Listing Thumbnail

    Vanta

     Info
    Sold by: Vanta 
    Deployed on AWS
    Vendor Insights
    Vanta helps thousands of fast-growing companies simplify and centralize compliance and security workflows so they can build trust.

    Overview

    Play video

    Whether you're just starting out or scaling a mature security program, demonstrating strong security practices and building trust with buyers has never been more critical.

    Vanta's Trust Management Platform helps over 6,000 AWS customers, including Atlassian, Modern Health, and Mistral AI, automate compliance, improve visibility, and reduce manual work. Security, GRC, and IT teams use Vanta to:

    • Automate evidence collection across 35+ frameworks, including SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR
    • Centralize GRC workflows like risk and vendor management
    • Complete security reviews up to 5x faster

    Now, with the Vanta AI Agent, teams can unlock a new level of efficiency. Acting like an intelligent teammate, the AI Agent helps manage tasks, recommend next steps, and generate audit-ready documentation, enabling teams to work faster, stay organized, and be more proactive in maintaining trust.

    Vanta customers report a 526% ROI over three years, with most seeing payback in just three months. On average, Vanta boosts compliance team productivity by 129%, helping teams do more with less.

    For more complex environments, Vanta supports custom automated tests, built directly in-platform or via the Vanta API, ideal for self-hosted and custom-built systems.

    As the only multi-product vendor in the Trust Management space, Vanta offers not only core compliance automation but also AI-powered solutions across Third Party Risk Management, Trust Center, and now, the Vanta AI Agent, which brings intelligent guidance and automation to every layer of your security.

    Pricing is tiered based on company size and program complexity. Preview pricing for 1-20 employees and more at: vanta.com/pricing. Interested in a private offer via AWS Marketplace? Email awsmarketplace@vanta.com 

    Highlights

    • Built for AWS - not just compatible: As an AWS Security Competency Partner with deep integrations across 40+ AWS services, Vanta gives you full visibility into your cloud security and compliance, and is purpose-built for AWS-native environments.
    • Automated and scalable compliance: Continuously monitor your AWS environment to meet frameworks like SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR. Vanta automates evidence collection and policy management to reduce manual effort and audit prep time.
    • Security posture, strengthened by AI: Leverage the Vanta AI Agent for intelligent task management, smart recommendations, and real-time responses to audit needs. Combined with features like real-time audit trails, centralized access reviews, and AI-powered Vendor Risk Management, Vanta helps you stay secure and audit-ready all year round.

    Details

    Sold by

    Delivery method

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (2)

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (9)

     Info
    Dimension
    Description
    Cost/12 months
    AWS FTR
    AWS FTR Module
    $7,500.00
    Core Package
    Starting cost for 1-20 employees
    $12,000.00
    Growth Package
    Starting cost for 1-20 employees
    $22,675.00
    Scale Package
    Starting cost for 1-20 employees
    $48,970.00
    Trust Center
    Starting cost for 1-20 employees
    $6,000.00
    Vendor Risk Management
    Up to 50 vendors managed
    $11,200.00
    Plus
    Starting cost for 1-20 employees
    $17,000.00
    Customer Trust Management
    Starting cost for 1-20 employees
    $22,250.00
    Questionnaire Automation
    Starting cost for 1-20 employees
    $10,000.00

    Vendor refund policy

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Support

    Vendor support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Centralized Risk Management, Compliance and Auditing, Security
    Top
    10
    In Centralized Risk Management, Compliance and Auditing, Security
    Top
    25
    In IT Business Management, Monitoring

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Compliance Automation
    Automates evidence collection across 35+ security and compliance frameworks including SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR
    Cloud Service Integration
    Deep integrations with 40+ AWS services providing comprehensive cloud security and compliance visibility
    AI-Powered Security Management
    AI Agent provides intelligent task management, smart recommendations, and real-time audit documentation generation
    Custom Test Support
    Supports custom automated tests built directly in-platform or via API for self-hosted and custom-built systems
    Multi-Product Security Platform
    Offers comprehensive trust management solutions including compliance automation, third-party risk management, and trust center capabilities
    Compliance Framework Support
    Supports continuous monitoring and automation for over 20 compliance frameworks including SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR
    Cloud Service Integration
    Integrates with 45+ AWS services and leverages AWS Bedrock for AI-powered compliance monitoring
    Automated Security Control Monitoring
    Provides continuous automated monitoring with real-time alerts when security controls are not operating effectively
    Evidence Collection Mechanism
    Automatically collects compliance evidence to streamline audit processes and reduce manual documentation efforts
    Multi-System Application Connectivity
    Integrates with hundreds of applications and systems to enable comprehensive security and compliance tracking
    Compliance Framework Support
    Supports multiple global security and privacy compliance standards including SOC 2, ISO 27001, HIPAA, GDPR, CCPA, NIST frameworks, CMMC, and PCI DSS
    Cloud Service Integrations
    Provides over 100 automated integrations with cloud services like AWS, Azure, Google Cloud, G Suite, GitHub, Okta, and Slack for continuous evidence collection and infrastructure monitoring
    Machine Learning Questionnaire Processing
    Utilizes machine learning to automate RFP and security questionnaire completion by generating responses based on approved past answers
    Continuous Security Monitoring
    Performs automated tests, continuous infrastructure monitoring, and nonconformity detection across cloud environments
    Risk and Compliance Management
    Offers comprehensive risk management capabilities including personnel and asset inventory, vendor risk management, risk register, and enterprise policy management

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    No security profile
    No security profile

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    5
    2 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    100%
    0%
    0%
    0%
    0%
    2 AWS reviews
    |
    2101 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    Computer Software

    Simple Interface, But Needs More Detailed Error Info

    Reviewed on Oct 27, 2025
    Review provided by G2
    What do you like best about the product?
    The simple interface that provides easy access into what I need to take care of.
    What do you dislike about the product?
    Some of the items that need to be fixed tend to have shorter solutions than others. It would be nice if there were more details on certain failed items.
    What problems is the product solving and how is that benefiting you?
    Vanta is helping our company work through the SOC 2 compliance.
    Shane F.

