Listing Thumbnail

    Vanta

     Info
    Sold by: Vanta 
    Deployed on AWS
    Vendor Insights
    Vanta helps thousands of fast-growing companies simplify and centralize compliance and security workflows so they can build trust.

    Overview

    Play video

    Whether you're just starting out or scaling a mature security program, demonstrating strong security practices and building trust with buyers has never been more critical.

    Vanta's Trust Management Platform helps over 6,000 AWS customers, including Atlassian, Modern Health, and Mistral AI, automate compliance, improve visibility, and reduce manual work. Security, GRC, and IT teams use Vanta to:

    • Automate evidence collection across 35+ frameworks, including SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR
    • Centralize GRC workflows like risk and vendor management
    • Complete security reviews up to 5x faster

    Now, with the Vanta AI Agent, teams can unlock a new level of efficiency. Acting like an intelligent teammate, the AI Agent helps manage tasks, recommend next steps, and generate audit-ready documentation, enabling teams to work faster, stay organized, and be more proactive in maintaining trust.

    Vanta customers report a 526% ROI over three years, with most seeing payback in just three months. On average, Vanta boosts compliance team productivity by 129%, helping teams do more with less.

    For more complex environments, Vanta supports custom automated tests, built directly in-platform or via the Vanta API, ideal for self-hosted and custom-built systems.

    As the only multi-product vendor in the Trust Management space, Vanta offers not only core compliance automation but also AI-powered solutions across Third Party Risk Management, Trust Center, and now, the Vanta AI Agent, which brings intelligent guidance and automation to every layer of your security.

    Pricing is tiered based on company size and program complexity. Preview pricing for 1-20 employees and more at: vanta.com/pricing. Interested in a private offer via AWS Marketplace? Email awsmarketplace@vanta.com 

    Highlights

    • Built for AWS - not just compatible: As an AWS Security Competency Partner with deep integrations across 40+ AWS services, Vanta gives you full visibility into your cloud security and compliance, and is purpose-built for AWS-native environments.
    • Automated and scalable compliance: Continuously monitor your AWS environment to meet frameworks like SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR. Vanta automates evidence collection and policy management to reduce manual effort and audit prep time.
    • Security posture, strengthened by AI: Leverage the Vanta AI Agent for intelligent task management, smart recommendations, and real-time responses to audit needs. Combined with features like real-time audit trails, centralized access reviews, and AI-powered Vendor Risk Management, Vanta helps you stay secure and audit-ready all year round.

    Details

    Sold by

    Delivery method

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (2)

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (9)

     Info
    Dimension
    Description
    Cost/12 months
    AWS FTR
    AWS FTR Module
    $7,500.00
    Core Package
    Starting cost for 1-20 employees
    $12,000.00
    Growth Package
    Starting cost for 1-20 employees
    $22,675.00
    Scale Package
    Starting cost for 1-20 employees
    $48,970.00
    Trust Center
    Starting cost for 1-20 employees
    $6,000.00
    Vendor Risk Management
    Up to 50 vendors managed
    $11,200.00
    Plus
    Starting cost for 1-20 employees
    $17,000.00
    Customer Trust Management
    Starting cost for 1-20 employees
    $22,250.00
    Questionnaire Automation
    Starting cost for 1-20 employees
    $10,000.00

    Vendor refund policy

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Support

    Vendor support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Centralized Risk Management, Compliance and Auditing, Security
    Top
    10
    In Centralized Risk Management, Compliance and Auditing, Security
    Top
    25
    In IT Business Management, Monitoring

