There is significant room for improvement in support, product clarity, and flexibility for small startups. Our experience with Vanta has been terrible. We previously used Sprinto, with which we completed our SOC 2 readiness in about one week, with the help of a real person who guided us over Zoom. She remained available during the audit, answered questions, and helped resolve issues. I was largely hands-off and couldn’t have been happier. We switched to Vanta primarily for HITRUST and decided to manage SOC 2 and HIPAA there as well. That turned out to be a roughly $14,000 mistake. Initially, the salesperson pressured us to make a quick decision and then stopped responding after the sale. I followed up three times simply trying to determine who our account manager was and received no response. The implementation support fell short of our expectations, as Vanta relies on Workstreet, whose initial engagement with us was limited to approximately 30 days. Communication involved delays, and we did not receive the live, hands-on Zoom guidance we had experienced with our previous compliance provider. In practice, “assistance” was very different from having someone take ownership and help us reach completion. The platform is extremely confusing. Vanta’s sales messaging emphasized automation and suggested that the product was intuitive enough that extensive account management would not be necessary. That was not our experience. We were left to interpret a substantial portion of the requirements, figure out what evidence was needed, update policies, and even use ChatGPT to understand how to complete Vanta’s own HITRUST tasks. When it became clear that we had no intention of continuing with Vanta, we tried to reach a reasonable resolution. We are a small startup and proposed that Vanta keep everything we had already paid—even though our platform usage had been minimal—and simply cancel the unpaid remainder of the contract. We later offered to pay an additional monthly installment as an early-termination fee. Vanta refused every proposal, citing its policy against mid-contract cancellations and its revenue-recognition practices. Instead, it repeatedly offered more onboarding and Workstreet support, even after we clearly explained that we had decided not to use Vanta or maintain our compliance program and policies there. The most disappointing part was the complete lack of flexibility. We were not asking for previous payments back. We were asking Vanta to stop charging a small startup for a platform it would not use. Vanta chose to enforce the remaining commitment anyway. Based on our experience, I cannot recommend Vanta to an early-stage company expecting hands-on compliance support. I recommend understanding exactly how much work your team will still be responsible for, what assistance is time-limited, and that Vanta may hold you to the entire contract even if the platform is not a workable fit.
To improve Vanta, I suggest continuing to improve the areas of integration with the HITRUST CSF for R2 assessments. It would be helpful for much of the testing of the evidence to be done within Vanta's environment and then prior to the testing, to have the information tested and uploaded into the CSF portal.
Failed tests for device CVEs seem to be cumulative, meaning I have to clear all CVEs before the test will pass, which makes it difficult to resolve the test before the next round of CVEs are published.
There are always tons of rooms for improvement for Vanta. I kind of exaggerated a little bit about the policy control. I don't really love the way they handle the revision management of that feature. If I'm on V1 of the policy document and I make some changes to it, then I get rid of V1 and then I re-upload V2. It's not that it keeps a running history of each of the different revisions. A little bit of an issue with that, but workable. I don't really have any negative complaint right now that would be worthwhile expressing. It's just that there's a lot of features. The UI is not super intuitive, but now that I've worked with it for a couple of years, I know how to navigate and get around. Initially, it was a little bit of a struggle understanding how these things would all work.
The only thing I wish for regarding the features is better RBAC. Permissions for platform users have been an issue. We've had to give admin access to Vanta for another team member to view all items. It would be great if the permissions of Vanta platform users had more verbosity to them, more dynamic. To improve Vanta, I think the refresh after remediation takes place could be controlled more. If it could be faster, that would be great. Besides the user permissions and the refreshing, which are improvements rather than issues, the rest looks fine. Vanta has been really nice, with a nice user experience, clear layout, and very reasonable recommendations compared to other platforms we've tried.
Every product has a lot of areas to improve. They have an AI generator for the system description for SOC 2, for example, however, the outline is a little sketchy. The system description has to have a little more insight or context about your business and why you're different. A true auditor will look at that closely. A lot of it is a little bit too automated and not really realistic. One area that they tout as being a real-time savings, we haven't found that to be a time savings yet.
The main area for improvement in Vanta is the user interface's refresh rate. Sometimes, after satisfying a control, the dashboard may not immediately update, requiring multiple refreshes for accurate status display.
Vanta offers real-time integration, automated compliance monitoring, and prebuilt control frameworks. It provides efficient reporting tools and KPI tracking, streamlining audit readiness and task management with a user-friendly interface and automated control testing.Vanta is designed to enhance corporate risk analysis, evidence collection, and security posture. With seamless integration into internal environments, it optimizes policy compliance and audit readiness. Users rely on Vanta for...
