External reviews
External reviews are not included in the AWS star rating for the product.
Vanta is the best compliance enterprise-ready service
What do you like best about the product?
Tight integration with AWS/GCP/Heroku, Slack, Datadog, and Linear.
What do you dislike about the product?
Lots of fields to fill out, but that's generally how compliance works.
What problems is the product solving and how is that benefiting you?
We are getting SOC-2 compliance and they are accelerating the pace we can do it as a small team.
- Leave a Comment |
- Mark review as helpful
Vanta made SOC 2 painless
What do you like best about the product?
Vanta makes the SOC 2 audit process way more manageable and makes it possible for us to continually monitor our compliance.
What do you dislike about the product?
You still need to work with an auditor, but Vanta is able to put you in touch with several high quality auditors.
What problems is the product solving and how is that benefiting you?
We needed SOC 2 - Vanta helped us achieve this.
Excellent product and service
What do you like best about the product?
Ease of use, customer success person assigned to us.
What do you dislike about the product?
Not much really, if I was nitpicky, some quality-of-life features are missing, like bulk-update of items.
What problems is the product solving and how is that benefiting you?
SOC2 audit.
Helpful and friendly staff boost the journey to a SOC 2
What do you like best about the product?
Vanta's platform picks up the correct information and provides a helpful front view of the company's compliance effort. It also covers a lot of the nooks and crannies of compliance -- things like tracking and rolling out policies, inventory etc.
What do you dislike about the product?
Vanta has built out most of its compliance-related workflow features, but some specifically are still in baby steps. For example, vulnerability management -- Vanta will pull the right list of Docker container vulnerabilities, but won't sync it up to GitHub Issues. I'm really looking forward to seeing more integrations and pulling data together, so I could rely on Vanta as the only place I check for compliance.
What problems is the product solving and how is that benefiting you?
Qminder is using Vanta as a SOC 2 speed-boost tool, to get most of the evidence collection handled with Vanta. We've also partnered with an auditor company who Vanta connected to us, which helps our company spend less time on evidence management and negotiations - and more time on the product.
Recommendations to others considering the product:
For small businesses considering Vanta for your first SOC 2 report - get ready to implement a lot of new policies. You should have the OK from higher-ups right from the start, as the speed of implementing these policies will mean faster rollout & employee approval!
Makes security compliance attainable for small and medium companies.
What do you like best about the product?
One of the most immediately impactful features centers around Vanta's excellent Integrations which automate a massive amount of otherwise manual labor. Vanta has always had highly responsive customer support for issues and feature requests. Throughout our time using this platform Vanta has shipped many time-saving feature updates and releases. These are great and keep the platform delivering on that primary goal of ensuring compliance while adding efficiency and reliability. The regular and actionable email alerts allow our administrators to stay on top of any security gaps or updates with the information needed for follow-up.
The onboarding tools make it especially easy to get new employees or contractors set up and tracked in a way that aligns with company policy while being simple and streamlined for the user.
Vanta has two external agent applications that can be used to support security and compliance efforts. The Vanta Agent for individual workstations has proven to be very stable and easy to work with. The same can be said about the server agent.
The onboarding tools make it especially easy to get new employees or contractors set up and tracked in a way that aligns with company policy while being simple and streamlined for the user.
Vanta has two external agent applications that can be used to support security and compliance efforts. The Vanta Agent for individual workstations has proven to be very stable and easy to work with. The same can be said about the server agent.
What do you dislike about the product?
I have nothing to dislike. Vanta continues to overdeliver for us.
What problems is the product solving and how is that benefiting you?
Like anyone dealing with Security and Compliance, a significant amount of time is often spent doing work that Vanta automates away and makes low or no effort. In a small company or startup environment, that level of effort can be a major obstacle to a strong security posture and eventually obtaining a certification. Vanta saves what would require whole FTE's worth of work with stronger more reliable results. Vanta also connected us with vetted vendors who could support the auditing and certification process.
