External reviews
External reviews are not included in the AWS star rating for the product.
Makes security compliance easy and (almost) fun
What do you like best about the product?
Simple, clean interface for managing the complexities of SOC II compliance. The policy management features are particularly useful. Vanta isn't just a tool for managing docs — it helped us to clarify our processes and organize our thinking around security compliance issues. It's hard/impossible to get a sense of best practices when you're pursuing SOC 2 on your own.
What do you dislike about the product?
Could always benefit from more integrations with vendors. We had to do a little extra work to chase lesser known cloud vendors.
What problems is the product solving and how is that benefiting you?
Vanta practically gamifies SOC compliance. We actually enjoyed the process, at least as much as such a thing is possible.
The primary benefit for us was achieving SOC 2 Type 2 compliance. This has opened up the door for sales growth, particularly in enterprise accounts where security compliance can be a major hurdle for smaller service providers like us.
The primary benefit for us was achieving SOC 2 Type 2 compliance. This has opened up the door for sales growth, particularly in enterprise accounts where security compliance can be a major hurdle for smaller service providers like us.
- Leave a Comment |
- Mark review as helpful
Very pleased with this compliance tool
What do you like best about the product?
I like the UI; it's a very clean platform that makes tracking our team's various security controls much easier.
What do you dislike about the product?
It would be great for more policy templates to be provided and for alerts to be sent out.
What problems is the product solving and how is that benefiting you?
I want to be able to easily use Vanta for any security audit, not just SOC2. However I have realized that with some effort it can work well for any audit.
SOC-2 helper for startups
What do you like best about the product?
Ease of use and automated checks of our infrastructure
What do you dislike about the product?
More integrations would be awesome. JAMF integration is welcome.
What problems is the product solving and how is that benefiting you?
SOC-2 compliance
Head of Growth
What do you like best about the product?
So easy to use! Out of the box setup was plug and play. It integrated with all of our stack and the vendors that they recommended for us have been really easy to work with.
Their customer support is fast and responsive. When issues arise they fix them quickly.
Their customer support is fast and responsive. When issues arise they fix them quickly.
What do you dislike about the product?
There are some bugs that pop up from time to time. The policy wizard isn't 100% intuitive.
It's a bit funky to disable the monitoring and I wish they could incorporate some outside systems, but early stage.
It's a bit funky to disable the monitoring and I wish they could incorporate some outside systems, but early stage.
What problems is the product solving and how is that benefiting you?
SOC2 Type II
Security and time-savings - double win
What do you like best about the product?
Clear ROI for us. Relatively easy to configure to our existing tech stack. Easy to implement policies. Best of all, a majority of documentation was available to our auditors from inside the tool.
What do you dislike about the product?
Setup wasn't insignificant. But if the goal is SOC2 compliance, as it was for us, the time spent is worth it.
What problems is the product solving and how is that benefiting you?
We needed to spend less time on security compliance and have more proof to show our customers. Vanta provided that with security reports immediately after configuration. Then it set the stage for a pretty painless audit.
Recommendations to others considering the product:
Security is critical, so make time to get it setup correctly with your tech stack. We also used their recommended audit partners, who were well versed with how the software works. Getting the SOC2 program going isn't trivial, but Vanta provides a terrific hub for it.
Great product makes SOC2 certification easy
What do you like best about the product?
Turnkey audit evidence that covers 90% of SOC2 auditor questions.
Made Type I audit a breeze.
Made Type I audit a breeze.
What do you dislike about the product?
Out of the box policies were a little too corporate for our use. They were a good basis to build and soften our policies.
Early adopter meant that not every integration we used was covered at the time.
Would like greater detail or insight into control coverage, more robust risk and vendor management.
Early adopter meant that not every integration we used was covered at the time.
Would like greater detail or insight into control coverage, more robust risk and vendor management.
What problems is the product solving and how is that benefiting you?
Security control justification.
Suggestion of vendors to meet control requirements (looking at integrations Vanta offers)
Audit readiness & evidence capture.
Suggestion of vendors to meet control requirements (looking at integrations Vanta offers)
Audit readiness & evidence capture.
Recommendations to others considering the product:
If the integrations cover your needs, it makes SOC2 certification so much easier.
Message to early stage companies: Save time and money automating your SOC with Vanta
What do you like best about the product?
Deep integrations with virtually every major tech stack. Connecting AWS, Google, GitHub, & Jira took automated what used to take us weeks of evidence gathering prior to using Vanta.
What do you dislike about the product?
Integrations are awesome, but it would be great if they built a framework for us to build some of our own checks! There's some weird stuff we do that other companies probably don't (everyone's got their own sauce), and I'd be happy to write my own integration to send up various pieces of evidence from our own stack.
What problems is the product solving and how is that benefiting you?
They make evidence gathering so easy that you can focus your time and energy getting your system securely setup rather than spending your time and energy taking screenshots of weird admin panels and system configurations that you then have to tediously explain to an auditor what it means and why it's reasonable evidence.
Recommendations to others considering the product:
If you're an early stage company skeptical about spending extra money on compliance, consider that the cost of contracting with Vanta will lower the cost of your audit. It saves both you and your auditor time, so you'll end up paying less or the same amount overall. Plus, Vanta offers great references for ancillary services you'll inevitably need such as a penetration test, etc. They can help you find a cost effective auditor and connect you with resources that best-fit your organization and budgetary needs.
Everything is automated and it suits perfectly any company using cloud providers.
What do you like best about the product?
Automation, clear goals. Just follow the centralized checklist everyday, look at your email alarms. That's it.
What do you dislike about the product?
Very specific but you have to immediately distribute security issue at creation time. It would be great to define a window period (one week) where security issues don't count in the "Non distributed security issues" check. As we create issue on the fly and distribute everything once a week.
Otherwise it forces us to think even on little useless things (like private test github projects...) but it's a blessing in disguise.
Otherwise it forces us to think even on little useless things (like private test github projects...) but it's a blessing in disguise.
What problems is the product solving and how is that benefiting you?
Having clear goals toward SOC2 certification.
Recommendations to others considering the product:
If you use every classic IT tools to manage your cloud and company. Vanta would easily help you organize and align yourself with standard security compliance.
Vanta is a valuable platform for achieving and maintaining SOC compliance
What do you like best about the product?
The ability to generate template automatically is incredibly helpful. The punchlist is great. The risk assessment tools are very helpful too. The integrations that exist work well. Excellent post-sales support.
What do you dislike about the product?
The UI is patchy. It has some lovely touches, but the main navigation could use some work. You can get a bit lost when ramping up on the product. But once you're familiar with it, it's simple enough.
What problems is the product solving and how is that benefiting you?
SOC 2 Type 1 compliance. We will use for SOC 2 Type II when ready.
Vanta has made compliance a breeze.
What do you like best about the product?
I'm a big fan of automation, so when I heard about the legwork required for gathering evidence as part of SOC 2 audits, I cringed. That's why when I found out about Vanta and how they automate what can and should be automated, I was so relieved. I love how easy Vanta has made the audit and maintenance processes for SOC 2 and other compliance certifications.
What do you dislike about the product?
Not much to dislike. They do what they say they'll do. My only wish is that they would add some kind of IDS feature so they can be a complete one-stop shop for me in terms of compliance and security automation.
What problems is the product solving and how is that benefiting you?
Compliance audits were exactly what they said they would be: a breeze.
showing 1,331 - 1,340