Vanta
BlogProduct updates
December 12, 2025

New in Vanta | December 2025

Written by
Vicki Robertson
Reviewed by
No items found.

Accelerating security solutions for small businesses 

Tagore offers strategic services to small businesses. 

A partnership that can scale 

Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate.

Standing out from competitors

Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

This past month, the Vanta team launched new features to help you: 

  • Generate and edit policies in seconds with the Vanta AI Agent 
  • Give each team a structured space to manage risk with multiple risk registers
  • Create data inventories and easily manage ROPAs
  • Capture information with vendor intake forms to accelerate assessments
  • Get answers to security and compliance questions in Slack 
  • Unlock greater visibility and deeper automation with new and enhanced integrations

Generate and edit policies in seconds with the Vanta AI Agent 

Creating tailored policies has traditionally demanded significant time and specialized expertise. Even with templates, teams often had to research requirements, interpret frameworks, and manually customize each document. Now, the Vanta AI Agent does that work for you. Simply ask the agent to draft a policy, and it produces a complete, editable, audit-ready document in seconds, all built on your company’s information and aligned to specific frameworks. Each policy draws from Vanta’s best-in-class expertise, informed by insights from more than 20,000 audits and 14,000 customers.

The agent also updates and refines policies with simple prompts. Customers can ask, “Can you resolve this contradiction?” or “Please update this policy to include X.” The agent will propose precise edits for review and then apply the final changes to one policy or cascade edits across multiple policies in your program.

Policy generation and editing is available to all customers. Learn more about the agent here

Give each team a structured space to manage risk with multiple risk registers

As organizations expand, risk management often becomes fragmented—each function tracks risks in its own spreadsheets or tools, using different definitions and levels of rigor. This makes ownership unclear, reporting reactive, and leadership visibility inconsistent. Multiple risk registers in Vanta solve this by giving every team its own structured space to manage the risks they know best, while Vanta applies a consistent scoring model and framework across all registers. Legal can focus on regulatory obligations, IT on vulnerabilities, finance on exposures, and HR on people-related risks without sacrificing standardization or a unified view of risk. This brings clarity, accountability, and proactive oversight to even the most distributed programs, ensuring risks are tracked and governed the way your business actually operates.

Multiple risk registers is now available and included as part of Vanta’s Enterprise Risk Management offering. Learn more here

Create data inventories and easily manage ROPAs

Organizations today struggle to understand what data they hold, where it lives, and how it’s being used. Yet, regulators increasingly expect complete, accurate, and always-up-to-date documentation. Manual spreadsheets can’t keep pace with the complexity or change, leaving privacy teams overwhelmed and exposed. Vanta is launching a new way for privacy teams to keep inventories of their internal data and their processing activities, streamlining the complex and often manual process of identifying data within an organization, and creating and maintaining their record of processing activities (ROPAs).

By leveraging the data that organizations have in Vanta already, teams can more easily develop data inventories that track the personal data in their business. They can create, export, and share ROPAs for compliance and regulatory reviews, all within the Vanta platform. This empowers privacy teams and compliance officers to significantly reduce effort, improve accuracy, and ensure adherence to global privacy regulations like GDPR and CCPA.

Data inventory is now available for customers with a privacy framework (GDPR, USDP, CCPA, ISO 27701, ISO 27018). Learn more here

Capture information with vendor intake forms to accelerate assessments

Vendor assessments often begin the moment a business unit identifies a need and requests a new vendor. However, security teams rarely receive the critical context they need up front, like how the vendor will be used or what data it will handle. Without it, assessments stall, workflows become inconsistent, and the business feels unnecessary friction. 

Vanta’s new vendor intake form offers guided, customizable workflows that capture the right vendor information up front to accelerate every assessment. It automatically classifies inherent risk so teams can prioritize with confidence, and gives employees a simple self-serve way to request new vendors without relying on procurement tools or engineering work. It’s a streamlined, scalable intake experience that strengthens the process, eliminates delays, and keeps everyone on the same page.

