
Initial Setup and Integration:
Pre-built Integrations: Vanta offers pre-built integrations with various tools and systems that businesses rely on. This helps in quickly setting up the platform to monitor and secure these tools.
Vanta API: For more customized needs, businesses can use the Vanta API to ensure a comprehensive view of their key risk surfaces, including employees, assets, and vendors.
Real-time Monitoring:
Hourly Tests: Vanta performs hourly tests to monitor the state of your security posture in real-time. This ensures that any issues are detected promptly.
Alerts and Task-Tracker Integrations: When something looks off, Vanta sends alerts and integrates with task trackers to help users stay on top of fixes.
Holistic Risk Visibility:
Single View of Risk Surfaces: Vanta provides a single view across key risk surfaces, helping businesses understand and manage their security risks comprehensively.
Audit Preparation and Execution:
Seamless Audit Process: Vanta simplifies the audit process by enabling auditors to complete audits entirely within the platform. This reduces the time spent on back-and-forth communications and documentation.
Compliance Program Building:
Custom Frameworks:
Vanta allowsbusinesses tocreate customframeworks tosupport any usecase, whetherit's a less commonframework requiredby a customeror an internalcompliance initiative.
Customframeworks canbe managed andevidenced withinVanta, and userscan map customor Vanta-managed controlsand automatedtests to requirementswithin theircustom framework.
Custom Controls:
Businessescan add customcontrols andnotes for bettercollaborationand understandingamong teams.
Vanta supportsbulk import ofcustom controls, making it easierto manage andcustomize complianceefforts.
Policies:
Users can createcustom policies, including underlyingstandards andprocedures, ifthey prefer notto use Vanta’s securitypolicy templates. Vanta will automaticallycreate policytests to monitorand ensure compliance.
Evidence/Documents:
Vanta automates much of theevidence gatheringbut also allowsfor the additionof custom evidencefor non-technical requirements. Custom evidencecan be linkedto relevant controls.
Risk Management:
Vanta offerscustomizationin risk management, allowing businessesto add theirown risk scenarios, customize attributes, risk scoringdimensions, andscore groups. Custom fieldscan also be addedto the risk register.
Access Reviewsand Vendor RiskManagement:
Vanta providestools for automating access reviewsand vendor riskmanagement, includingcustomizablerisk rubrics forvendor assessments.
Integrations andAPIs:
Vanta supportsover 150 pre-built integrationsand offers anAPI for advancedorganizationsto automate workflowsand create externalreports.
Employee Management:
Customchecklists foremployee onboarding, ongoing, andoffboarding taskscan be createdbased on departmentor group, ensuringrelevant processesare followed.
Security QuestionnaireResponse:
Vanta usesAI-powered automationto build a libraryof high-confidence Q&A pairs for securityquestionnaires, tailored tothe company’s specificpolicies andprior responses.
Public Demonstration of Securityand Compliance:
Security andPrivacy TrainingLibrary:
Vanta providesa library oftraining modulesfor SecurityAwareness, HIPAA, GDPR, CCPA/CPRA, andPCI DSS, developedby in-house experts. These modulesare designedto be engaging, memorable, andrelevant.
Automated TrainingManagement:
The platformallows for theautomation oftraining assignments, tracking, andfollow-up, ensuringemployees completerequired training.
Customer Support:
Vanta offersa full supportteam of customersuccess managers, compliance experts, and technicalsupport to assistwith implementation, configuration, and troubleshooting.
Guided Implementation:
The platformguides usersthrough the implementationprocess withprompts for addingadmins, integratingsystems, runningtests, and creatingpolicies. Thisis supplementedby expert support.
Continuous Updatesand Improvements:
Encryption:
Vanta uses TLS 1.2 or higher for data transmission over potentially insecure networks, ensuring that data is encrypted during transit.
Portable and removable media devices are encrypted when used, and there is an approved Cryptography Policy in place.
Access Controls:
Multi-factor authentication (MFA) is enforced for remote access to production systems, including AWS accounts and GitHub accounts.
User access to in-scope system components is based on job roles and functions, with documented access request forms and manager approvals required prior to provisioning access.
Continuous Monitoring and Vulnerability Management:
Vanta provides continuous monitoring capabilities to detect and mitigate vulnerabilities in real-time.
Regular vulnerability scanning and penetration testing are conducted to identify and address security weaknesses.
Data Protection and Privacy:
Vanta complies with various data protection regulations, including GDPR, HIPAA, and CCPA, ensuring that data privacy rights are maintained.
Data pseudonymization and encryption are implemented as needed to protect sensitive information.
Incident Response and Risk Management:
Vanta has a comprehensive incident management process to respond to security incidents promptly and effectively.
Enhanced risk management capabilities allow for the identification, assessment, and mitigation of risks, including third-party vendor risks.
Employee Training and Policies:
Vanta provides a security and privacy training library to ensure employees are aware of and adhere to security best practices and compliance requirements.
