Vanta
VantaExternal reviews
2,108 reviews
from
and
External reviews are not included in the AWS star rating for the product.
Excellent Compliance Resources, No Downsides
What do you like best about the product?
the resources to help me achieve compliance
What do you dislike about the product?
i do not find anything to dislike about it
What problems is the product solving and how is that benefiting you?
i am using it for business purposes
Effortless Security Compliance Management with Vanta
What do you like best about the product?
I absolutely appreciate how Vanta aligns perfectly with the compliance frameworks like SOC 2 Type 2 and ISO 27001, which are crucial for us. The automation feature, especially in the trust center and security questionnaire, is incredibly beneficial as it lays out security controls in simple terms and helps with monitoring and managing them efficiently. Setting up Vanta was a breeze with the easy integration of various tools. I also love that it saves us significant engineering time by offloading many manual tasks, allowing our team to focus more on sales. The comprehensive alerts and internal controls keep us on track with compliance efforts, and I find the updates to the security questionnaires making our processes much faster. In case I moved to a company without a compliance tool, choosing Vanta again would be a no-brainer due to the time-saving and streamlined operations it offers. Overall, Vanta is integral in distributing security responsibilities effectively across our team, providing a much more informed approach towards compliance.
What do you dislike about the product?
I find the current capability insufficient for handling web portal questionnaires directly, and I believe it would be beneficial if Vanta's AI could continuously refine our knowledge base and keep our trust center up-to-date.
What problems is the product solving and how is that benefiting you?
I find Vanta streamlines our compliance processes, distributing security responsibility, informing our team, and saving significant engineering time compared to manual methods.
Compliance on autopilot, great integrations but not cheap
What do you like best about the product?
Easy to setup. Very useful integrations. Give a roadmap/guide to get certified in ISO27001. Covers a lot of bases that we would need other products for.
What do you dislike about the product?
Cost is high, some features still behind higher plans. Would like task tracking more directly embedded.
What problems is the product solving and how is that benefiting you?
Achieving and maintaining ISO270001 compliance. General improvement of security posture.
Effortless Process Implementation Made Simple
What do you like best about the product?
Easy to make implement all the process. While developing the SOC2 certification all the process was straight forward
What do you dislike about the product?
There are quite a few warnings, but these are connected to the SOC2 certifications.
What problems is the product solving and how is that benefiting you?
Vanta made achieving the SOC2 Type 2 certification straightforward by assisting in the creation of various controls. From there, it was easy to request and upload all the necessary documents, which helped streamline the entire compliance process.
Simplifies Compliance, But Needs More Integrations
What do you like best about the product?
The abstraction from the complexity of the audit compliance
What do you dislike about the product?
Not integrated with enough business tools
What problems is the product solving and how is that benefiting you?
Compliance with SOC 2, it eases the processes and ensuring compliance on many areas.
User-Friendly and Compliant, But Key Features Locked Behind Paywall
What do you like best about the product?
SO easy, convinient, compliant and user friendly, Ease of Implementation Customer Support
What do you dislike about the product?
Some features like cutom roles and permissions should not be in the plus packages and should include in the core package.
What problems is the product solving and how is that benefiting you?
Vanta has made GRC easy and quick
Effortless Policy Management, Needs More Integrations
What do you like best about the product?
Vant is very easy to use, you can subscribe to the modules/frameworks that are applicable to your organization and be able to organize, sort, filter by those. The way it easily allows for building up your policies and documents makes things easy to manage
What do you dislike about the product?
Could offer more integrations for things like compliance training or offer this themselves.
What problems is the product solving and how is that benefiting you?
Managing our entire risk management and compliance story.
Comprehensive and Collaborative, But Task Overlap Can Be Confusing
What do you like best about the product?
Comprehensive, great layout and supporting in product guidance to ensure we resolve any issues/tasks at hand in the best way possible. It' s also easy to collaborate on. We use it almost on a daily basis as we received notifications and alerts. It has been easy to implement some of the feaures and roll it out to the org. Customer support has been great and we have a dedicated CSM that has supported us thrughout our journey.
What do you dislike about the product?
Sometimes confusing as many of the tasks form part of other lists, reports, charts, alerts and they are intertwined but in a confusing way.
