Vanta
Also known as: Vanta AI Agent, Vanta Risk Graph, Vanta Trust Center
Agentic trust and compliance platform: the Vanta AI Agent answers questionnaires and flags gaps from the customer's own knowledge base, Custom Agents run on schedules and events with approval steps and curated templates, and an API and MCP server run in US, EU and Australian regions.
Vanta is a compliance automation company that repositioned as an Agentic Trust Platform in November 2025. The Vanta AI Agent works from the customer's Knowledge Base, previous responses, policies, controls and tests: it answers security questionnaires for a person to review and submit, flags inconsistencies between policy and practice, monitors vendors' attack surfaces and alerts in real time, and writes remediation snippets for tools such as Terraform and the AWS CLI for developers to review.
Since July 2026 customers can build Custom Agents that run on a schedule, on demand or on platform events (Knowledge Base additions, risk scenario changes, vendor risk score changes and assessment milestones), start from curated agent templates, require approval before a run proceeds with Slack notifications for pending requests, and keep a run history per agent. The Risk Graph connects controls, vendor assessments, configurations and people data, and built-in workflows require reviewer approval for questionnaires, access changes and audit evidence.
Coverage spans SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR, PCI DSS, FedRAMP and other frameworks with prebuilt controls and policy templates. The Vanta API (public beta) and a remote MCP server (beta) run from US, EU and Australian instances. Vanta holds SOC 2 Type II, ISO 27001 and ISO 42001, supports SAML and SCIM with role-based and custom roles, and sells Essentials, Plus, Professional and Enterprise plans through sales. An AI governance product for inventorying and monitoring agents is in early access.
Vendor details
Canonical URL
https://www.vanta.com
Category
Security / SOC agent
Subcategory
Agentic compliance and trust management
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Evidence is collected automatically from connected systems, access management spans integrated applications, and the Vanta API (OAuth with granular read and write scopes) ingests data from systems without a native integration, extracts data for reporting and triggers external remediation workflows. The remote MCP server at US, EU and Australian endpoints lets Claude Code, Cursor, Claude Cowork, Perplexity and other MCP clients remediate failing tests, manage controls and govern policies.
In practice
A sales team drowning in security questionnaires has the agent answer them from evidence the company has already collected, rather than a human retyping the same answers each quarter.
A security lead lets the agent draft and remediate policies continuously so the posture holds between audits rather than being reconstructed before each one.
A company running SOC 2, ISO 27001 and HIPAA together reuses evidence across frameworks through cross mapping instead of collecting it three times.
Sources & related URLs
Agentic Index coverage score
9.5 / 14 capabilities · 68%
| Integrations & Tool Calling | Full |
|---|---|
|
Automated evidence collection from connected systems, access management across integrated applications, remediation snippets for tools such as Terraform and AWS CLI, an API that ingests data from systems without a native integration and triggers external remediation workflows, and an MCP server whose tools remediate failing tests and open pull requests. Sourcevanta.com/products/vanta-apiread 2026-09-28 |
|
| Workflow Orchestration | Full |
|
Custom Agents, generally available since July 2026, let customers create their own agents that run on a schedule, on demand or on platform events, beside the Vanta AI Agent, so a buyer can run several agents it built and configure its own flows. Sourcehelp.vanta.com/en/articles/11345422-product-updatesread 2026-09-28 |
|
| Knowledge Grounding & RAG | Full |
|
The Vanta AI Agent answers from the customer's Knowledge Base and previous responses and draws on its policies, controls, frameworks, tests and documentation, with the Risk Graph connecting controls, vendor assessments, configurations and people data: a maintained store of the customer's knowledge that the agent retrieves from. Sourcevanta.com/products/airead 2026-09-28 |
|
| Human Oversight & Guardrails | Full |
|
Custom Agent runs can require approval, with Slack notifications linking to pending requests; built-in workflows require reviewer approval for questionnaires, access changes and audit evidence before they are final; questionnaire answers are reviewed and submitted by a person and remediation arrives as snippets for developer review. Sourcehelp.vanta.com/en/articles/11345422-product-updatesread 2026-09-28 |
|
| Security, Identity & Governance | Full |
|
Attestations include SOC 2 Type II, ISO 27001 and ISO 42001, named on the security page, with the SOC 2 report and ISO certificate on the Trust Center. Access runs through roles (Admin, View-only Admin, Editor, Collaborator, scoped and custom roles), SCIM role sync from the identity provider and custom SAML connections. Sourcevanta.com/company/securityread 2026-09-28 |
|
