Vanta Logo
Vanta Logo
Platform
Products
Platform
Compliance
Get compliant quickly and painlessly with automation.
Continuous GRC
Join the modern way to GRC.
Personnel and Access
Easily control user access and permissions.
Risk Management
Proactively manage risk to drive smarter decisions.
Third Party Risk Management
Manage vendor onboarding and security reviews in one place.
Questionnaire Automation
Automate security questionnaire responses.
Trust Center
Showcase your compliance status and documentation.
Streamlined audits
Automate audit prep and evidence collection.
Customer Commitments
Centralize, track and act on every customer commitment.
AI Governance
Govern AI as fast as you adopt it.
Vanta AI
Automate compliance and uncover insights with AI.
Agentic Trust Platform
Build and prove trust from a single, unified platform.
Integrations
Automatically pull data from 400+ tools.
Vanta API
Build custom integrations and workflows.
NEW RELEASE
See what's new from
Vanta Delivers
Learn more
PRODUCTS
Compliance
Get compliant quickly and painlessly with automation.
Personnel and Access
Easily control user access and permissions.
Risk Management
Proactively manage risk to drive smarter decisions.
Third Party Risk Management
Manage vendor onboarding and security reviews in one place.
Questionnaire Automation
Automate security questionnaire responses.
Trust Center
Showcase your compliance status and documentation.
Streamlined audits
Automate audit prep and evidence collection.
Customer Commitments
Centralize, track and act on every customer commitment.
AI Governance
Govern AI as fast as you adopt it.
Vanta AI
Automate compliance and uncover insights with AI.
PLATFORM
See an interactive demo
Agentic Trust Platform
Build and prove trust from a single, unified platform.
Integrations
Automatically pull data from [integrations_count] tools.
Vanta API
Build custom integrations and workflows.
Solutions
Size
Industry
Frameworks
Find a partner
Startups
Automate compliance so you can keep building.
Mid-market
Expand your security and compliance program as you scale.
Enterprise
Gain a unified view of your compliance, security, and trust workflows.
Vanta is the one-stop shop that helps us scale as a business. The future of Vanta is an exciting one for us.
Paul Yoo
Head of Platform Security
Ramp logo
Healthcare
Protect sensitive info more easily by automating HIPAA and HITRUST.
Government
Proactively monitor emerging threats and automate security workflows.
Fintech
Stay ahead of evolving regulations and keep financial data secure with ease.
Vanta has saved us hundreds of hours and well over six figures in potential lost deals or added headcount.
Everett Berry
GTM Engineering
Clay logo
SOC 2
ISO 27001
GDPR
HIPAA
HITRUST
USDP
NIST AI Risk Management Framework
ISO 42001
Custom frameworks
All frameworks
Service provider directory
Discover world-class service providers.
Auditor directory
Connect with top compliance auditors.
AWS
Continuous compliance for teams building with AWS
Size
Startups
Automate compliance so you can keep building.
Mid-market
Expand your security and compliance program as you scale.
Enterprise
Gain a unified view of your compliance, security, and trust workflows.
“
Vanta just worked out of the box. It pulled in the right data and gave us a solid foundation for a secure, audit-ready program.”
Cursor logo
Industry
Healthcare
Protect sensitive info more easily by automating HIPAA and HITRUST.
Government
Proactively monitor emerging threats and automate security workflows.
Fintech
Stay ahead of evolving regulations and keep financial data secure with ease.
How Ramp keeps its global financial operations platform compliant with Vanta
Ramp logo
Frameworks
SOC 2
ISO 27001
GDPR
HIPAA
HITRUST
USDP
NIST AI Risk Management Framework
ISO 42001
Custom frameworks
All frameworks
Find a partner
Service provider directory
Discover world-class service providers.
Auditor directory
Connect with top compliance auditors.
AWS
Continuous compliance for teams building with AWS
Partners
Partner program overview
Set yourself apart with Vanta.
Service providers
Build, scale, and grow your business.
Auditors
Elevate your clients' experiences.
Partner program overview
Set yourself apart with Vanta.
Service providers
Build, scale, and grow your business.
Auditors
Elevate your clients' experiences.
We don’t partner with anyone else. We’ve gone all in on Vanta.
Steve Spence
CEO
Cognisys Logo
Resources
Customers
Company
Compliance resources
All resources
Customer stories
Hear from leaders who trust Vanta
Help center
Find the help you need to get started with Vanta.
Vanta Academy
Deepen your security knowledge and learn new skills.
Vanta Community
Connect with fellow Vanta users and security experts.
Instructor-led training
Live, interactive training to help you master the product and progress quickly.
About
Learn more about Vanta.
Security
Understand Vanta's security and compliance strategy.
Press
See the latest in Vanta news and press releases.
Careers
Join our team!
SOC 2
Learn everything you need to know about SOC 2.
Trust
Get the guide to all things trust.
HIPAA
Get the guide for HIPAA compliance.
TPRM
Implement and optimize your TPRM program.
GRC
Implement a GRC program with ease.
ISO 27001
Get the guide to ISO 27001 certification.
ISO 42001
Get your resource for ISO 42001 certification.
GDPR
Get the guide to GDPR compliance.
CMMC
Hear from leaders who trust Vanta
Cyber essentials
Get the guide to Cyber Essentials certification.
HITRUST
Get the guide to HITRUST certification.
FedRAMP
Get the guide to FedRAMP compliance.
All resources
Find all your security and compliance content here.
Blog
Explore security trends and thought leadership.
Guides and reports
Find ebooks, checklists, whitepapers, and more.
Events
Watch on-demand webinars on trending security topics.
Videos
Watch videos on security trends and expert insights
Product updates
See what's new across the Vanta platform.
Vanta graphic with tagline 'AI can run your GRC program. Build anything, anywhere.' featuring photos and titles of Adam Eickhoff, Justin Pagano, and Dongting Yu.
Register for the event ->
NEW RELEASE
See what's new from
Vanta Delivers
Learn more
Customers
Customer stories
Hear from leaders who trust Vanta
Help center
Find the help you need to get started with Vanta.
Vanta Academy
Deepen your security knowledge and learn new skills.
Community
Connect with fellow Vanta users and security experts.
Instructor-led training
Live, interactive training to help you master the product and progress quickly.
Product updates
Learn what's new on the Vanta Platform.
Company
About
Learn more about Vanta.
Security
Understand Vanta's security and compliance strategy.
Press
See the latest in Vanta news and press releases.
Careers
Join our team!
Compliance resources
SOC 2
Learn everything you need to know about SOC 2.
Trust
Get the guide to all things trust.
HIPAA
Get the guide for HIPAA compliance.
TPRM
Implement and optimize your TPRM program.
CMMC
Learn everything to need to know about CMMC.
GRC
Implement a GRC program with ease.
ISO 27001
Get the guide to ISO 27001 certification.
ISO 42001
Get your resource for ISO 42001 certification.
GDPR
Get the guide to GDPR compliance.
Cyber essentials
Get the guide to Cyber Essentials certification.
HITRUST
Get the guide to HITRUST certification.
FedRAMP
Get the guide to FedRAMP compliance.
All resources
All resources
Find all your security and compliance content here.
Blog
Explore security trends and thought leadership.
Guides and reports
Find ebooks, checklists, whitepapers, and more.
Events
Watch webinars and videos on trending security topics.
Product updates
See what's new across the Vanta platform.
Plans
Log inLog in
Get a demo
Get a demo

