BlogCompany news
August 11, 2026

Introducing the 2026 Vanta 25 to Trust Award winners

Written by
Kaitlin Pettersen
Head of Customer Engagement
Reviewed by
No items found.

Accelerating security solutions for small businesses 

Tagore offers strategic services to small businesses. 

A partnership that can scale 

Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate.

Standing out from competitors

Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

Congratulations to this year’s cohort of winners for the Vanta 25 to Trust Awards!

The Vanta 25 to Trust honors 25 individuals who are pushing the fields of trust, security, and compliance forward through leadership, innovation, and real-world impact. These are the practitioners on the forefront, the ones setting the standard for what trust looks like at every stage and scale of a business.


This year, we’re opening voting to the Vanta Community. Within each category, we’re asking you to vote for category winners. We’ll celebrate these final five at VantaCon this fall. 

Read on to meet the Vanta 25 to Trust award winners, and vote below. 

Security culture

These category winners are the leaders who embed security into how their teams work, driving quantifiable adoption and behavior change.

Jason Kirk, Group CISO at Nando’s

Jason leads security for Nando's global operations, where he's built a scalable, automated, and verifiable system for board-level security reporting. Nando's operates across multiple markets worldwide and is focused on staying lean, so Jason has ensured his team can make security critical to Nando's culture without burying anyone in administrative overhead. Automated data feeds power the evidence layer behind his security reporting, giving leaders immediate and thorough visibility into the company's security posture — and the confidence to stand behind it.

Nazia Khan, Director of Compliance at Teladoc

With nearly two decades in cybersecurity, Nazia has played a key role in maturing and advancing one of the most sophisticated multi-framework compliance programs in telehealth. Building on an established unified control framework, she has strengthened governance across HITRUST, HIPAA, SOC 2, and ISO 27001, reducing duplication across audits and improving operational efficiency. She's now compressing Teladoc's audit prep window from six months to three through continuous control testing, turning compliance from an annual scramble into an always-audit-ready operation.

Joanna Chen, CISO at Dashlane

At a company where security is the product, Joanna holds the bar for what it means to live that value from the inside out. She's made compliance a shared operating standard at Dashlane — not a back-office function — by unifying the company's SOC 2 Type 2 and ISO 27001 programs into a single, streamlined audit process that every team can navigate and own. The result is a culture where security isn't something that happens to the company once a year. It's how Dashlane works.

Marcia Foley, Vice President of Global Compliance and IT at Sauce Labs

A staunch advocate for compliance and security throughout her tenure at Sauce Labs, Marcia has built a certification program that keeps pace with a fast-moving engineering culture. She's led the team to SOC 2, ISO 27001, and ISO 27701 certifications — and, as of June 2026, achieved ISO/IEC 42001 certification, positioning Sauce Labs ahead of the curve on AI governance. Her approach has always been to make compliance work with the business rather than slow it down — a philosophy on full display at trust.saucelabs.com.

Glenn Gabagat, VP of Information Protection Risk and Controls at JPMorgan Chase

At one of the world's largest financial institutions, driving security culture means influencing hundreds of people across a deeply complex organization. Glenn has done exactly that — engaging over 100 Business Information Security Officers (BISOs), stakeholders, and control owners to embed compliance into how teams operate day to day. The result isn't just a successful PCI or SOC 2 audit. It's a workforce where security accountability is built into the workflow, not bolted on after the fact.

AI innovation

The winners in this category are leading the way for responsible AI deployment, with real governance, controls, and risk management practices.

Arthur Stromquist, Security and Compliance Manager at LangChain

Arthur is building LangChain's security and compliance program from the ground up — and doing it the way you'd expect at an AI agent platform: by running agents to do it. Using LangSmith, LangChain's own product, his agents continuously build context on how the company operates, taking on the judgment-heavy work — risk assessments, policy drafting, vendor reviews, and framework expansion. Other teams can now self-serve much of the security program. Arthur's team owns the final call when it matters.

Martin Tschammer, Head of Security at Synthesia

Martin believes security teams should be AI-native — and he's built one of the most admired programs in the industry to prove it. Synthesia is the first AI video company in the world certified against ISO 42001, the international standard for AI management systems. Martin's team also built an AI agent that collected and packaged 939 pieces of compliance evidence in two days — work that would normally take weeks or months. At Synthesia, AI isn't just the product. It's how security gets done.

Geert van Asperen, Snitcher

While most compliance professionals are still exploring how AI fits into their programs, Geert has already built it in—with real workflows, real governance, and real results. What distinguishes him isn't just the work itself, but his willingness to share it openly: the wins, the lessons, and the actual processes, so peers across the industry can learn and build alongside him.

Jeremy Carriger, CISO at Arcadia

Jeremy's approach to compliance is built for scale: use AI to do the work that would otherwise require more people. By embedding compliance intelligence directly into Arcadia's AI-native engineering workflows, his team gets real-time security context at the point where decisions are made — not after the fact. The result is a program designed to grow with the company without growing the headcount behind it.