| Observability & Auditability | Partial |
|
Custom Agents keep an execution history, and each agent's details page shows its prompt, configuration and scoped run history. That is a run level record; no per step or per tool call detail is documented. Continuous control monitoring, the Risk Graph and the Trust Center report on the customer's estate rather than on the agents. Sourcehelp.vanta.com/en/articles/11345422-product-updatesread 2026-09-28 |
|
| Memory & State Persistence | Not documented |
|
No agent memory with a scope and lifetime is documented. Previous responses and the Knowledge Base ground the agent's answers, and run history is an execution record rather than memory. Sourcevanta.com/products/airead 2026-09-28 |
|
| Deployment & Data Residency | Full |
|
Separate United States, Europe and Australia instances run on AWS infrastructure, each with its own endpoint (mcp.vanta.com, mcp.eu.vanta.com, mcp.aus.vanta.com). Sourcedeveloper.vanta.com/docs/vanta-mcpread 2026-09-28 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
Curated Custom Agent templates create workflows in one click with recommended schedules (August 2026), policy templates come in every plan, and framework coverage is packaged with prebuilt controls. Sourcehelp.vanta.com/en/articles/11345422-product-updatesread 2026-09-28 |
|
| Triggers & Channel Coverage | Full |
|
Custom Agents run on a schedule and on events: Knowledge Base document additions, risk scenario creation or update, vendor residual risk score changes and vendor assessment due-date milestones; the AI Agent also monitors continuously and alerts in real time. Sourcehelp.vanta.com/en/articles/11345422-product-updatesread 2026-09-28 |
|
| Model Flexibility & Routing | Not documented |
|
Vanta uses "a combination of models from industry-leading third-party platforms" without naming them and offers no model choice. Claude and Cursor reaching Vanta through its MCP server is a way in for outside assistants, not a model choice. Sourcevanta.com/products/airead 2026-09-28 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
The Vanta API (public beta) with OAuth applications and granular read and write scopes, documented at developer.vanta.com, for data ingestion, process automation, data extraction and remediation triggers; plus a remote MCP server (beta) at regional endpoints with OAuth, whose tools remediate failing tests, manage controls and mappings and govern policies. Sourcedeveloper.vanta.com/docs/vanta-mcpread 2026-09-28 |
|
| Testing, Debugging & Optimization | Not documented |
|
No harness or scored tests for evaluating the AI Agent or Custom Agents are documented; continuous control tests check the customer's estate, not the agent. Sourcevanta.com/products/airead 2026-09-28 |
|
| Browser & Computer Use | Not documented |
|
Evidence is collected through integrations and the API; no browser or computer use by an agent is documented. Sourcevanta.com/products/airead 2026-09-28 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Vanta released a major update to its Custom Agent and MCP capabilities. Users can now trigger Custom Agent workflows automatically from Knowledge Base additions or vendor assessment milestones, utilize curated agent templates, and ask the Vanta Agent questions about vendor findings and alerts. Non-admins can now also connect to Vanta's MCP server based on their existing permissions.
Bears on: Workflow orchestration
View sourcePricing
Contact sales; plans are Essentials, Plus, Professional and Enterprise with no published prices
Plan tier with questionnaire allowances; price not published
Included quota
25 automated questionnaires a year on Plus, 144 on Professional.
What is public
Plan names and inclusions: Essentials (one framework, the Vanta AI Agent, Trust Center), Plus (25 automated questionnaires a year, access management), Professional (144 questionnaires a year, risk management, custom tests) and Enterprise (custom). No prices.
Billing mechanics
Personalized pricing through sales per plan; plan inclusions set questionnaire allowances and modules.
Cost watchouts
Inference, not stated by the vendor: the independent audit firm's fee for an attestation sits outside the platform subscription.
Variable cost rationale
Plan tiers cap questionnaire automation (25 or 144 a year), so higher volume moves a buyer up a plan; the price steps are not published.
Additional watchouts
Check the questionnaire allowance against expected inbound volume when choosing a plan.
Sales call required
Yes, required for paid access
Free / trial
None retrieved
Key ambiguities
No plan price is published, and what sets the price within a plan is not stated.
Missing data
All plan prices and the pricing basis within each plan.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Vanta
The closest documented capability profiles to Vanta among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Sprinto9.0 / 14A lighter documented profile than Vanta
- Anvilogic8.5 / 14A lighter documented profile than Vanta
- BlinkOps10.5 / 14Adds documented Memory & State Persistence
- Drata10.5 / 14Adds documented Testing, Debugging & Optimization
- Seemplicity8.5 / 14A lighter documented profile than Vanta
- SentinelOne10.5 / 14Adds documented Model Flexibility & Routing
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded