.
Cons
The frequent changes that Vanta undergoes as they continue to improve their platform can be mildly disruptive, but the payoff is always worth it.
They integrate with some of the key components of our software stack but we'd like to see more as it relates to provisioning/deprovisioning, vendor management/security assessment, and MDMs.
- Industry: Computer Software
- Company size: 201–500 Employees
- Used Daily for 6-12 months
-
Review Source
Great Product, Great support
It's been great. I'm huge on support for apps. I'll pay more for an app if they have A+ support along with automations.
Pros
I love how easy it is to understand, the service and support. When I was first introduced to Vanta it was already set up, and while I was trying to put all the puzzle pieces together all I did was go in every day, attend/watch some webinars, my CSM has been great and it didn't take long for me to start to understand. I love that they take my feedback and pass it on to their team.
Cons
There was an update to the homepage, however their support team shared a quick tip on how to view the testing page ANNNND took my feedback to the why
- Industry: Computer Software
- Company size: 11–50 Employees
- Used Daily for 6-12 months
-
Review Source
Smooth and seamless SOC2 preparation
We needed to get a SOC2 audit completed quickly to satisfy a customer need. Most "traditional" audit shops told us it would take 12 - 15 months. With the automation features, customer support, and auditor integration, we were done end-to-end (from signing up with Vanta to receiving our SOC2 report) in just over 5 months. Very smooth process from beginning to end - went almost exactly as advertised during the sales process - that's rare and unexpected these days.
Pros
User interface was intuitive - provided a clear "checklist" approach for actions to take and problems to resolve. Vanta Agent (for our laptops and (virtual) servers at AWS) is very useful to ensure continuous oversight of what's on the machine and when it needs to be updated. Working with our auditor to get our first SOC2 was also seamless and painless - the auditor plugged right into our Vanta instance and downloaded/monitored everything remotely - no need for screen shots or sending lots of documentation.
Cons
Would have been nice to have more integrations with some of our existing tools (monday.com, AWS Code Commit, etc.) to make the process even more automated. The automated policy generator is nice for filling holes in an existing policy suite, but isn't great if you have to make a lot of customizations to it as the "automated" part breaks down once you edit it offline. Two minor things in an overall great experience.
- Industry: Music
- Company size: 11–50 Employees
- Used Weekly for 6-12 months
-
Review Source
Vanta's automated tests are great. Dashboard is intuitive.
Vanta's dashboard is easy to follow. Instructions for how to fix failing tests are clear. I am happy that we don't have to create these tests ourselves. And I am thankful that Vanta tells us what's important.
Pros
As a software engineer in charge of preparing our cloud infrastructure for security compliance, I really enjoy the automated tests that Vanta deploys to our cloud providers. These tests are comprehensive. They would take us months to create ourselves. I am happy Vanta does this for us.
Cons
I do not know how to efficiently triage the information I get from Vanta notifications. I get a lot of notifications about failing automated tests in my email and in my Slack. I get "alarm fatigue" and end up ignoring most of the notifications.
- Industry: Hospital & Health Care
- Company size: 201–500 Employees
- Used Daily for 6-12 months
-
Review Source
Great Resource for Security Compliance
The support at Vanta is incredible and the platform continues to be a huge asset to our security compliance program.
Pros
I use Vanta every day for my work in compliance. The main Tasks page is extremely helpful in flagging and identifying where I need to focus my attention, which allows me to efficiently spend my energy. Being part of a smaller company (for now!), this platform was invaluable during our SOC 2 audit as a source of evidence for many technical and operational controls. My favorite features include a space for hosting security policies (they have so many awesome customizable templates, too) and tracking who has reviewed and accepted them, allowing real-time reporting on technical controls that our customers can view, and vendor and other inventories to keep track of our resources.
Cons
I look forward to seeing more product enhancements in the future. I would love to see more integrations or an admin-facing API so that the same groups and dates used in our identity platforms aligned here, and other user-experience efficiencies like bulk sending email reminders or viewing a person's onboarding tasks plus their assigned computer's information within one row on the same page.
- Industry: Financial Services
- Company size: 2–10 Employees
- Used Daily for 6-12 months
-
Review Source
Playbook for SOC-2, and Outsourced Compliance Employee!
