I use Vanta to ensure that our product meets security and compliance requirements while keeping product release on schedule. It gives me visibility into the organization's compliance status for frameworks such as SOC2 and ISO 27001, which allows me to coordinate with engineering, security, and compliance teams. I like the continuous monitoring feature the most, as Vanta doesn't just check compliance during audit season but continuously monitors connected systems such as cloud infrastructure, identity providers, and endpoint management. If a new employee's laptop encryption is disabled or critical security settings fall out of compliance, Vanta automatically flags the issue and assigns the appropriate task. Continuous monitoring automatically checks our cloud infrastructure, user access, devices, and security controls around the clock. Instead of waiting for audits, Vanta immediately alerts us to compliance issues, allowing my team to resolve them quickly. This keeps us audit ready, reduces manual efforts, minimizes security risks, and gives me confidence that our product remains compliant as it evolves. Setting up Vanta was easy for us. Review collected by and hosted on G2.com.
There's not a major improvement needed for Vanta, but I would like to see improvement. Configuring the platform for complex environments can take time, especially for organizations using many custom systems. Also, some compliance checks still require manual evidence because they are not fully automated, so these need to be automated first. Review collected by and hosted on G2.com.