Vanta Information Security Addendum

1.  Introduction

Security is at the heart of Vanta’s mission. This Information Security Addendum (the “Addendum”) describes Vanta’s comprehensive information security program for the Services and Customer Information. Capitalized terms not defined in this Addendum have the meanings set forth in the MSA at vanta.com/legal/terms.

‍

2.  Information Security Program

Vanta maintains an ISO 27001-compliant risk-based information security governance program. The framework for Vanta’s security program includes administrative, organizational, technical safeguards reasonably designed to protect the Services and the confidentiality, integrity, and availability of Customer Information.

Vanta has adopted measures for ensuring accountability, such as implementing data protection and information security policies across the business, formally assigning roles and responsibilities for information security and data privacy functions, and periodically reviewing and updating its information security program as appropriate.

  • Vanta’s Information Security Program is reviewed at least annually, or earlier if prompted by a Security Incident (as defined below) or a material change in applicable law.
  • Oversight of the Information Security Program is assigned to appropriately qualified senior personnel with dedicated information security responsibilities.

‍

3.  Policies and Codes of Conduct

  • Vanta maintains written information security and privacy policies aligned with its Information Security Program and all applicable data protection laws.
  • These policies are communicated to all relevant personnel, who are required to formally acknowledge them.
  • Vanta monitors compliance with its policies and remediates non-compliance through documented processes; policy violations are addressed with appropriate disciplinary action.
  • Vanta maintains and communicates a code of conduct applicable to all employees. Vanta’s code of conduct is available on its Trust Center at trust.vanta.com. 