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Compliance Automation
    Automates evidence collection across 35+ security and compliance frameworks including SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR
    Cloud Service Integration
    Deep integrations with 40+ AWS services providing comprehensive cloud security and compliance visibility
    AI-Powered Security Management
    AI Agent provides intelligent task management, smart recommendations, and real-time audit documentation generation
    Custom Test Support
    Supports custom automated tests built directly in-platform or via API for self-hosted and custom-built systems
    Multi-Product Security Platform
    Offers comprehensive trust management solutions including compliance automation, third-party risk management, and trust center capabilities
    Compliance Framework Support
    Supports continuous monitoring and automation for over 20 compliance frameworks including SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR
    Cloud Service Integration
    Integrates with 45+ AWS services and leverages AWS Bedrock for AI-powered compliance monitoring
    Automated Security Control Monitoring
    Provides continuous automated monitoring with real-time alerts when security controls are not operating effectively
    Evidence Collection Mechanism
    Automatically collects compliance evidence to streamline audit processes and reduce manual documentation efforts
    Multi-System Application Connectivity
    Integrates with hundreds of applications and systems to enable comprehensive security and compliance tracking
    Compliance Framework Support
    Supports multiple global security and privacy compliance standards including SOC 2, ISO 27001, HIPAA, GDPR, CCPA, NIST frameworks, CMMC, and PCI DSS
    Cloud Service Integrations
    Provides over 100 automated integrations with cloud services like AWS, Azure, Google Cloud, G Suite, GitHub, Okta, and Slack for continuous evidence collection and infrastructure monitoring
    Machine Learning Questionnaire Processing
    Utilizes machine learning to automate RFP and security questionnaire completion by generating responses based on approved past answers
    Continuous Security Monitoring
    Performs automated tests, continuous infrastructure monitoring, and nonconformity detection across cloud environments
    Risk and Compliance Management
    Offers comprehensive risk management capabilities including personnel and asset inventory, vendor risk management, risk register, and enterprise policy management

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    No security profile
    No security profile

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    5
    2 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    100%
    0%
    0%
    0%
    0%
    2 AWS reviews
    |
    1975 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    Anas Rifai

    Has improved our compliance workflow and helped identify and fix security vulnerabilities

    Reviewed on Oct 15, 2025
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Vanta  is compliance in general, aiming for an ISO to be compliant with the standards.

    A specific example of how I use Vanta  for ISO compliance is that we have Vanta connected to our AWS  account and our Azure DevOps  repositories.

    Regarding my main use case for Vanta, we are using it to make sure our security posture is good. For example Vanta has picked up all the AWS  Inspector  for our ECR repos vulnerabilities, and we create tickets and hand them out to our team, trying to remediate these images one by one, which provides a very useful view of our weak points.

    What is most valuable?

    The best features Vanta offers include reasonable recommendations, a nice user experience, and everything being organized. The remediation guidance is very nice, so if I don't have a clue about that item, Vanta gives me a hint on what to do and what the subject of that resource is.

    Most of the time the recommendations are quite sufficient, which is great. Sometimes, if the task is a little bit complicated, it requires some extra research, but in general, it's good, especially for infrastructure as code. It even has solid examples on what to do.

    Vanta has positively impacted my organization by helping us remediate a lot of vulnerabilities and bad practices, especially from vulnerable ECR repos, and enforced good behavior. For example, we enforce reviews for our pull requests, which wasn't mandatory before and was on a per-repo basis. Now, this enforcement is uniform across the entire organization.

    After implementing those changes with Vanta, we tracked specific outcomes and metrics and improved compliance scores, which we can see in Vanta. We started out at around 17%, and we're now at over 80%. It's still a work in progress, but we've come a long way.

    What needs improvement?

    The only thing I wish for regarding the features is better RBAC. Permissions for platform users have been an issue. We've had to give admin access to Vanta for another team member to view all items. It would be great if the permissions of Vanta platform users had more verbosity to them, more dynamic.

    To improve Vanta, I think the refresh after remediation takes place could be controlled more. If it could be faster, that would be great.

    Besides the user permissions and the refreshing, which are improvements rather than issues, the rest looks fine. Vanta has been really nice, with a nice user experience, clear layout, and very reasonable recommendations compared to other platforms we've tried.

    For how long have I used the solution?

    I've been using Vanta for the past 10 months, starting in early January this year.

    What do I think about the stability of the solution?

    Vanta is very stable; we haven't had any downtimes or weird behavior so far, which we really appreciate.

    What do I think about the scalability of the solution?

    Regarding Vanta's scalability, our whole DevOps team and SRE teams have been onboarded, and it has been a smooth ride.

    How are customer service and support?

    I haven't interacted with customer support yet, as we haven't had any need to contact them so far. I'm sure they will be good.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    I previously used Azure Defender , which was a hideous solution with inconsistencies. Connectors would go down randomly, and some suggestions from Azure Defender  were very awful and unrealistic. We had a rough time with it; We've had a very nice time with Vanta so far compared to Azure Defender.

