TrustRadius: an HG Insights company

Vanta

Score1 out of 10

13 Reviews and Ratings

What is Vanta?

Vanta is an automated security and compliance platform. Vanta helps businesses get and stay compliant by continuously monitoring people, systems and tools to improve security posture.

Media

Vanta's task management, used to monitor a control system and take action on outstanding configuration issues, security issues, and required compliance tasks.
the results of a risk assessment and identified risks to a business.
policy that can be generated from templates or by uploading a company's existing policies that describe the business' internal and external commitments to security and compliance.
vendor assessments.
employee and contractor task completion status monitoring. Take action to flag ex-employee accounts to be deprovisioned or service accounts that are not included in onboarding processes.
Vanta's monitoring, used to take action to remediate package vulnerabilities that have been detected on a company servers.

1 / 6

Top Performing Features

  • Common repository of GRC items

    A common repository linking all GRC elements such as policies, risks, regulations, etc.) to give a 360 degree view

    Category average: 7.7

  • Risk management

    Risk management capabilities including alert engine to warn of trending risk exposure and risk visualizations like heat maps, dashboards, etc.

    Category average: 7.4

  • Integration with Corporate Performance Management (CPM) systems

    Ability to integrate with external CPM software

    Category average: 6.8

Areas for Improvement

  • GRC policy management

    Support for policy lifestyle changes including creation, approval, communication etc.

    Category average: 7.5

  • Incident management

    System captures risk-related incidents, including cause and result

    Category average: 7.3

In my experience, Vanta will make no pricing refund exceptions for customers who derive no value from the product

Use Cases and Deployment Scope

We originally purchased Vanta for SOC 2 compliance but did not derive any value or utility from it. Beyond that, even after stating to our reps we never hardly used the product nor derived value, in our experience, they forced us to pay and continue with a full 2-year term. In my opinion, this is terrible customer service and predatory behavior - I think you should stay away from Vanta.

Pros

  • Collects your money
  • Connectors to GitHub and AWS

Cons

  • Customer service
  • Price transparency
  • Value

Return on Investment

  • In our experience, $18,000 or so of lost precious capital

Usability

Alternatives Considered

Drata

Other Software Used

GitHub, Snowflake, Amazon Web Services

Buyer Beware of this Company

Use Cases and Deployment Scope

We hired them to help us with SOC (System and Organization Controls) compliance.

Pros

  • They were supposed to help me create and store documents, but ended up losing them.

Cons

  • In my opinion, they make it very hard to contact them when you need something.
  • In my experience, they write their contracts to make it difficult to cancel service.
  • In my experience, they have no policy for refunds in addition to their [...] contacts.

Return on Investment

  • In my experience, they aren't really helpful after all. They ended causing more problems when documents went missing on our trust page. They caused us some embarrassment when we referred people to a mostly empty page.
  • They are now attempting to, in my opinion, force us to renew service.

Vanta Vindicates as a Small to Medium Sized Business SOC2 Tool

Use Cases and Deployment Scope

The Vanta software tool is being used with our Information Technology & Information Security departments to continue our SOC2 compliance after the company-wide SOC2 audit from August to November 2021.

This is helping us address any security concerns before the auditor needs to inquire on a resolution or require an exemption to be implemented.

Pros

  • SOC2
  • Ease of Use
  • Explanation of Steps to Resolve

Cons

  • Better Explanations.
  • More Detailed Resolutions.
  • Allows Greater Auditor Editing of Extraneous Tasks.

Most Important Features

  • Clarity of compliance.
  • Dashboard of tasks.
  • Ease of Use

Return on Investment

  • Will allow the company to attract more partners and clients.
  • Spotlight on deeper security needs
  • Provides better organization of assets

Other Software Used

Microsoft 365 Business Premium, Keeper, Bitdefender GravityZone

Usability

Great tool to get ready for Soc2

Use Cases and Deployment Scope

We've begun our journey for Soc2 certification. Vanta helped us with any steps required for preparation, contacts, and monitoring. Their customer success is great. The tool works fine and we're reaching the end of our audit period without any trouble. We just did what Vanta suggested we do.

Pros

  • Soc2 guidance and contacts building.
  • Well monitoring the infrastructure.
  • Well monitoring the people requirements.

Cons

  • Cannot differentiate Heroku review apps.
  • Vanta agent misses some HD encryption settings.
  • More than one Google Workspace setup.

Most Important Features

  • Easy process monitoring for Soc2.
  • Guidance for the process.
  • Alerts for the missing items.

Return on Investment

  • Process guidance.
  • Easy Monitoring.
  • Company restructure for better people & IT management.

Alternatives Considered

Drata

Other Software Used

Heroku Platform, Atlassian Confluence, GitHub

Vanta paid for itself 100x over

Pros

  • Compliance
  • Security
  • Partnership
  • Ongoing support

Cons

  • They truly do what we needed them to do really well

Most Important Features

  • compliance
  • security

Return on Investment

  • Money
  • Customers
  • Security checklists made easy

Other Software Used

Slack