‍

4.  Risk Management

Vanta maintains and operates a risk management program that includes regular risk assessments and controls for risk identification, analysis, monitoring, reporting, and corrective action.

  • At least annually, Vanta performs risk assessments (internally or with contracted, independent resources) to identify risks to Customer Information, risks to Vanta’s business assets (including technical infrastructure), threats against those elements (both internal and external), the likelihood of those threats occurring, and the impact upon the organization.
  • Vanta triages security risks to Customer Information and prioritizes their remediation based on risk rating and potential impact.

‍

5.  Access Controls and Identity Management

Vanta uses secure access protocols and follows industry best practices for authentication, including Multi-Factor Authentication (MFA) and Single Sign-On (SSO). All production access requires the use of two-factor authentication, and production network infrastructure is securely configured to industry best practices to block all unnecessary ports, services, and unauthorized network traffic.

  • Vanta uses Okta to secure identity and access management. Phishing-resistant authentication factors (i.e. FIDO2, WebAuthn, etc.) are enforced wherever technically possible.
  • Vanta employees are granted access to applications based on their role (role-based access control i.e. RBAC), and access follows least-privilege and separation-of-duties principles.
  • Employees are automatically deprovisioned upon termination. Credentials are disabled or revoked within one (1) business day of termination.
  • Vanta maintains documented policies and procedures governing access management for personnel and service accounts.
  • Vanta maintains an accurate and current list of all personnel with access to systems that process Customer Information.
  • Privileged (i.e. root” or “administrator”) accounts are used only when technically required under approved change-control procedures; non-privileged users are prohibited from executing privileged functions.
  • Formal review and approval are required for any access request to systems storing Customer Information, plus periodic (at least annual) access audits to confirm appropriateness of privileges.
  • Vanta maintains procedures to report and revoke compromised credentials (e.g., passwords, API keys) and to verify user identity before issuing resets.
  • Vanta does not store user-provided passwords for Customer end-users; authentication is managed via the Customer’s identity access management service.

‍

6.  Device Security and System Controls

Corporate devices that process Customer Information are centrally managed and are equipped with mobile device management (MDM) software and anti-malware protection, with security configurations such as disk encryption, screen lock configuration, and software updates enforced. Endpoint security alerts are monitored with 24/7/365 coverage.

  • All corporate laptops are centrally managed through an approved MDM.
  • Centralized MDM systems are used to enforce baseline security configurations and implement patching, including addressing major vulnerabilities.
  • Full-disk encryption is required on laptops.
  • Portable and removable media are disabled or strictly controlled on all corporate laptops.

‍

7.  Personnel Security and Awareness

Vanta provides comprehensive security training to all employees upon onboarding and annually through educational modules within Vanta’s own platform. In addition, all new employees attend a mandatory onboarding session centered around key security principles. 

  • Vanta provides supplemental specialized training as appropriate for certain roles such as incident response and secure coding.
  • Vanta conducts, to the extent legally permissible in each worker’s jurisdiction, pre-employment background screenings for personnel who will access Customer Information or support Vanta’s service delivery.
  • Vanta personnel are subject to confidentiality obligations as a condition of employment or engagement and must follow policies on the protection of customer and other third-party data.
  • Vanta verifies the identity of its employees and contingent workers.

‍

8.  Data Encryption

Vanta has deployed secure methods and protocols for transmission of confidential or sensitive information over public networks.

  • Data in transit: Vanta uses TLS 1.2 or higher everywhere data is transmitted over potentially insecure networks. Legacy or insecure protocols (e.g., SSL v3, TLS 1.0/1.1) are disabled. HSTS (HTTP Strict Transport Security) is enforced to maximize security of data in transit.
  • Data at rest: All datastores housing Customer Information are encrypted at rest using industry-standard AES-256 encryption. Additionally, sensitive data is protected with field-level encryption.
  • Key management: Encryption keys are managed via AWS Key Management System (KMS). KMS stores key material in FIPS 140-2 validated Hardware Security Modules (HSMs), which prevents direct access by any individuals. Application secrets are stored via AWS Secrets Manager and Parameter Store with strictly limited access.

