What I like most about Vanta is how much manual work it removes from our compliance audits. Automated evidence collection and continuous monitoring across our tech stack (AWS, GitHub, Google Workspace, etc.) mean we’re not scrambling to gather screenshots and logs every time an auditor asks for something—it’s already there and kept up to date in real time. The pre-built control mappings for frameworks like SOC 2 and ISO 42001 also saved us a lot of time by clarifying what evidence ties to which requirement. On top of that, the dashboard makes it easy to see at a glance which controls are passing or failing, so we can address issues before they turn into audit findings rather than reacting afterward. Review collected by and hosted on G2.com.
What I dislike about Vanta is that some of the automated checks can be overly rigid or throw false positives, which then forces a manual review just to confirm a control is actually fine. Pricing can also feel steep as you add more integrations or frameworks, and it isn’t always clear or transparent upfront. A few integrations are also shallower than I expected: they’ll flag an issue, but they don’t always provide enough context to resolve it without digging into the underlying system yourself. Customer support has been hit or miss depending on who picks up the ticket, and the UI—while generally clean—can start to feel cluttered once you’re managing multiple frameworks at the same time. Review collected by and hosted on G2.com.