    Seamless Integrations and Support, Access Reviews Still Improving

    Reviewed on Oct 27, 2025
    Review provided by G2
    What do you like best about the product?
    Seamless integrations, easy to setup, great communication with our account team!
    What do you dislike about the product?
    non-integrated access reviews aren't fully refined or useful just yet. But they are working on it!
    What problems is the product solving and how is that benefiting you?
    Our Governance and Compliance team needed a better solution than Drata that has more features and a better price point.
    Matt S.

    Very happy with the tool, would recommend

    Reviewed on Oct 27, 2025
    Review provided by G2
    What do you like best about the product?
    Vanta's software has significantly streamlined our ISO audit process. The platform allows us to map controls directly to certification requirements, and its process management tools enable us to assign work or evidence-gathering tasks directly to the relevant controls and service owners. This setup also provides comprehensive tracking for the steering committee, making oversight much easier.

    Recently, I reached out to Vanta's customer support for assistance with an access review question. My support agent, Paige, was outstanding—she created a video with a screen recording that clearly demonstrated all the possible solutions within my account, which made it very straightforward to identify and resolve the issue.

    I'm very satisfied with both the software and the support team, and I would recommend Vanta to others.
    What do you dislike about the product?
    It has taken me some time to get familiar with how the different tools in Vanta are arranged in the navigation. I would really appreciate a feature that makes it easier to jump to my most recently visited or bookmarked pages within the tool.
    What problems is the product solving and how is that benefiting you?
    Managing our evidence gather processes for compliance audits, Access and vendor security reviews as well as mandatory staff training programs
    Jhon Lexter P.

    Streamlined Vulnerability Management with Powerful Integrations Make Compliance a Breeze

    Reviewed on Oct 27, 2025
    Review provided by G2
    What do you like best about the product?
    Vanta has truly transformed how we handle security and compliance workflows. The platform excels at making vulnerability management both easy and convenient—something that's rare in the compliance space. What I appreciate most is the intuitive way it allows us to manage and resolve security and compliance action items without the usual headaches.

    The standout feature for me is the Linear integration. Being able to seamlessly convert vulnerabilities and security callouts into actionable tasks for our engineering team has been a game-changer. It bridges the gap between security/compliance teams and engineering, ensuring nothing falls through the cracks. Instead of manually tracking items in spreadsheets or bouncing between platforms, we can create tasks directly in Linear, which our engineers are already using daily. This integration alone has significantly improved our response time and accountability.
    What do you dislike about the product?
    While Vanta is excellent overall, there's definitely room for improvement in how it handles scan management. My main frustration is the lack of an easy way to deactivate scans that aren't relevant to our specific environment. When certain scans become repetitive or don't apply to our infrastructure, it would be incredibly helpful to have a more granular way to turn them off.

    Additionally, I wish there was better memory functionality for deactivated action items. Currently, when you deactivate something, your options are limited—you can either deactivate it indefinitely or deal with it repeatedly. What would be ideal is a middle ground: an option for Vanta to "remember" that we've reviewed and dismissed certain items, without having to make permanent deactivation decisions. This would reduce noise and help us focus on genuinely relevant security issues.
    What problems is the product solving and how is that benefiting you?
    As a startup with limited human resources where everyone wears multiple hats, Vanta has been essential in making compliance manageable without requiring a dedicated full-time team. The platform solves several critical challenges that are particularly acute for small, growing companies:

    Centralized Policy Access
    Vanta provides a single source of truth for all our security and compliance policies. Instead of hunting through shared drives or outdated wikis, every team member—whether they're in engineering, sales, or operations—can instantly access the policies they need. This is invaluable when you don't have a compliance department and everyone needs to be self-sufficient.

    Streamlined Training Management
    The platform makes security training accessible and trackable for our entire team. Employees can review training materials on their own schedule, and I don't have to chase people down or manually track completion. For a small team juggling competing priorities, this automation is a lifesaver.

    Administrative Efficiency
    From the administrator perspective, Vanta gives me easy oversight of all compliance tasks and monitoring without drowning in spreadsheets or manual processes. I can quickly see what needs attention, who's responsible, and what's been completed—all in one dashboard. This is critical when compliance is just one of many responsibilities on my plate.

    Reduced Compliance Burden
    Ultimately, Vanta transforms compliance from a resource-intensive burden into a manageable, sustainable process. Instead of needing specialists or consultants, our lean team can maintain our security posture and compliance certifications while still focusing on building our product and growing the business. For a startup, this efficiency directly translates to cost savings and faster time-to-market for compliance-dependent deals.
    Marketing and Advertising

    Streamlined Audits and Integrations, But Needs Better Evidence Management

    Reviewed on Oct 27, 2025
    Review provided by G2
    What do you like best about the product?
    Streamlined audits, evidence uploads, integrations, and implementation.
    What do you dislike about the product?
    Lack of evidence reference labels. For example, labeling the "Password Configuration" control PW-1 or something similar will provide an easy way to reference which control we need employees to handle.
    What problems is the product solving and how is that benefiting you?
    Audit, vendor, and compliance management. Audit readiness.
    View all reviews