‍

9.  Data Retention, Deletion of Customer Information and Secure Disposal

  • During the term of the Agreement, Customer may delete Customer Information using the self-service functionality available within the Services. 
  • Following the effective date of termination or expiration of a Customer’s subscription, Vanta will delete Customer Information by expunging such Customer’s unique instance of the Vanta Services within 365 days. Customers may also request to have their data deleted, which Vanta will do within 30 days of receiving such request.
  • Notwithstanding the foregoing, Vanta shall not be obligated to delete any back-up or archival copies or data that Vanta is required to retain copies under applicable laws.
  • Where retention is legally required, Vanta will isolate and protect that Customer Information from any further processing except to the extent required by applicable laws. Where data is retained in back-up or archival systems, Vanta will not actively process such data and will delete it in the ordinary course in accordance with Vanta’s data retention policies. 
  • Vanta implements controls designed to ensure the secure disposal of Customer Information in accordance with applicable law and considering available technology, so that Customer Information cannot be read or reconstructed. Upon Customer’s request, Vanta shall provide Customer with written confirmation of destruction. 

‍

10.  Customer-Configurable Security Controls

Vanta provides a variety of configurable security controls that allow Customer to manage and protect its own use of the Services, including SSO authentication for administrative and user access and role-based access controls and permissions for access to resources. Customer is responsible for appropriately configuring such controls taking into account the nature of its Customer Information. Vanta’s secure implementation guidance is available on our Trust Center.

‍

11.  Security Incident Response

Vanta maintains a Security Incident response plan with measures to be followed in the event of any confirmed event that results in the unlawful or accidental destruction, alteration, damage, or loss, unauthorized disclosure of, or access to, Customer Information (a “Security Incident”).

  • Vanta will promptly investigate Security Incidents.
  • Vanta will provide notice promptly upon, and in any event within 72 hours of, becoming aware of a Security Incident. Where possible, such notice will include all available details required under applicable data protection laws for Customer to comply with its own notification obligations to regulatory authorities or affected individuals.
  • Vanta will take reasonable measures to mitigate the risks of further Security Incidents following a confirmed or suspected event.
  • Vanta will cooperate with Customer in good faith to provide information necessary for Customer to comply with applicable data protection law notification obligations.

‍

12.  Penetration Testing

Vanta engages a qualified third party to conduct penetration testing at least annually. All areas of the Vanta product and cloud infrastructure are in-scope for these assessments, and source code is fully available to testers to maximize effectiveness and coverage. Vanta’s penetration testing partner shall be an expert in GraphQL security. A summary of the most recent penetration testing report is available upon request at trust.vanta.com. Annual third-party penetration tests cover: (i) the hosted Services; and (ii) the entire internet-facing perimeter. Evidence that tests occurred, plus executive summaries of findings, are available to Customers under NDA upon written request. Critical and high-severity vulnerabilities affecting Customer Information will be remediated within defined SLAs:

  • Critical: 7 days
  • High: 30 days
  • Medium: 60 days
  • Low: 90 days

‍

13.  Bug Bounty Program

Vanta engages a third party to manage a vulnerability disclosure program as well as a private bug bounty program. All valid issues identified are handled according to Vanta’s vulnerability management program.

‍

14.  Vulnerability Management

Vanta maintains a vulnerability management program that includes regular network scanning and scanning at key stages of Vanta’s secure development lifecycle, and remediation of vulnerabilities on a risk basis in accordance with formal SLAs.

  • Vanta’s vulnerability management program includes: static analysis (SAST) testing during pull requests, software composition analysis (SCA) for known vulnerabilities, malicious dependency scanning, dynamic analysis (DAST) of running applications, network vulnerability scanning on a periodic basis, and external attack surface management (EASM).
  • Vanta subscribes to vulnerability notification services and prioritizes remediation based on risk rating, with remediation timeframes established based on risk severity.
  • Once a vulnerability has been reviewed and assessed for applicability, the vulnerability is remediated and verified in a timeframe commensurate with the risk posed, as per the SLAs set out in section 12 above.
  • Vanta deploys a log management solution and retains logs produced by intrusion detection systems for a minimum period of one (1) year.

‍

15.  Backups, Business Continuity, and Disaster Recovery

Daily and weekly backups of production datastores are taken. Backups are periodically tested in accordance with Vanta’s information security and data management policies.

  • Vanta maintains documented business continuity and disaster recovery (BC/DR) plans that address emergencies or other events capable of disrupting the Services or compromising Customer Information.
  • BC/DR plans are tested at least annually. Material gaps identified during testing are remediated.
  • Vanta continuously monitors, analyzes, and evaluates system performance and availability, and internally detects and reports faults in a timely manner.