Having no SOC-2 background, a friend suggested checking out Vanta to speed up the SOC-2 process. We were blown away by the amount of work that needed to be completed, but working with Vanta helped automate and most importantly organize the requirements for SOC-2 type 1. Our SOC vendor was impressed by the number of things we had completed and it made our type 1 attestation a cinch - 5 weeks!
We're in the process of type 2 (12 months) and Vanta has been a valuable asset to help us maintain our compliance. Without Vanta, we would have had to hire a consultant or FT employee to manage the project.
Pros
Ease of use, support and expertise and confidence in remaining compliant before and after the real SOC-2 process.
Cons
Only critique is that when we started, Vanta was very new to the market and they lacked some integrations. However, we saw rapid improvements and additional integrations during our initial work with them and they were very responsive to our needs.
- Industry: Information Technology & Services
- Company size: 51–200 Employees
- Used Daily for 6-12 months
-
Review Source
Great value and support
I found the support getting the controls to be compliant and option for auditors very useful. Additionally, the templates for documentation and automation for people and computer controls to be extremely helpful.
Pros
The automation, templates, features and support. The ability to view and remediate the issues with people and hardware was very useful. The document templates were very helpful in getting them done quickly.
Cons
One or two brief bugs in the software. They were resolved quickly!
- Industry: Financial Services
- Company size: 11–50 Employees
- Used Daily for 6-12 months
-
Review Source
Excellent security product
Pros
Vanta keeps track of our device inventory and cloud resources. Integration to our systems is seamless. The software is easy to set up and has a few great dashboards for monitoring and addressing vulnerabilities and compliance issues.
Cons
It is fairly easy to trick Vanta into passing a certain compliance check. It's up to the implementer of the security measures to check carefully that the resources are in compliance, since Vanta can at times provide false positives.
- Industry: Financial Services
- Company size: 11–50 Employees
- Used Daily for 6-12 months
-
Review Source
Best path to get to SOC 2 for early stage startups
Pros
Extensive integrations made it very easy to audit our entire infrastructure. Without Vanta, gathering critical evidence for our SOC 2 audit would have been a pain.
Cons
I wish the platform could be extended to other popular certifications such as PCI .
- Industry: Computer Software
- Company size: 11–50 Employees
- Used Weekly for 6-12 months
-
Review Source
Finally confident in our HIPAA compliance
Pros
In the past we navigated our HIPAA compliance on our own. There was just too much to keep track of. Vanta has made it really easy to know if we're compliant or if there are issues we need to address.
Cons
There aren't really any cons. The training videos for employees are cheesy, but I don't think there's any way around that :)
- Industry: Computer Software
- Company size: 11–50 Employees
- Used Weekly for 6-12 months
-
Review Source
Vanta makes SOC 2 compliance easy
Pros
Vanta makes it easy by giving you a dashboard to check regressions, and gives you easy templates of complying policies to implement in your organization.
Cons
The dashboard is web-UI only. An API would be nice, or even better - integrations with our existing issue trackers.
- Industry: Information Services
- Company size: 11–50 Employees
- Used Weekly for 1-5 months
-
Review Source
Makes security compliance fun and easy (for real)
Killer product. Great engagement with their account management too.
Pros
* Clean, simple, easy to use.
* Policy generation is particularly magical.
* Brings structure and order to the SOC compliance mess.
Overall, Vanta has gamified aspects of compliance to the point where I no longer dread or fear it. It's actually kinda fun.
Cons
Could use more integrations. Once you go off the beaten path, you're fully on your own.
- Industry: Information Technology & Services
- Company size: 201–500 Employees
- Used Weekly for 6-12 months
-
Review Source
title
Very good customer support.
Pros
Easy to get overiew about your systems in use and compliance check list.
Cons
In general not sure about overall security.
- Industry: Computer & Network Security
- Company size: 2–10 Employees
- Used Monthly for 1-5 months
-
Review Source
Vanta is the future of compliance.
Pros
Software is intuitive, the policies alone are worth the cost, and I'm impressed by how Vanta continually expands coverage and functionality.
Cons
There really isn't anything I don't like about the software.