BlogProduct updates
July 21, 2025

New in Vanta | July 2025

Written by
Vicki Robertson
Reviewed by
No items found.

Accelerating security solutions for small businesses 

Tagore offers strategic services to small businesses. 

A partnership that can scale 

Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate.

Standing out from competitors

Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

 This past month, the Vanta team launched new features to help you: 

  • Supercharge your GRC team with the new Vanta AI Agent
  • Identify threats proactively and take action with vendor continuous monitoring
  • Seamlessly transition to new framework versions with framework version manager
  • Get visibility into evidence overlap across frameworks
  • Power deeper automations across cloud, code, and communication platforms with new and updated integrations 

Supercharge your GRC teams with the new Vanta AI Agent

We’re excited to introduce the Vanta AI Agent—built to supercharge GRC teams. With a deep understanding of your program, the Vanta AI Agent proactively guides you through key workflows and takes action on your behalf, all while keeping you firmly in control. It continuously scans your program for inconsistencies and issues that are easy to overlook and handles the most tedious, repetitive tasks to enhance the overall quality of your program, and maximize your impact.

Starting with policy management and evidence evaluation, the Vanta AI Agent: 

  • Extracts key details from policies like titles, version history, and SLAs to automate policy uploads in bulk (available in the coming weeks on the Growth package and above).
  • Recommends relevant controls for each uploaded policy, streamlining the mapping process (available today on the Growth package and above).
  • Generates policy change summaries to simplify annual review updates and enable seamless approvals (available today on the Growth package and above).
  • Detects misalignments between documented SLAs and actual practices, and then suggests quick fixes (available today on the Growth package and above).
  • Answers questions about your policies so you can quickly find the information you need (available in the coming weeks on the Core package and above).
  • Checks evidence against audit requirements and flags any issues (available in the coming weeks on the Core package and above). 

To learn more about the Vanta AI Agent, check out this blog post

Identify threats proactively and take action with vendor continuous monitoring 

Vanta has acquired Riskey, a leader in real-time third-party risk intelligence. Riskey developed best-in-class capabilities for monitoring third- and fourth-party vulnerabilities including breaches, misconfigurations, leaked credentials, and subprocessor exposure. Their AI-powered scoring engine intelligently categorizes findings to reduce noise and surface what truly matters.

Riskey’s technology is now integrated into Vanta’s Vendor Risk Management capabilities, enabling customers to enhance traditional first-party reviews with real-time third-party insights. This integration unlocks continuous vendor monitoring—allowing security and compliance teams to proactively detect threats, take timely action, and safeguard vital business assets.

Learn more about vendor continuous monitoring in this blog post. 

Seamlessly transition to new framework versions with framework version manager

Framework updates shouldn’t slow you down or leave you in the dark. With Vanta’s new framework version manager, staying current is simpler than ever. This new experience helps you clearly understand what’s changed, preview side-by-side differences, and seamlessly upgrade while preserving your existing work. Whether you’re transitioning from ISO 27001:2013 to 2022 or planning ahead for a PCI update, Vanta highlights what’s new, imports your customizations, and walks you through the upgrade with clarity and control. No more audit disruption, redundant work, or guessing what’s different.

Framework version manager will be available to all customers by the end of July. 

Get visibility into evidence overlap across frameworks

When expanding into a new compliance framework, one of the biggest unknowns is how much of your existing work carries over. Framework evidence overlap, Vanta’s newest update to framework explorer, brings clarity to that question. You can now see a clear, percentage-based breakdown of control and evidence overlap across all of your frameworks. This drill-down experience highlights what’s already been completed, what’s net-new, and what action is required. It eliminates guesswork, streamlines planning, and accelerates framework adoption by showing exactly where you can reuse work and where to focus next. Whether you're scaling to meet customer demands or preparing for global expansion, Vanta helps you grow smarter. 

Framework evidence overlap will be available to all customers by the end of July. 

Power deeper automations across cloud, code, and communication platforms with new and updated integrations

This month, Vanta released one new integration with Oracle Cloud Infrastructure (OCI). Vanta’s OCI integration enables users to continuously monitor their cloud infrastructure for security risks and compliance requirements, and automatically collect evidence for audit. Vanta automates over 20 tests with OCI, tracking key requirements like data encryption, proper versioning, limited access, and more. 

Vanta also released four key integration updates:

  • Two-way Slack app interactions for access requests - your employees can submit access requests and receive notifications on request status within Slack, and admins can approve/deny requests and mark them as provisioned within Slack. Learn more about Vanta’s access requests capability, now generally available to customers on the Plus package or above.
  • GitHub rulesets support - Vanta can now detect organizational rulesets and pull in their related configuration information, using the GitHub integration. This allows for more accurate results within Vanta’s branch protection automated tests, enabling deeper automation for organizations that leverage rulesets within GitHub.
  • GitLab self-managed v17.x and v18.x support - Vanta now supports version 17 and 18 of GitLab’s self-managed console, allowing users to easily leverage the latest versions of GitLab while maintaining their continuous monitoring within Vanta.
  • Azure DevOps support for code changes tracking - Vanta users leveraging Azure DevOps can now see PRs automatically within the code changes page, so you can easily identify code changes that are out of compliance. The code changes view is available to Vanta customers on the Growth plan or above, in preview.

Explore all our integrations or tell us about others you’d like to see.

Try it for yourself!

Log in to your Vanta account to try out these new features today. If you’re not a Vanta customer and want to learn more, request a demo.

As always, we welcome your feedback. Let us know what you think by reaching out to your Customer Success Manager and stay in the loop on Vanta news on LinkedIn.

Access Review Stage Content / Functionality
Across all stages
  • Easily create and save a new access review at a point in time
  • View detailed audit evidence of historical access reviews
Setup access review procedures
  • Define a global access review procedure that stakeholders can follow, ensuring consistency and mitigation of human error in reviews
  • Set your access review frequency (monthly, quarterly, etc.) and working period/deadlines
Consolidate account access data from systems
  • Integrate systems using dozens of pre-built integrations, or “connectors”. System account and HRIS data is pulled into Vanta.
  • Upcoming integrations include Zoom and Intercom (account access), and Personio (HRIS)
  • Upload access files from non-integrated systems
  • View and select systems in-scope for the review
Review, approve, and deny user access
  • Select the appropriate systems reviewer and due date
  • Get automatic notifications and reminders to systems reviewer of deadlines
  • Automatic flagging of “risky” employee accounts that have been terminated or switched departments
  • Intuitive interface to see all accounts with access, account accept/deny buttons, and notes section
  • Track progress of individual systems access reviews and see accounts that need to be removed or have access modified
  • Bulk sort, filter, and alter accounts based on account roles and employee title
Assign remediation tasks to system owners
  • Built-in remediation workflow for reviewers to request access changes and for admin to view and manage requests
  • Optional task tracker integration to create tickets for any access changes and provide visibility to the status of tickets and remediation
Verify changes to access
  • Focused view of accounts flagged for access changes for easy tracking and management
  • Automated evidence of remediation completion displayed for integrated systems
  • Manual evidence of remediation can be uploaded for non-integrated systems
Report and re-evaluate results
  • Auditor can log into Vanta to see history of all completed access reviews
  • Internals can see status of reviews in progress and also historical review detail
FEATURED VANTA RESOURCE

The ultimate guide to scaling your compliance program

Learn how to scale, manage, and optimize alongside your business goals.