‍

16.  Sub-processors and Third-Party Risk Management

Vanta leverages sub-processors to provide the Services to Customers. Vanta’s current list of sub-processors is available at trust.vanta.com/subprocessors. Vanta maintains industry standard due diligence and contracting procedures with respect to its sub-processors, as described below:

  • Vanta uses a risk-based approach to vendor security evaluation. Factors that influence inherent risk ratings include: access to customer and corporate data, integration with production environments, and potential business impact.
  • Vanta maintains and operates an industry-standard risk management program for all subprocessors, subcontractors, and critical suppliers with access to Customer Information or who support Vanta’s software or services.
  • Vanta enters into written agreements with each such third party appropriate for such vendor’s risk rating.
  • All third parties are subject to Vanta’s formal security assessment process before onboarding and at regular intervals thereafter.
  • Vanta maintains processes that evaluate ICT and product supply-chain risks and will promptly notify Customer of any material disruption or emerging threat that compromises the confidentiality, integrity, or availability of Customer Information.

‍

17.  Vanta’s Audits and Certifications

Vanta conducts regular third-party audits to ensure compliance with privacy and security standards:
‍

Certification / Audit Scope Availability
SOC 2 Type II Security, Availability, Confidentiality, Processing Integrity trust.vanta.com
ISO 27001 (27017/27018) Information Security Management System trust.vanta.com
ISO 27701 Privacy controls as Data Processor trust.vanta.com
ISO 42001 AI Risk Management trust.vanta.com

‍

  • Vanta’s SOC 2 Type II report and ISO 27001 certificate are available on the Trust Center at trust.vanta.com.
  • Upon written request, Vanta will provide summary or full reports (as appropriate) from its most recent independent security audits.

‍

18.  Customer Audits & Security Questionnaires

  • Vanta demonstrates continuous compliance via its Trust Center at trust.vanta.com where Vanta evidences its security certifications, active security controls and other resources detailing Vanta’s security and compliance posture. 
  • Customer shall have the right to conduct an audit of Vanta’s data security infrastructure pursuant to and in accordance with the audit terms set forth in the Vanta DPA. 
  • Vanta will complete security questionnaires submitted by Customer at reasonable frequencies, to confirm its security posture.

‍

19.  Physical Security

Vanta has reasonable controls in place to ensure the physical locations that process, store, or transmit Customer Information are appropriately secured. Vanta’s hosting and cloud infrastructure is provided by AWS, housed in physical data centers managed by AWS. Additional information on AWS’ physical security controls is available at: https://aws.amazon.com/compliance/data-center/controls/

  • Access to Vanta’s offices is controlled through badge, biometric, or equivalent authentication.

‍

20.  Logging, Monitoring, and Audit Accountability

Vanta monitors access to applications, tools, and resources that process or store Customer Information, including cloud services. Monitoring of security logs is managed by the security and engineering teams. Log activities are investigated when necessary and escalated appropriately.

  • Vanta creates and retains audit records for all systems, networks, and supporting infrastructure used to deliver the Services, enabling monitoring, analysis, investigation, and reporting of unlawful or unauthorized activity.
  • Privileged actions are logged in a manner that links every event to a named individual.
  • Privileged activity on supporting infrastructure is continuously monitored to detect unauthorized changes or policy violations.
  • Vanta continuously monitors security and availability—including network traffic and service logs—and acts promptly on any alerts.
  • Security and operational logs are regularly analyzed to detect suspicious activity, policy violations, or events that could affect the confidentiality, integrity, or availability of Customer Information.

‍

21.  Change, Configuration Management, and Change Notification

Vanta adheres to a change management process to administer changes to the production environment for the Services, including changes to its underlying software, applications, and systems. All production changes are automated through CI/CD tools to ensure consistent configurations.

  • Vanta regularly assesses the effectiveness of its security controls—through automated scanning, manual reviews, and policy compliance checks—against industry-standard frameworks and its own policies.
  • Vanta will provide reasonable advance notice to Customer of any material change to its infrastructure, architecture, third-party dependencies, data flows, or security posture that affect the confidentiality, integrity, or availability of Customer Information.

‍

22.  Data Integrity and Management

Vanta’s customers unilaterally determine what Customer Information they route through the Services. As such, Vanta operates on a shared responsibility model.