The vendor intake form is available with the TPRM add-on. Learn more about third-party risk management here

Get answers to security and compliance questions in Slack 

Employees across an organization often have quick, ad-hoc questions about security and compliance, whether they’re responding to customers and prospects or seeking clarity on internal policies for their own work. For example: “Can I use my personal laptop for work?” or “What’s the policy for taking my laptop abroad?” Today, these questions surface in scattered, unstructured ways, whether it be in Slack threads, emails, or ticketing systems. This creates delays in getting accurate answers, forces SMEs to repeat the same guidance, reduces visibility into common questions, and introduces risk when employees rely on outdated information.

We’ve expanded our Slack integration to solve this. Employees can now ask one-off security and compliance questions directly in Slack, and the feature automatically pulls answers from the organization’s knowledge base in Vanta. This ensures responses are accurate, consistent, and aligned to company-approved information, reducing the risk of sharing outdated information while improving efficiency for both internal employees and GRC teams alike. 

This feature is now in preview and will be available to all Questionnaire Automation customers in January. Learn more here

Unlock greater visibility and deeper automation with new and enhanced integrations

Vanta has added many new integrations to the platform, and has made significant enhancements to existing integrations, all in an effort to deliver more automation and time savings to customers. Five new HRIS integrations sync account data and support automated onboarding and offboarding workflows, to simplify access reviews and support compliance requirements—7 Shifts, CyberArk, ISolved, Kenjo, and Square Payroll are now supported. In addition, Vanta has introduced 12 new user access integrations to centralize visibility into sensitive account access. Capsule, CATS, Clockwork Recruiting, Close, Copper, Insightly, Comeet, JobAdder, Jobvite, SmartRecruiters, Teamtailor, and Breezy are now supported.

Vanta has delivered significant enhancements to existing integrations, unlocking greater visibility and deeper automation:

  • AWS Bedrock support: Vanta has added support for AWS Bedrock as a resource, pulling AI models in use into the platform for visibility. This adds a new tab on the Assets > Inventory page in Vanta showing the model(s) in use, detection and last use dates, total uses over the last 90 days, and more.
  • Simplified connection flows for GCP and Microsoft Azure: Vanta has streamlined the connection setup process for GCP and Azure by adding clear guidance and recommended paths, and pre-built scripts to generate required policies and roles.

These integrations are available to all Vanta customers. 

Explore all our integrations or tell us about others you’d like to see.

Try it for yourself!

Log in to your Vanta account to try out these new features today. If you’re not a Vanta customer and want to learn more, request a demo.

As always, we welcome your feedback. Let us know what you think by reaching out to your Customer Success Manager and stay in the loop on Vanta news on LinkedIn.

Access Review Stage Content / Functionality
Across all stages
  • Easily create and save a new access review at a point in time
  • View detailed audit evidence of historical access reviews
Setup access review procedures
  • Define a global access review procedure that stakeholders can follow, ensuring consistency and mitigation of human error in reviews
  • Set your access review frequency (monthly, quarterly, etc.) and working period/deadlines
Consolidate account access data from systems
  • Integrate systems using dozens of pre-built integrations, or “connectors”. System account and HRIS data is pulled into Vanta.
  • Upcoming integrations include Zoom and Intercom (account access), and Personio (HRIS)
  • Upload access files from non-integrated systems
  • View and select systems in-scope for the review
Review, approve, and deny user access
  • Select the appropriate systems reviewer and due date
  • Get automatic notifications and reminders to systems reviewer of deadlines
  • Automatic flagging of “risky” employee accounts that have been terminated or switched departments
  • Intuitive interface to see all accounts with access, account accept/deny buttons, and notes section
  • Track progress of individual systems access reviews and see accounts that need to be removed or have access modified
  • Bulk sort, filter, and alter accounts based on account roles and employee title
Assign remediation tasks to system owners
  • Built-in remediation workflow for reviewers to request access changes and for admin to view and manage requests
  • Optional task tracker integration to create tickets for any access changes and provide visibility to the status of tickets and remediation
Verify changes to access
  • Focused view of accounts flagged for access changes for easy tracking and management
  • Automated evidence of remediation completion displayed for integrated systems
  • Manual evidence of remediation can be uploaded for non-integrated systems
Report and re-evaluate results
  • Auditor can log into Vanta to see history of all completed access reviews
  • Internals can see status of reviews in progress and also historical review detail
FEATURED VANTA RESOURCE

The ultimate guide to scaling your compliance program

Learn how to scale, manage, and optimize alongside your business goals.