Monthly Updates:
Vanta typically releases product updates on a monthly basis, introducing new features, integrations, and improvements to the platform.
Update Management:
Updates are managed through a combination of automated processes and user notifications. For example, users can update their Vanta software via wireless LAN and cloud connections or USB storage, with detailed instructions provided for each method.
Data Ownership:
Customers retain ownership of their data. Vanta acts as a processor of service data, while the customer is the controller.
Vanta may use aggregated or de-identified data for business purposes, but this data is no longer associated with identifiable individuals.
Data Portability:
Vanta provides mechanisms for customers to access and export their data. The Vanta API allows users to securely access their account data, enabling the creation of custom dashboards, reports, or notifications outside of Vanta.
Pricing Based on Headcount and Frameworks:
Vanta's pricing structure is based on the number of security frameworks and the headcount of the organization. This means that as an organization grows or shrinks, the pricing can be adjusted accordingly to reflect the new headcount and compliance needs.
Custom Frameworks and Integrations:
Vanta supports a wide range of compliance frameworks and can add new ones as needed. This flexibility allows organizations to scale their compliance efforts without being limited by the platform's existing capabilities. The platform's ability to support custom frameworks and integrations ensures that it can adapt to the specific needs of growing or changing businesses.
Automated Processes:
Vanta automates up to 90% of the work required for security audits, which helps organizations manage compliance more efficiently as they scale. This automation reduces the need for additional manual effort, making it easier to handle increased compliance requirements as the organization grows.
Vendor Risk Management:
Vanta's Vendor Risk Management (VRM) solution allows organizations to continuously monitor and evaluate the trustworthiness of their vendors. This feature is particularly useful for organizations that are scaling up and need to manage a larger number of third-party relationships.
Lifecycle Management:
Vanta automates the onboarding and offboarding processes for employees, ensuring that access to systems and data is managed efficiently as the organization scales. This automation helps reduce the risk of user error and ensures that security policies are consistently applied.
Support for Multiple Compliance Frameworks:
Vanta supports a wide range of compliance frameworks, including SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and CCPA. This broad support allows organizations to scale their compliance efforts across different regulatory requirements as they expand into new markets or industries.
Contract Renewal
Automatic Renewal:
The initial term of the contract is typically one year unless specified otherwise in the Order Form. The contract will automatically renew for successive one-year periods unless the customer provides notice of termination at least thirty (30) days prior to the end of the current term.
Price Changes:
Vanta reserves the right to change prices for the services at the commencement of the next renewal term. Customers will be provided with reasonable notice of any fee increases prior to the expiration of the current term.
Discounts and Promotional Pricing:
Any discounts or promotional pricing specified in the Order Form may be temporary and could expire upon the commencement of a renewal term without additional notice. Vanta reserves the right to discontinue or modify any promotion, sale, or special offer at its discretion.
Contract Cancellation
Termination for Convenience:
Customers can terminate the contract by providing notice to Vanta at least thirty (30) days prior to the end of the current term.
Termination for Cause:
Either party may terminate the contract for cause if the other party materially breaches the terms and fails to cure the breach within ten (10) days of receiving notice of the breach. Material breaches include non-payment of fees for sixty (60) days after invoice issuance and any violation of the Prohibited Uses clause.
The contract can also be terminated if either party becomes the subject of bankruptcy or insolvency proceedings.
Effect of Termination:
Upon termination, the customer will lose access to the services, and Vanta will cease providing the services under the terminated order forms. Customers are not entitled to any refund of fees paid unless otherwise specified in writing.
Certain sections of the agreement, such as those related to fees and payment, ownership, confidentiality, disclaimers, indemnification, and limitation of liability, will survive termination.
Data Retention and Deletion:
Upon account termination, Vanta retains customer data and credentials for up to 365 days unless earlier deletion is requested. This allows customers to retrieve their data before it is permanently deleted.
Notice Requirements:
SOC 2:
SOC 2 is a widely recognized standard for managing customer data based on five "trust service principles"—security, availability, processing integrity, confidentiality, and privacy.
ISO 27001:
ISO 27001 is an international standard for information security management systems (ISMS). Vanta helps automate up to 80% of the work required to obtain ISO 27001 certification.
HIPAA:
HIPAA (Health Insurance Portability and Accountability Act) sets the standard for protecting sensitive patient data. Vanta helps healthcare organizations comply with HIPAA regulations.
PCI DSS:
PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards designed to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment.
GDPR:
GDPR (General Data Protection Regulation) is a regulation in EU law on data protection and privacy for all individuals within the European Union and the European Economic Area.
ISO 27017 and ISO 27018:
ISO 27017 provides guidelines for information security controls applicable to the provision and use of cloud services, while ISO 27018 focuses on the protection of personal data in the cloud.
US Data Privacy (USDP):
USDP is a compliance framework exclusive to Vanta that unifies controls and requirements for various US state data privacy laws.
ISO 42001:

Vanta
By Vanta