Vanta has a multi-tiered approach for ensuring data quality. These measures include: (i) code review and unit testing to ensure quality of logic used to process API calls, (ii) database schema validation rules which execute against data before it is saved, (iii) client-configurable user permissioning to ensure access is properly scoped.

‍

23.  Secure Development Lifecycle (SDLC)

  • Vanta maintains and operates a documented Secure Development / Security-by-Design process covering planning, coding, testing, deployment, and maintenance of the Services.
  • Vanta’s SDLC includes threat modeling as applicable, code review, automated dependency-vulnerability scanning, and security testing (static, dynamic, and container or IaC scanning) before code is promoted to production.
  • Results of SDLC security activities, along with remediation evidence for  findings, are retained for at least twelve (12) months.

‍

24.  Cloud Infrastructure and Network Security

  • Vanta segregates environments, keeping production and non-production environments separate and ensuring Customer Information only resides in production environments.
  • Customer Information is logically separated from other customer data, with distinct user-level boundaries enforced within each customer organization.
  • Primary backend resources are deployed behind private network controls (including private link or equivalent zero-trust architecture).
  • Network security policies and firewalls are configured for least-privilege access against a pre-established set of permissible traffic flows; non-permitted traffic flows are blocked.

‍

25.  Bulk Sensitive Personal Data

  • Vanta acknowledges the Final Rule implementing Executive Order 14117 (U.S. DOJ) prohibiting or restricting access to bulk Covered Data by Countries of Concern or Covered Persons.
  • To the extent Vanta’s services involve access to bulk Covered Data, Vanta represents that: (i) neither it nor any of its affiliates is organized or has its principal place of business in a Country of Concern, nor is 50% or more owned by Countries of Concern or Covered Persons; (ii) no employee or contractor of Vanta who has access to such Covered Data is located in a Country of Concern or qualifies as a Covered Person and (iii) none of Vanta, its Affiliates or its and their employees, contractors or subcontractors will process Covered Data or Customer Information in any Countries of Concern. 
  • Notwithstanding the foregoing, Customer acknowledges and agrees that subsection (iii) of the foregoing sentence is dependent in part on Customer not accessing the Services in any Country of Concern and, therefore, it shall not be considered a breach by Vanta of such subsection if Customer Information or Covered Data is processed in a Country of Concern as a result of Customer's or its Authorized Users' use of the Services in such a jurisdiction.

‍

26.  Updates

Vanta may update or modify this Addendum from time to time, provided that such updates and modifications do not materially reduce the overall security of the Service.

‍

‍

‍

Get compliant and build trust—fast

Request a demo
G2 badge - Summer 2026 LeaderG2 badge - Summer 2026 Leader EnterpriseG2 Badge Milestone 'Users Love Us'
Product
Automated ComplianceContinuous GRCThird Party Risk ManagementStreamlined Audits
Questionnaire AutomationRisk ManagementTrust CenterPersonnel and AccessCustomer CommitmentsAI GovernanceVanta AI
Frameworks
SOC 2ISO 27001GDPRHIPAAHITRUSTUSDPNIST AI RMFISO 42001CMMC
CJISNIS2DORACPS 234EU AI ActEssential EightCyber EssentialsFedRAMPCRICustom frameworksAdditional frameworks
Platform
Vanta integrationsVanta AI ✨Vanta APIWhat's New
Solutions
StartupMid-marketEnterprise
Customers
Customer storiesRelease notes
Become a partner
Partner program overviewService providersAuditors
Find a partner
Service provider directoryAuditor directoryIntegrationsAWS
Resources
All resourcesSOC 2 collectionISO 27001 collectionISO 42001 collectionGRC collectionTPRM collectionTrust collectionHITRUST collectionCyber Essentials collectionCMMC collectionHIPAA collectionGDPR collectionFedRAMP collection
Help centerVanta AcademyVanta CommunityVanta for developers
Articles
SOC 2 complianceSOC 2 checklistISO 27001 certification
ISO 27001 documentationHIPAA checklistGDPR checklist
Company
About
Careers
HIRING
PressSecuritySystem statusSupport statusTrust center
Linkedin iconFacebook iconTwitter (X) iconYoutube icon
Legal CenterTermsPrivacy
Do Not Sell or Share My Personal Information
Modern Slavery Act Statement
© 2026 Vanta. All rights reserved
SOC 2 Type 2 Compliance Badge for VantaISO 27001 Compliance Badge for VantaISO 42001 badgeGDPR Compliance Badge for Vanta