There is significant room for improvement in support, product clarity, and flexibility for small startups. Our experience with Vanta has been terrible. We previously used Sprinto, with which we completed our SOC 2 readiness in about one week, with the help of a real person who guided us over Zoom. She remained available during the audit, answered questions, and helped resolve issues. I was largely hands-off and couldn’t have been happier. We switched to Vanta primarily for HITRUST and decided to manage SOC 2 and HIPAA there as well. That turned out to be a roughly $14,000 mistake. Initially, the salesperson pressured us to make a quick decision and then stopped responding after the sale. I followed up three times simply trying to determine who our account manager was and received no response. The implementation support fell short of our expectations, as Vanta relies on Workstreet, whose initial engagement with us was limited to approximately 30 days. Communication involved delays, and we did not receive the live, hands-on Zoom guidance we had experienced with our previous compliance provider. In practice, “assistance” was very different from having someone take ownership and help us reach completion. The platform is extremely confusing. Vanta’s sales messaging emphasized automation and suggested that the product was intuitive enough that extensive account management would not be necessary. That was not our experience. We were left to interpret a substantial portion of the requirements, figure out what evidence was needed, update policies, and even use ChatGPT to understand how to complete Vanta’s own HITRUST tasks. When it became clear that we had no intention of continuing with Vanta, we tried to reach a reasonable resolution. We are a small startup and proposed that Vanta keep everything we had already paid—even though our platform usage had been minimal—and simply cancel the unpaid remainder of the contract. We later offered to pay an additional monthly installment as an early-termination fee. Vanta refused every proposal, citing its policy against mid-contract cancellations and its revenue-recognition practices. Instead, it repeatedly offered more onboarding and Workstreet support, even after we clearly explained that we had decided not to use Vanta or maintain our compliance program and policies there. The most disappointing part was the complete lack of flexibility. We were not asking for previous payments back. We were asking Vanta to stop charging a small startup for a platform it would not use. Vanta chose to enforce the remaining commitment anyway. Based on our experience, I cannot recommend Vanta to an early-stage company expecting hands-on compliance support. I recommend understanding exactly how much work your team will still be responsible for, what assistance is time-limited, and that Vanta may hold you to the entire contract even if the platform is not a workable fit.
To improve Vanta, I suggest continuing to improve the areas of integration with the HITRUST CSF for R2 assessments. It would be helpful for much of the testing of the evidence to be done within Vanta's environment and then prior to the testing, to have the information tested and uploaded into the CSF portal.
Failed tests for device CVEs seem to be cumulative, meaning I have to clear all CVEs before the test will pass, which makes it difficult to resolve the test before the next round of CVEs are published.
There are always tons of rooms for improvement for Vanta. I kind of exaggerated a little bit about the policy control. I don't really love the way they handle the revision management of that feature. If I'm on V1 of the policy document and I make some changes to it, then I get rid of V1 and then I re-upload V2. It's not that it keeps a running history of each of the different revisions. A little bit of an issue with that, but workable. I don't really have any negative complaint right now that would be worthwhile expressing. It's just that there's a lot of features. The UI is not super intuitive, but now that I've worked with it for a couple of years, I know how to navigate and get around. Initially, it was a little bit of a struggle understanding how these things would all work.
The only thing I wish for regarding the features is better RBAC. Permissions for platform users have been an issue. We've had to give admin access to Vanta for another team member to view all items. It would be great if the permissions of Vanta platform users had more verbosity to them, more dynamic. To improve Vanta, I think the refresh after remediation takes place could be controlled more. If it could be faster, that would be great. Besides the user permissions and the refreshing, which are improvements rather than issues, the rest looks fine. Vanta has been really nice, with a nice user experience, clear layout, and very reasonable recommendations compared to other platforms we've tried.
Every product has a lot of areas to improve. They have an AI generator for the system description for SOC 2, for example, however, the outline is a little sketchy. The system description has to have a little more insight or context about your business and why you're different. A true auditor will look at that closely. A lot of it is a little bit too automated and not really realistic. One area that they tout as being a real-time savings, we haven't found that to be a time savings yet.
Scalability could be improved.
The main area for improvement in Vanta is the user interface's refresh rate. Sometimes, after satisfying a control, the dashboard may not immediately update, requiring multiple refreshes for accurate status display.
Currently, Vanta's user access review module is still in development, and we've been giving them continuous feedback to help them improve that.