Adam Eickhoff, Director of Cybersecurity at Hard Rock Digital

At Hard Rock Digital, gaming licenses across roughly 10 US states depend on compliance — which means AI governance can't be theoretical. Adam built Springfield, a multi-agent AI platform that runs a digital twin of the company's entire compliance environment, with every major security function flowing through the same agentic pipeline. Work that once took months now takes minutes. A peer CISO called it a center of excellence unprompted. Adam's north star: a fully automated, continuous audit — with humans out of the loop only where the controls have earned it.

Operations excellence

These category winners excel at scaling security or GRC programs with rigor, repeatability, and outcomes.

Kim Park, Masterclass

Kim has run Masterclass's SOC 2 compliance program with relentless standards for four years running — and she's built it to scale. By automating evidence collection across roughly 80% of the company's controls, she's eliminated the manual scramble that once consumed weeks of her team's time each audit cycle. Her approach: if a control is failing, fix it. If evidence can be automated, automate it. She's transformed compliance from a reactive exercise into an operational discipline embedded across the organization.

Mandy Matthew, Lead Security Risk Program Manager at Duolingo

During her time at Duolingo - a publicly traded tech company operating at global scale - Mandy has built one of the most operationally efficient GRC programs in the industry. She simultaneously manages five compliance frameworks (SOC 2, ISO 27001, GDPR, HIPAA, and NIST CSF 2.0) through a single source of truth covering audit evidence, automated testing, policies, vendor assessments, and risk reviews. Her program saves the team over 40 hours per week, letting a lean team run what would otherwise require far more headcount. That's not just efficiency. That's a benchmark.

Megan Snyder, Director of Customer Assurance at GitHub

When GitHub Copilot launched, it triggered a surge of over 300 enterprise security questionnaires—a potential bottleneck for sales cycles and AI adoption at scale. Megan didn't just solve the immediate problem; she built a system. Through cross-functional rollout, change management, and sustained enablement across hundreds of users, she drove 93% questionnaire automation in six months — half the original target timeline. That program has been running at scale for over a year, a testament to how operationally sound it was from day one.

Chrysa Freeman, Senior Manager of Governance, Risk, and Compliance at Perforce

When a company grows through acquisitions, it inherits complexity — including compliance programs that don't talk to each other. Chrysa and her team have spent their time at Perforce solving exactly that: rationalizing compliance across a broad portfolio of acquired products, building enterprise-wide policies that replaced a patchwork of disconnected standards, and operationalizing it all so the team can succeed at scale. Managing multiple frameworks across more than 20 products, she's turned a fragmented compliance environment into a coordinated, scalable program.

Kyley Forbes, Privacy Officer, Senior Data Security, and Privacy Consultant at Mirai Security

Kyley manages security and GRC programs for over 30 clients simultaneously — without ever sacrificing quality. She transforms complex, overlapping compliance requirements into standardized, repeatable processes that clients can rely on audit after audit, and has spearheaded Mirai's own ISO 27001 program while guiding clients through their own. What makes her exceptional isn't just her practitioner-level expertise — it's the operational precision she brings to every engagement, and the consistency of the outcomes she delivers across dozens of clients at once.

Industry influence

The winners in this category are individuals who actively advance trust beyond their roles through community, influence, and knowledge sharing.

Ayoub Fandi, GRC Engineer at Lovable

Ayoub is one of the driving forces behind GRC Engineering — the movement pushing the compliance profession to embrace software engineering principles like automation and systems thinking. As a co-author of the GRC Engineering Manifesto, host of the GRC Engineering Podcast, and author of the GRC Engineer Newsletter, he's built one of the most active communities in the field. Ayoub doesn't just practice what he preaches. He wrote the document that defined what practicing it even means.

John Hoffoss, Director of Information Security & Privacy at Ovative

John is a founding member of the Society of Information Risk Analysts (SIRA), a nonprofit dedicated to advancing quantitative risk practices across the security field — and his fingerprints are on the movement to replace gut-feel severity ratings with risk scoring grounded in data science and empirical evidence. He brings original research and field observations into the broader discourse, helping mature a discipline that's only becoming more consequential in the AI era.

Phil Grove, Principal Product Manager at Atlassian 

Phil is setting a new standard for trust across the Atlassian Marketplace. He's establishing compliance requirements — including SOC 2 and ISO — as the bar for Marketplace partners seeking premier status on one of the world's most widely used enterprise software platforms. By embedding trust signals directly into how partners are evaluated and how customers discover apps, Phil is quietly raising the compliance expectations for an entire layer of the enterprise software industry.

Akhila Chitiprolu, Head of Security and GRC at Sierra

Akhila brings her expertise in security and GRC beyond the walls of her organization, making the case for treating compliance as an engineering discipline at a moment when the industry is grappling with what it means to secure AI agents. She's appeared on the Security & GRC Decoded podcast, spoken at the Cloud Security Alliance's inaugural Agentic AI Security Summit, and joined an ISACA Silicon Valley panel on the autonomy-security tightrope in agentic AI. In each setting, she's helping define the field in real time.

