A purple and white icon with a gear wheel on it.
BlogProduct updates
July 25, 2023

Connect any app to Vanta with Private Integrations

Written by
Chris Morris
Staff Product Manager
Reviewed by
No items found.

Accelerating security solutions for small businesses 

Tagore offers strategic services to small businesses. 

A partnership that can scale 

Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate.

Standing out from competitors

Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

Update, 12/5/2023: Private Integrations are now generally available in all plans for all customers to help you automate compliance and continuously monitor your security. Learn more here.

We’re thrilled to announce the launch of Private Integrations today, enabling Vanta customers to easily connect their in-house or third-party applications to Vanta’s Trust Management platform. With Private Integrations, in-house systems that need compliance controls can now be managed with the same level of automation as any third-party application available in Vanta’s integration directory

Customers can also build an integration to any  third-party application, even if they’re not available in Vanta’s integration directory. Private Integrations are only available to the account in which they are built, meaning your integration and data are secure and inaccessible to other Vanta customers.

Collecting evidence from internal tools

A lot of companies build internal tools like custom CRMs, ticketing systems, or workflow tools to improve their operations. Building them in-house is often a necessity given the highly custom nature of their requirements. Quite often, these tools touch sensitive customer and employee information, making it critical to collect evidence from them in the most secure manner.

No more manual data uploads

Before the launch of Private Integrations, collecting evidence from internal tools or third-party applications was a lot harder than doing so using applications supported by the Vanta integrations directory. Security teams instead had to manually export the right information from their internal tools and upload it to Vanta to provide evidence for each control. In addition to being time consuming and error prone, it also meant that these applications could not benefit from Vanta’s continuous monitoring capabilities. 

How Private Integrations work

Security, transparency and customizability is at the heart of Private Integrations. Implementing  a Private Integration involves setting up the integration in the Vanta app, and writing custom code to extract and handle the integration data in a way that best suits your organization’s needs.

Setting up the integration

Setting up the integration in Vanta only takes a few moments and is handled mostly by the in-app UI:

1. Create an application in the Vanta Developer Console

2. Authorize using OAuth. This involves obtaining the access token to be used in the next step.

3. Return to the Developer Console and use the UI to create and define the resource(s) or document(s) you’d like to send.

After you've completed these steps, you’re ready to sync resources over to Vanta and take advantage of the platform’s continuous monitoring capabilities. To sync, you’ll need to implement a periodic job to extract the resources from the application you’d like to integrate and sync them over to Vanta. This is highly dependent on the application at hand, but the custom nature of this step ensures that the data is handled per your organization’s needs. 

You can read more about the process and API in our documentation.

Supported resources

At launch, we’ll support the integration of the following resources into Vanta: 

  • User Access information
  • Mac and Windows computer information
  • Security Training information
  • Vulnerabilities
  • Background Check information
  • Application secrets
  • Security tasks

We’ll be expanding this list over time.


Our approach to integrations

At Vanta, we’re committed to eliminating the manual and repetitive work involved in staying compliant and demonstrating security to your customers and stakeholders. Evidence collection is one of the most time consuming activities in that list and our Integration platform aims to eliminate as much of this work as possible.

In the past year we’ve added over 189 integrations to our directory, averaging 27 integrations every month with many more to come. Along with the Connectors API, Private Integrations further improves our ability to support a diverse array of integrations. 

Get started with Private Integrations

Private Integrations are available in all Vanta plans for all customers to help you automate compliance and continuously monitor your security. Reach out to our team today to learn more!

Access Review Stage Content / Functionality
Across all stages
  • Easily create and save a new access review at a point in time
  • View detailed audit evidence of historical access reviews
Setup access review procedures
  • Define a global access review procedure that stakeholders can follow, ensuring consistency and mitigation of human error in reviews
  • Set your access review frequency (monthly, quarterly, etc.) and working period/deadlines
Consolidate account access data from systems
  • Integrate systems using dozens of pre-built integrations, or “connectors”. System account and HRIS data is pulled into Vanta.
  • Upcoming integrations include Zoom and Intercom (account access), and Personio (HRIS)
  • Upload access files from non-integrated systems
  • View and select systems in-scope for the review
Review, approve, and deny user access
  • Select the appropriate systems reviewer and due date
  • Get automatic notifications and reminders to systems reviewer of deadlines
  • Automatic flagging of “risky” employee accounts that have been terminated or switched departments
  • Intuitive interface to see all accounts with access, account accept/deny buttons, and notes section
  • Track progress of individual systems access reviews and see accounts that need to be removed or have access modified
  • Bulk sort, filter, and alter accounts based on account roles and employee title
Assign remediation tasks to system owners
  • Built-in remediation workflow for reviewers to request access changes and for admin to view and manage requests
  • Optional task tracker integration to create tickets for any access changes and provide visibility to the status of tickets and remediation
Verify changes to access
  • Focused view of accounts flagged for access changes for easy tracking and management
  • Automated evidence of remediation completion displayed for integrated systems
  • Manual evidence of remediation can be uploaded for non-integrated systems
Report and re-evaluate results
  • Auditor can log into Vanta to see history of all completed access reviews
  • Internals can see status of reviews in progress and also historical review detail
FEATURED VANTA RESOURCE

The ultimate guide to scaling your compliance program

Learn how to scale, manage, and optimize alongside your business goals.