Select your cookie preferences

We use essential cookies and similar tools that are necessary to provide our site and services. We use performance cookies to collect anonymous statistics, so we can understand how customers use our site and make improvements. Essential cookies cannot be deactivated, but you can choose “Customize” or “Decline” to decline performance cookies.

If you agree, AWS and approved third parties will also use cookies to provide useful site features, remember your preferences, and display relevant content, including relevant advertising. To accept or decline all non-essential cookies, choose “Accept” or “Decline.” To make more detailed choices, choose “Customize.”

    Listing Thumbnail

    Vanta

     Info
    Sold by: Vanta 
    Vendor Insights
    Vanta helps thousands of fast-growing companies simplify and centralize compliance and security workflows so they can build trust.

    Overview

    Play video

    Vanta is the creator and global leader in Trust Management. Today, more than 4,000 AWS customers trust Vanta to streamline their security and compliance programs.

    With more than 300 third-party integrations, Vanta is able to automate the testing and collecting of evidence for frameworks ranging from SOC 2 to FedRamp to NIST AI.

    For companies with self-hosted or custom-built solutions, Vanta also offers the ability to quickly create custom automated tests in the platform, or through the Vanta API.

    Vanta is the only multi-product vendor in the Trust Management category and also offers AI-powered Third Party Risk Management and Trust Center solutions.

    Vanta has three unique packages for customers based on the complexity of their security and compliance programs. Those packages are also based on company headcount.

    A preview of pricing for companies with 1-20 employees can be found below. More details on Vanta pricing and packaging can be found at: vanta.com/pricing.

    AWS customers interested in private offers should email awsmarketplace@vanta.com .

    Highlights

    • Vanta goes beyond checklists and point-in-time audits with continuous monitoring that keeps you secure and compliant at all times. If issues arise, you can receive alerts and guidance via email and Slack or use Vanta's task-tracker integrations to stay on top of fixes.
    • Vanta unifies security program management by bringing together key compliance and security workflows, like access reviews, vendor risk management, and more, saving you time and giving you better contextual insight for prioritizing and managing risk.
    • Build trust in your organization and demonstrate a commitment to security by proactively sharing your Trust Center with customers and prospects.

    Details

    Sold by

    Delivery method

    Features and programs

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (2)

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Pricing is based on contract duration. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.

    12-month contract (6)

     Info
    Dimension
    Description
    Cost/12 months
    AWS FTR
    AWS FTR Module
    $7,500.00
    Core Package
    Starting cost for 1-20 employees
    $11,500.00
    Growth Package
    Starting cost for 1-20 employees
    $22,675.00
    Scale Package
    Starting cost for 1-20 employees
    $48,970.00
    Trust Center
    Starting cost for 1-20 employees
    $6,000.00
    Vendor Risk Management
    Up to 50 vendors managed
    $11,200.00

    Vendor refund policy

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Support

    Vendor support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Monitoring
    Top
    25
    In IT Business Management
    Top
    10
    In Centralized Risk Management, Monitoring, Security

    Customer reviews

     Info
    AI generated sentiment from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness

    Error loading component.

    Error loading component.

    Error loading component.

    Error loading component.

    Error loading component.

    Error loading component.

    Error loading component.

    Error loading component.

    Error loading component.

    Error loading component.

    Error loading component.

    Error loading component.

    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Continuous Monitoring
    Continuous monitoring that keeps the organization secure and compliant at all times, with alerts and guidance for addressing any issues that arise.
    Unified Security Program Management
    Unification of key compliance and security workflows, such as access reviews and vendor risk management, to save time and provide better contextual insight for prioritizing and managing risk.
    Trust Center
    Ability to proactively share the organization's security and compliance posture with customers and prospects to build trust.
    Automated Testing and Evidence Collection
    Automation of testing and evidence collection for a range of security and compliance frameworks, including SOC 2, FedRAMP, and NIST AI.
    Custom Automated Tests
    Capability to quickly create custom automated tests within the platform or through the API for self-hosted or custom-built solutions.
    Automated Evidence Collection
    Automated collection of audit evidence through more than 100+ integrations with core services such as AWS, Asana, Azure, G Suite, Google Cloud, Github, Gusto, JAMF, Okta and Slack
    Customizable Security Policies
    Prebuilt security policy templates that can be edited to meet the organization's specific needs and ensure they meet the high standards of an auditor or regulatory framework
    Scalable Platform
    Ability to support unique setups with multiple cloud service providers and hundreds of instances, scaling with the business
    Machine Learning-powered Questionnaires
    Secureframe's machine learning-powered solution that makes it fast and easy to respond to RFPs and security questionnaires by pulling the best answer for each question based on approved past responses
    Dedicated Compliance Expert
    Every customer is assigned a dedicated compliance expert, an ex-auditor who can help answer complicated and specific questions that come up, especially during the audit process
    Continuous Monitoring
    Continuously monitors security controls and alerts customers when controls are not operating effectively to remediate and stay secure
    Automated Evidence Collection
    Automatically collects evidence needed for audits to streamline the audit process
    Compliance Framework Integration
    Integrates with over 20 compliance frameworks, standards, and regulations such as SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR
    Application and System Integration
    Integrates with over 200 applications and systems to continuously monitor security controls
    AWS Integration
    Integrates with 45+ AWS services and is an AWS Security Competency partner with an AI engine built on AWS Bedrock