Andrew Becherer, CISO at Socket

Andrew has built world-class security programs from scratch at some of the most recognized companies in tech — including as Datadog's first security hire, scaling security through hypergrowth and IPO. What makes him an industry influencer isn't just the resume. It's that he takes what he's learned and brings it back to the community — from conference stages to peer conversations — consistently making the case that security done right is a competitive advantage, not a tax.

Business impact

The category winners here are leaders who’ve translated security and compliance into real customer trust and tangible business impact.

Ryan Fullerton, GRC and Trust Lead at Radar

Fullerton turned Radar’s security and compliance program from a reactive process into a proactive system that improves revenue in measurable, demonstrable ways. Along the way, he rebuilt the company’s SOC 2 program, cut audit prep from two months to two weeks, and launched a SOC 1 program on a custom common controls framework. Fullerton stands out for embedding compliance into Radar’s go-to-market strategy, ensuring that trust is a sales accelerant rather than a gate.

Chuck Kesler, CISO at Pendo

Chuck has done what most security leaders only talk about: turned compliance into a measurable revenue driver. At Pendo, his Trust Center has logged tens of thousands of visits and audit report downloads, influencing hundreds of millions of dollars in revenue by giving prospects and customers immediate, self-service access to security documentation. He's also driven real operational efficiency — access reviews that once took days now take hours. Chuck didn't just build a security program. He made the business case for it.

Dongting Yu, Security Engineer at Clay

Dongting's philosophy is simple: get compliant before customers ask, so trust supports sales instead of slowing it down. At Clay, he's built a compliance program that enables enterprise sales without pulling internal teams away from the product — and has proactively pursued certifications, including ISO 42001, ahead of customer demand. The result is a company that walks into enterprise deals with its security posture already answered.

Nick Hardy, Senior Director of Security GRC and Program Management at Samsara

At Samsara — whose AI platform powers real-world decisions for fleets and infrastructure operators — trust isn't optional. Nick has built a GRC program that operates at full enterprise scale: 10 compliance frameworks, 820 controls consolidated to 260, and 600 vendors managed with up to 50% faster review times. His Trust Center has influenced over $150 million in revenue, SME interview time per audit cycle has been cut nearly in half, and Samsara is among the first companies globally to achieve ISO 42001.

Joshua McKibben, Head of Trust & AI Risk at Harvey

Josh has been a pioneer in applying AI, data, and automation to trust and risk at hyperscale. At Snowflake he architected the Trust function's data and AI strategy—a common control framework, control-monitoring dashboards, and production AI agents for vendor risk and compliance validation. This cut effort by 44% across 3,000+ customer reviews a year, while achieving and maintaining compliance across 65+ global certifications and frameworks during growth from $250M to $4.67B in revenue. As Head of Trust at Harvey, he's extending that engineering approach to AI itself, where the control surface includes frontier and open source models, data lineage, and agents.

Vote for the final five in the Vanta Community

Voting for Vanta's 25 to Trust category winners is now open in the Vanta Community, open to all active Vanta customers. You can vote for one final winner in each category. Voting ends on September 10, 2026. Head over to the Vanta Community's #announcements channel in Slack to submit your vote. Not a member yet? Fix that by requesting to join here.

Access Review Stage Content / Functionality
Across all stages
  • Easily create and save a new access review at a point in time
  • View detailed audit evidence of historical access reviews
Setup access review procedures
  • Define a global access review procedure that stakeholders can follow, ensuring consistency and mitigation of human error in reviews
  • Set your access review frequency (monthly, quarterly, etc.) and working period/deadlines
Consolidate account access data from systems
  • Integrate systems using dozens of pre-built integrations, or “connectors”. System account and HRIS data is pulled into Vanta.
  • Upcoming integrations include Zoom and Intercom (account access), and Personio (HRIS)
  • Upload access files from non-integrated systems
  • View and select systems in-scope for the review
Review, approve, and deny user access
  • Select the appropriate systems reviewer and due date
  • Get automatic notifications and reminders to systems reviewer of deadlines
  • Automatic flagging of “risky” employee accounts that have been terminated or switched departments
  • Intuitive interface to see all accounts with access, account accept/deny buttons, and notes section
  • Track progress of individual systems access reviews and see accounts that need to be removed or have access modified
  • Bulk sort, filter, and alter accounts based on account roles and employee title
Assign remediation tasks to system owners
  • Built-in remediation workflow for reviewers to request access changes and for admin to view and manage requests
  • Optional task tracker integration to create tickets for any access changes and provide visibility to the status of tickets and remediation
Verify changes to access
  • Focused view of accounts flagged for access changes for easy tracking and management
  • Automated evidence of remediation completion displayed for integrated systems
  • Manual evidence of remediation can be uploaded for non-integrated systems
Report and re-evaluate results
  • Auditor can log into Vanta to see history of all completed access reviews
  • Internals can see status of reviews in progress and also historical review detail
FEATURED VANTA RESOURCE

The ultimate guide to scaling your compliance program

Learn how to scale, manage, and optimize alongside your business goals.