We're trying to get SOC 2 compliance, and we're trying to get HIPAA compliance.
Vanta
VantaExternal reviews
External reviews are not included in the AWS star rating for the product.
Helping you attain AND retain compliance easily
As we onboard new employees Vanta is constantly alerting me of the steps needed to maintain our compliance so I spend many days checking into Vanta to sure we do not fall behind. The number of integrations are vast as well.
Customer Support is always helpful as well and have been extremely responsive.
They do not have all the integrations we require yet but they are slowly adding continuously.
One stop shop for Compliance
Helpful tool for navigating complex requirements
Clean, simple and complete
good job with vanta
Best security & compliance tool on the market
Streamlined compliance with API integrations for real-time monitoring
What is our primary use case?
How has it helped my organization?
We haven't seen any problem with that yet. That said, our company is a tiny 20-person company right now. We're probably six months ahead of where we should be in terms of doing compliance anyhow. We're not really at the critical masses yet, but we're trying to get a head start on it.
What is most valuable?
The fact it does the real-time integration with the APIs into our hosting service, which is AWS, can at times be painful - yet it's very effective. We get working pretty easily. They integrate into New Relic as a performance monitoring tool.
When there's a control in Vanta that says, 'I want to know if you are doing performance monitoring on a certain web server,' it goes and knows how to talk to New Relic and grab that information and make it part of your Vanta Viewport.
What needs improvement?
Every product has a lot of areas to improve. They have an AI generator for the system description for SOC 2, for example, however, the outline is a little sketchy. The system description has to have a little more insight or context about your business and why you're different. A true auditor will look at that closely. A lot of it is a little bit too automated and not really realistic. One area that they tout as being a real-time savings, we haven't found that to be a time savings yet.
For how long have I used the solution?
I've been using Vanta for about a year and a half.
What do I think about the stability of the solution?
I haven't seen a fail yet. But I am only using the tool about ten hours a week, and I'm a contractor as well, so I'm not working at this every day. But every time I seem to need it, it works.
What do I think about the scalability of the solution?
We haven't seen any problem with that yet. Our company is a tiny twenty-person company right now. We're probably six months ahead of where we should be in terms of doing compliance anyhow. We're not really at the critical masses yet, but we're trying to get a head start on it.
How are customer service and support?
I've had experience with both tech support as well as with their customer success. They're interchangeable at some point, at least for our size business. I would give them at least eight out of ten. They've been responsive, which is the most important thing. They seem to come back, and they give you good answers, and they give you good options to pursue what you're trying to do.
How would you rate customer service and support?
Positive
How was the initial setup?
It's a fairly large learning curve to get going. Not impossibly so. Once you get familiar with the system and where things are located, then you can work around it reasonably well. It's more tolerant as you get to know the product a little more. Initially, they're not very clear about the differences between the need for evidence, so-called evidence, and what would be automated.
What was our ROI?
We're just not at scale to even evaluate that. And even if you could, it's hard to evaluate something like, okay, this company is running in a compliant way versus they're cutting corners. It's hard to attach a value to that.
What's my experience with pricing, setup cost, and licensing?
Seems reasonable. We just renewed. I don't have a lot of experience in this space, but this is the first generation of automation products for purposes of compliance. There are a group of different companies out there, like Drata. They all seem to be similarly priced.
What other advice do I have?
They've done a good job, actually. I can't tell if they're a leader or not. All I know is that it gets us that seems to be constructive right now. We're not investing that much money.
I'd rate the solution eight out of ten.