What problems is the product solving and how is that benefiting you?
Before Vanta, ensuring ongoing SOC 2 compliance at Josef required manual tracking across multiple systems — cloud infrastructure, HR tools, access management, vulnerability management, and evidence collection. This created risks around:
Missed control evidence (e.g. proof of access reviews or change management processes)
Lack of real-time visibility into security posture
Time-consuming audits due to fragmented evidence and ad-hoc screenshots
Limited accountability across engineering and operations teams
Vanta centralises all of this by automatically monitoring controls and integrations (Google Workspace, AWS, Slack, GitHub, ClickUp, etc.), surfacing exceptions, and maintaining continuous audit readiness.
💡 How That Benefits Josef
Continuous compliance and audit readiness
Vanta automatically pulls and updates evidence daily, ensuring our SOC 2 controls remain in place year-round. This has removed the “scramble” before audit periods and simplified the annual audit cycle with Johanson Group.
Reduced manual workload
Instead of maintaining spreadsheets and screenshots, Vanta automatically checks controls like employee onboarding/offboarding, MFA enforcement, and change management. Our compliance and engineering teams can now focus on remediations, not evidence gathering.
Improved visibility and accountability
Dashboards show real-time compliance health across control families, which helps track ownership and identify gaps (e.g., missing device encryption, overdue risk assessments). It’s become the single source of truth for our audit posture.
Integrated risk and vulnerability tracking
With integrations to ClickUp and vulnerability management tools (like our Vanta Zap to auto-create tickets when new vulns are detected), we’ve automated follow-up on risk items and can demonstrate a complete remediation workflow.
Streamlined communication with auditors
During audits, most evidence can be shared directly from Vanta — audit requests are mapped to controls with attached evidence, reducing back-and-forth and cutting audit prep time significantly.
Missed control evidence (e.g. proof of access reviews or change management processes)
Lack of real-time visibility into security posture
Time-consuming audits due to fragmented evidence and ad-hoc screenshots
Limited accountability across engineering and operations teams
Vanta centralises all of this by automatically monitoring controls and integrations (Google Workspace, AWS, Slack, GitHub, ClickUp, etc.), surfacing exceptions, and maintaining continuous audit readiness.
💡 How That Benefits Josef
Continuous compliance and audit readiness
Vanta automatically pulls and updates evidence daily, ensuring our SOC 2 controls remain in place year-round. This has removed the “scramble” before audit periods and simplified the annual audit cycle with Johanson Group.
Reduced manual workload
Instead of maintaining spreadsheets and screenshots, Vanta automatically checks controls like employee onboarding/offboarding, MFA enforcement, and change management. Our compliance and engineering teams can now focus on remediations, not evidence gathering.
Improved visibility and accountability
Dashboards show real-time compliance health across control families, which helps track ownership and identify gaps (e.g., missing device encryption, overdue risk assessments). It’s become the single source of truth for our audit posture.
Integrated risk and vulnerability tracking
With integrations to ClickUp and vulnerability management tools (like our Vanta Zap to auto-create tickets when new vulns are detected), we’ve automated follow-up on risk items and can demonstrate a complete remediation workflow.
Streamlined communication with auditors
During audits, most evidence can be shared directly from Vanta — audit requests are mapped to controls with attached evidence, reducing back-and-forth and cutting audit prep time significantly.
Great AI and Automation, But Takes Time to Learn
What do you like best about the product?
The AI features, the UI is nice. I like the automation it provides.
What do you dislike about the product?
It can be clunky to figure out how to use.
What problems is the product solving and how is that benefiting you?
Speeds up review times during the sales cycles by providing the AI feature for the security questionnaires as well as a Trust Center to make it quicker and more accessible to customers. Some customers don't even send us a questionnaire because they can get the assurance level they need by using the Trust Center only.
Great for Onboarding, Offboarding Could Be More Flexible
What do you like best about the product?
The policies that are already built out in the system
What do you dislike about the product?
Offboarding an employee can be a little difficult because you have to wait for systems to talk to each other. it would be better if you could offboard someone manually as part of our termination checklist
What problems is the product solving and how is that benefiting you?
Vanta is helping us pass security audit tests from other companies because the policies are already built in and we can easily point to them when documents are being requested.
showing 81 - 90