BlogProduct updates
April 7, 2025

New in Vanta | April 2025

Written by
Vicki Robertson
Reviewed by
No items found.

Accelerating security solutions for small businesses 

Tagore offers strategic services to small businesses. 

A partnership that can scale 

Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate.

Standing out from competitors

Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

This past month, the Vanta team launched new features to help you: 

  • Demonstrate early commitment to security with a Vanta engagement letter
  • Customize document approval workflows to ensure you’re meeting requirements
  • Establish and maintain policies with new policy management improvements
  • Automate security questionnaires in Word Doc and PDF formats
  • Centralize key data and automate workflows with Halo Security and Panoptic Scans integrations 

Demonstrate early commitment to security with a Vanta engagement letter 

As startups establish product-market fit and pursue larger customers, they experience increased buyer expectations of their security and compliance posture. Often, these buyers ask for proof of security in the form of a SOC 2 report or ISO 27001 certification. Vanta has long been helping startups become and stay compliant with SOC 2 and ISO 27001, at every phase of growth and level of urgency. However, startups want to appease buyer expectations even while working towards an official compliance audit.

For startups pursuing SOC 2 or ISO 27001, Vanta now offers an official engagement letter that demonstrates your commitment to continuous monitoring and your progress towards audit, providing a way to satisfy buyer expectations earlier in the process. The engagement letter highlights your implementation of continuous monitoring through Vanta, your upcoming audit engagement (if applicable), and your public Trust Center, where you can provide transparency into your security posture, policies, and more.

Vanta customers that have not yet conducted a SOC 2 or ISO 27001 audit can view their engagement letter within the Compliance Roadmap.

Create document approval workflows to ensure you’re meeting requirements 

As companies grow and become more complex, they face challenges in ensuring that the documentation they’re gathering will meet the requirements of their frameworks. While Vanta tracks document uploads, the document owners may lack the necessary compliance expertise, making it difficult for them to  determine the evidence needed to meet the requirement.

To help our customers ensure their evidence is sufficient and to identify potential problems before an audit, Vanta now supports an optional document approval workflow. If activated, you can designate an approver for documents to confirm sufficient evidence has been provided to meet framework requirements. The approver will be notified once files are uploaded so that they know when action is required on their part. You can configure the approval process to include multiple approvers, including the option to create a multi-step approval chain.

Document approvals are available on the Growth package and above. Learn more here.

Establish and maintain policies with policy management improvements 

Clearly documenting policies and ensuring that relevant employees have reviewed and accepted them are essential to a company’s security and compliance program. We have introduced a collection of improvements for policy management to make it even easier to establish and maintain policies in Vanta. 

- Add controls from Policies page: You can now add controls to a policy directly from the Policies page. This enables a more efficient workflow when you set up a new policy or update an existing one.

- Import version history of policies: If you have existing policies that have already been approved, you can now set an approval date in the past and indicate that the policy does not need to go through the approval process at this time. The annual recurrence will be based on the date of approval. This ensures that your policies are approved or renewed in accordance with your existing internal cadence.

- Permanent link for last approved version of policy: You can now generate a permanent link that will always direct to the latest approved version of a policy. This means that if you want to link to policies from other internal systems, you will no longer need to make updates to the link when a policy is updated. 

These capabilities are available to customers in all packages. Learn more about policy management in Vanta here.

Automate security questionnaires in Word Doc and PDF formats

Security questionnaires today come in all shapes and sizes, and security and compliance teams are expected to respond to questionnaires promptly while ensuring they return questionnaires to customers in the same format they were received. For organizations to stay competitive and keep their sales process humming along, they need to find efficient ways to complete questionnaires, no matter the format.

Vanta now automates questionnaires in DOCX and PDF formats. This is in addition to the automation for spreadsheet-based questionnaires we already support. Security and compliance teams can now fully automate and collaborate on responses in all these formats, and return the questionnaires back to their customers in the same format they were received. In the coming months, Vanta will expand support beyond our browser extension with full end-to-end automation of portal-based questionnaires. 

Document automation is now in open preview for all customers with Questionnaire Automation. Learn more here


Centralize key data and automate workflows with Halo Security and Panoptic Scans integrations 

This month, we introduced two new integrations with Halo Security and Panoptic Scans to centralize key data and automate additional workflows. Users leveraging Halo Security for external attack surface management can ingest vulnerability scan results into Vanta, and continuously monitor adherence to SLAs based on vulnerability criticality. Users leveraging Panoptic Scans for scheduled, automated vulnerability scans can easily upload results into Vanta through the integration.

Explore all our integrations or tell us about others you’d like to see.

Try it for yourself!

Log in to your Vanta account to try out these new features today. If you’re not a Vanta customer and want to learn more, request a demo.

As always, we welcome your feedback. Let us know what you think by reaching out to your Customer Success Manager and stay in the loop on Vanta news on LinkedIn.

Access Review Stage Content / Functionality
Across all stages
  • Easily create and save a new access review at a point in time
  • View detailed audit evidence of historical access reviews
Setup access review procedures
  • Define a global access review procedure that stakeholders can follow, ensuring consistency and mitigation of human error in reviews
  • Set your access review frequency (monthly, quarterly, etc.) and working period/deadlines
Consolidate account access data from systems
  • Integrate systems using dozens of pre-built integrations, or “connectors”. System account and HRIS data is pulled into Vanta.
  • Upcoming integrations include Zoom and Intercom (account access), and Personio (HRIS)
  • Upload access files from non-integrated systems
  • View and select systems in-scope for the review
Review, approve, and deny user access
  • Select the appropriate systems reviewer and due date
  • Get automatic notifications and reminders to systems reviewer of deadlines
  • Automatic flagging of “risky” employee accounts that have been terminated or switched departments
  • Intuitive interface to see all accounts with access, account accept/deny buttons, and notes section
  • Track progress of individual systems access reviews and see accounts that need to be removed or have access modified
  • Bulk sort, filter, and alter accounts based on account roles and employee title
Assign remediation tasks to system owners
  • Built-in remediation workflow for reviewers to request access changes and for admin to view and manage requests
  • Optional task tracker integration to create tickets for any access changes and provide visibility to the status of tickets and remediation
Verify changes to access
  • Focused view of accounts flagged for access changes for easy tracking and management
  • Automated evidence of remediation completion displayed for integrated systems
  • Manual evidence of remediation can be uploaded for non-integrated systems
Report and re-evaluate results
  • Auditor can log into Vanta to see history of all completed access reviews
  • Internals can see status of reviews in progress and also historical review detail
FEATURED VANTA RESOURCE

The ultimate guide to scaling your compliance program

Learn how to scale, manage, and optimize alongside your business goals.