Recommendations to others considering the product:
This is an excellent solution for a startup or small business looking to implement an InfoSec Program from scratch or to replace an existing manual labor based program.
Really happy customer
What do you like best about the product?
How easy is it to check the status in real-time and stay updated with the progress of our changes in the infrastructure.
What do you dislike about the product?
All are perfect. We don't have any issues and we're happy with all the features.
What problems is the product solving and how is that benefiting you?
SOC 2 Type 2 compliences.
Using Vanta to prepare a SaaS company for a SOC 2 audit
What do you like best about the product?
This is an updated review now that my company has been using Vanta for about two years. We have successfully gone through two SOC 2 type II audits. Vanta clearly understands the pain points SaaS companies face with regards to preparing a company to live by the standards required by SOC 2 controls. The combination of their technology and people has been instrumental in making us successful with compliance. Given our success in using Vanta with SOC 2 we decided to use Vanta to manage CCPA and GDPR compliance as well.
Vanta has continued to make steady improvements to the product since we signed up as well. Whereas the Risk Management component was very limited when we first signed on, it is now quite robust and does an excellent job of walking you through the creation of a Risk Register, creating remediation tasks, etc.
One of the most useful additions is the Vanta Trust Report. The Trust Report is a web page where we can send customers and potential customers to see our compliance status and download documents that are necessary for a security review. This has saved us a lot of time when potential customers are gathering information for a security review.
Vanta has continued to make steady improvements to the product since we signed up as well. Whereas the Risk Management component was very limited when we first signed on, it is now quite robust and does an excellent job of walking you through the creation of a Risk Register, creating remediation tasks, etc.
One of the most useful additions is the Vanta Trust Report. The Trust Report is a web page where we can send customers and potential customers to see our compliance status and download documents that are necessary for a security review. This has saved us a lot of time when potential customers are gathering information for a security review.
What do you dislike about the product?
In my original review there were still a number of rough edges in the product. I'm happy to report that those have all been resolved. The interface makes it easy to find the information I need without being overly complicated.
What problems is the product solving and how is that benefiting you?
Preparing policies, assessing risk, monitoring systems, collecting evidence, and otherwise implementing what is needed for our company to be SOC compliant.
Great product and service
What do you like best about the product?
The optimized path and communication to getting the SOC 2 Type 2 was incredible.The sales and onboarding process was informational and consistent with positivity and guidance throughout.
What do you dislike about the product?
I have no improvement suggestions. Easy suggestion is more integrations, however all the ones needed were there for us.
What problems is the product solving and how is that benefiting you?
Soc 2 Type 2 and HIPAA. Benefits were a designed process to not waste time and money on resources that were superfluous to the main goal.
We closed deals because of Vanta. It's that simple.
What do you like best about the product?
Vanta covers nearly everything for SOC2.
What do you dislike about the product?
The risk assessment area could use more instruction.
What problems is the product solving and how is that benefiting you?
Demonstrating adequate security measures in our company. We increased our security to get SOC2 compliant. As promised, the IT assessment performed by our prospects/customers has gone much much better and smoother with Vanta's help.
Recommendations to others considering the product:
Exactly the type of system that we needed to demonstrate SOC2 compliance and manage the process on an ongoing basis.
Vanta review
What do you like best about the product?
A Framework and a focal point to manage all of the SOC2 requirements.
Automation of both the Server-side and the endpoint side
Automation of both the Server-side and the endpoint side
What do you dislike about the product?
Lack of the ability to define certification scope in the system.
I would like to be able to include all of my entities & my server environments in order to improve security, but I am limited to do it just for these in the certification scope.
( I am not the hands-on user)
I would like to be able to include all of my entities & my server environments in order to improve security, but I am limited to do it just for these in the certification scope.
( I am not the hands-on user)
What problems is the product solving and how is that benefiting you?
Advancing towards SOC2 with a Virtual CISO and only a partially dedicated in house person
showing 681 - 690