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    No security profile
    -
    -
    -
    -

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    5
    2 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    100%
    0%
    0%
    0%
    0%
    2 AWS reviews
    |
    1585 external reviews
    External reviews are sourced from G2  and are not included in the star rating for this product.
    Brooke Lynne B.

    Ever-Evolving GRC Platform

    Reviewed on Feb 18, 2025
    Review provided by G2
    What do you like best about the product?
    Ease of use for those who are not familiar with GRC platforms is a huge selling point. Setting up integrations and getting your GRC program up and running makes it incredibly easy for the end user; whether its a seasoned IT professional or a new compliance analyst.
    What do you dislike about the product?
    Some features aren't as "User Friednly" as they could be though this continues to be enhanced over time with customer feedback being taken into account. While we've had some issue with a certain 3rd party integration, Vanta has continued to make themselves and their engineers available to help resolve (even though the issue lies with the other 3rd party and not Vanta). I'm sure some of the "kinks" I refer to will be worked out over time with future sprints and continued customer feedback.
    What problems is the product solving and how is that benefiting you?
    The platform is allowing a small but mighty team to have a holisitic view of our overall compliance program and the health of it and its supporting programs and processes. It allows for organizational transparency and reduces the audit fatigue that can occur with technical teams. Once fully built, a client can easily self-serve any evidentiary objects needed to complete an audit without having additional resources involved. At the end of the day, Vanta helps us move from spreadsheets to a centralized location that isn't tamperable and allows for stakeholders to drill into specific metrics and areas to ensure compliance.
    Computer Software

    HR Consultant

    Reviewed on Feb 18, 2025
    Review provided by G2
    What do you like best about the product?
    The ease of the platform that walks you through necessary steps and the best customer service I have received from any platform.
    What do you dislike about the product?
    I find the email notifications make it easy to navigate but upon log in you may not know where exactly to go for the highest priority items.
    What problems is the product solving and how is that benefiting you?
    System integrations and access
    Computer Software

    Easy to use and with structured documentation

    Reviewed on Feb 18, 2025
    Review provided by G2
    What do you like best about the product?
    That it offers templates and guidance when developing documents and that it can directly correlate these to controls.
    What do you dislike about the product?
    There's some documentation and controls which need to be disabled based on type of business, ie not a company with a physical address.
    What problems is the product solving and how is that benefiting you?
    Helping us in our ISO 27001 accreditation.
    Andrei I.

    great tool for ISO 27001 compliance

    Reviewed on Feb 17, 2025
    Review provided by G2
    What do you like best about the product?
    - ease of use
    - detailed reporting
    - live reports with data flowing into Vanta from external apps
    - customer support is friendly
    - I use it on a daily basis to keep on top of the different compliance aspects of my function
    What do you dislike about the product?
    - newest visual update has some issues, which are fairly common across other vendors too (clicking on stuff pops the side of the browser in front of the list you were viewing)
    - could use more integrations
    - some of the MDM tools don't report all the required information (granted, this is more on the 3rd party vendors, but Vanta could incentivize them or pressure them)
    What problems is the product solving and how is that benefiting you?
    mainly the ISO 27001 certification, but also to get a better security posture overall
    Financial Services

    Great emerging product in the cyber GRC space

    Reviewed on Feb 17, 2025
    Review provided by G2
    What do you like best about the product?
    Using the AI assistance to review 3rd party documents.
    What do you dislike about the product?
    product still has a lot of bugs and incomplete features.
    What problems is the product solving and how is that benefiting you?
    Aspects of vanta that are running well have been great value-add:
    * User governance - Including notificaitons when this degrades in our environment.
    * General alerts when anything degrades that I care about (eg. open port 22 on internet)
    * Great to track ISO27 compliance progress.
    View all reviews