    What was our ROI?

    Besides achieving a better security posture and coming closer to ISO compliance, I have nothing else to share about return on investment.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing isn't in my domain to give a good answer.

    Which other solutions did I evaluate?

    Before choosing Vanta, our team lead evaluated other options, and I personally evaluated other options regarding security posture in general, mostly open-source ones.

    What other advice do I have?

    For others looking into using Vanta, I would say it's great, and if they're new to compliance, that's the perfect place to start. Start using Vanta, narrow down the scope, and take the items one by one to get one step closer to good compliance.

    I think Vanta is one of the good platforms out there. I'm glad we're using it. I'm comfortable with it, and so is my team.

    On a scale of 1-10, I rate Vanta a 9 out of 10.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Stella J.

    Efficient Log Access and Status View

    Reviewed on Oct 14, 2025
    Review provided by G2
    What do you like best about the product?
    It pulls logs and user info so I don’t have to ping five different people, and the status view helps me spot problem areas in seconds.
    What do you dislike about the product?
    A couple of legacy systems also needed manual evidence until we built small connectors.
    What problems is the product solving and how is that benefiting you?
    Vanta stopped audit prep being a frantic, last minute job missing items pop up early and many artifacts arrive automatically.
    Health, Wellness and Fitness

    Amazing product, amazing support, provides a complete end to end GRC solution

    Reviewed on Oct 12, 2025
    Review provided by G2
    What do you like best about the product?
    We’ve been using Vanta for a while now, and honestly, it’s been such a smooth experience. The platform is super easy to use, everything just makes sense, and it saves us so much time.

    The support team is incredible. Whenever we have a question, they’re quick to respond and genuinely helpful. Plus, our account manager has been amazing, really proactive and always checking in to make sure we’re getting the most out of the platform.

    What I love most is how comprehensive Vanta is. It truly feels like an end-to-end solution. It connects with nearly every tool we use, tracks compliance automatically, and works across pretty much any security framework. It takes so much of the stress out of staying compliant.

    Overall, Vanta has made the whole compliance process simple, efficient, and honestly enjoyable, which I never thought I’d say about compliance!
    What do you dislike about the product?
    If I had to pick something I dislike about Vanta, its a little pricey for smaller teams, and some of the customization options are limited if you have really specific processes. That said, once everything’s up and running, it works seamlessly and more than makes up for those small challenges.
    What problems is the product solving and how is that benefiting you?
    Vanta helps us track our SOC 2 and HIPAA compliance all in one place. It makes it so much easier to manage everything, from policies and documentation to controls and compliance tasks. Instead of juggling multiple tools or spreadsheets, Vanta brings everything together in a single platform, so we always have a clear view of where we stand. It really streamlines the entire compliance process and keeps us audit-ready without all the manual effort.
    Aurora G.

    Simplifies audits under control

    Reviewed on Oct 09, 2025
    Review provided by G2
    What do you like best about the product?
    Vanta connects to our cloud and identity systems and pulls evidence into one place, so I don’t have to hunt for screenshots and logs.
    What do you dislike about the product?
    A few older systems didn’t integrate cleanly at first and required manual proof during setup.
    What problems is the product solving and how is that benefiting you?
    Vanta turns audit prep from a frantic scramble into routine work by continuously checking controls and automatically collecting artifacts.
    Sophia H.

    My Honest Vanta Review

    Reviewed on Oct 08, 2025
    Review provided by G2
    What do you like best about the product?
    Vanta connects to our cloud and identity tools and starts collecting access logs and config snapshots automatically, so I don’t have to hunt for evidence across services. The dashboard shows which cloud controls are healthy and which need attention, which makes it quick to prioritize fixes.
    What do you dislike about the product?
    The platform can be picky about how documents and policies are uploaded sometimes I need to reformat files or follow a specific template before Vanta accepts them.
    What problems is the product solving and how is that benefiting you?
    Vanta turns audit prep from a frantic scramble into steady work by continuously checking controls and automatically gathering evidence. Missing items surface early on the dashboard, which saved my team many hours during SOC 2 preparation and keeps our cloud posture visible day to day.
    View all reviews