Access reviews cut from 5 days to 1/2 a day

Vendor reviews cut from 2 hours to 45 minutes

Shifted to quarterly risk reviews from annual—no additional time investment needed

"Vanta is my memory. It helps me know where I need to focus. That's where I go every day to ensure that we’re doing the right things to protect all of that data that we receive."

Chuck Kesler
CISO, Pendo

TL;DR

  • Challenge: Pendo's security team managed compliance through disconnected spreadsheets and manual processes that couldn't scale to meet growing enterprise customer demands.
  • Solution: Pendo deployed Vanta as the operating system for its security program, unifying compliance, third-party risk management, and trust into a single continuous platform.
  • ROI: Access reviews reduced from five days to half a day, and vendor reviews cut from two hours to 45 minutes.

The company

Helping companies create better software experiences

Pendo is an AI observability and adoption platform that helps companies improve how their users engage with software. Processing 20 billion events per day on behalf of its customers, Pendo carries a significant responsibility to keep data safe and secure. 

The challenge

Pendo needed a security program to match its growth

With its security team split across operations, product security, and compliance, Pendo was operating without a centralized way to manage governance, risk, and compliance.

What Pendo tried first: Initially, the team relied on spreadsheets and disconnected tools to run its GRC program, without a unified view across systems.

Pendo's pivot point: Manual processes slowed everything down. Quarterly access reviews took nearly a full week of one person’s time. Risk assessments were conducted infrequently and relied on fragile spreadsheets with inconsistent scoring. Collecting SOC 2 reports and questionnaires for vendor reviews required hours of manual coordination, averaging two hours per vendor across 400 vendors. Meanwhile, security requests from prospects created internal bottlenecks, requiring manual routing across email, Slack, and phone.

Why Pendo chose Vanta: Pendo needed a unified platform for compliance, risk, and third-party risk management with real-time data and fast implementation. After a proof of concept, the value of working with Vanta was immediate, and strong alignment on customer focus helped solidify the decision.

{{quote-2}}

The Vanta impact

From reactive and manual to continuous

Pendo deployed Vanta as the operating system for its security program, connecting it with tools and systems across the organization to create a single, real-time view of compliance, risk, and vendor posture. 

The platform replaced fragmented spreadsheet workflows with continuous monitoring, automated evidence collection, and self-serve customer trust—giving Pendo's team the leverage to operate at enterprise scale.

Here's how Pendo deployed Vanta:

Vanta tools and solutions ROI
Trust Center: Provides customers and prospects with self-serve access to security documentation, reducing manual request handling and accelerating deal cycles.
  • 33,000 visits and 13,000+ audit report downloads
Compliance: Continuously monitors controls, automates access reviews, and streamlines audit readiness through integrated evidence collection.
  • Access reviews reduced from 5 days to half a day
  • Shifted from annual to quarterly risk reviews with the same time investment
Third-Party Risk Management: Centralizes and automates vendor assessments, including AI-assisted questionnaire completion and automatic SOC 2 collection.
  • Vendor reviews reduced from 2 hours to 45 minutes
“A year ago, 15% of my job was spent on TPRM reviewing vendors. Today, with new AI vendors my team wants to use popping up every day, it's up to 50% of my time.” — Allyson Kuegel, Staff Security Compliance Engineer at Pendo

Looking ahead, Kesler sees Vanta as the platform that will carry Pendo through an increasingly complex AI risk landscape: "AI is obviously the thing that we’re all thinking about at the moment,” he says. “I view Vanta as our platform that’s going to help us get there. I’m excited about the AI capabilities that we’re seeing in the platform.”

{{quote-3}}

"Within the first day, we immediately got value, and we knew this was going to be the right fit."

Chuck Kesler
CISO, Pendo

"Risk doesn't sleep. And we can't just depend on a once-a-year annual risk assessment and say we're done. We have to assess risk continually."

Chuck Kesler
CISO, Pendo