All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Vanta's software continuously checks a company's cloud accounts, laptops, and staff access against standards such as SOC 2 and ISO 27001, then hands the auditors the evidence. Its published references include a lead compliance manager at Snyk and a director of customer assurance at GitHub. Fortune reports it crossed $300 million in recurring revenue in April 2026 across more than 16,000 customers. Wellington Management, which led a new $150 million round in 2025, told Forbes that Vanta had not touched the $150 million it raised the year before. In 2025 it published its own root cause analysis of a bug that exposed customer data to other customers. Its AI Governance product still asks visitors to join a waitlist, so the AI-agent discovery it describes is not yet generally available.
| Description | Vanta sells a platform that gathers the evidence a compliance audit requires and continuously monitors a customer's systems so the controls behind that evidence stay in place. | [f1] |
|---|---|---|
| Founded | 2018 | [f2] |
| HQ | San Francisco, California, United States | [f2] |
| Funding | $500M total | [f3] |
| Latest funding | $150M Series D led by Wellington Management at a $4.15B valuation, July 2025 | [f2] |
| Product | What it does |
|---|---|
| Automated Compliance | Continuously tests a customer's systems against a chosen compliance framework and assembles the evidence an auditor will ask for. |
| Risk Management | Central register for a customer's risks, with automated workflow for assigning, tracking, and closing out treatment tasks. |
| Third Party Risk Management | Discovers a customer's vendors, runs security assessments against them, and monitors third-party risk on a continuing basis. |
| Trust Center | Customer-facing page that publishes a company's security posture and documents so its prospects can review them without sending a questionnaire. |
| Personnel and Access | Tracks staff onboarding, offboarding, policy acceptance, and training, and runs periodic reviews of who holds access to which systems. |
| Vanta AI Agent | Assistant inside the platform that drafts policies, answers security questionnaires, and flags gaps in a customer's compliance program. |
| AI Governance | Waitlisted product that maps AI agents across developer laptops, production code, and vendor platforms and records what each one can reach. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Vanta Automated Compliance continuously tests a customer's applications, devices, and employee accounts against framework requirements, and Personnel and Access records who holds access to which systems. These capabilities are mapped to the Cyber Defense Matrix. [f4]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Forbes describes the spreadsheet-and-screenshot process Vanta was built to replace, and Forrester's own 2026 category write-up independently says many governance, risk, and compliance platforms still demand too much manual data entry. No non-vendor source in the reviewed record quantifies that pain, which leaves the magnitude on Vanta's own figures and an IDC study named for Vanta. [s20, s23, s2] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | Fast Company reports more than 400 integrations and quotes Vanta's chief product officer on over 1,400 continuously running tests, its security page details encryption, key management, and its testing pipeline, and the FedRAMP Marketplace records Vanta Government Cloud as certified under the 20x program at Class C. Its trust center lists a February 2026 penetration test summary with retest. No third-party benchmark in the reviewed record compares that depth against rivals. [s21, s4, s25, s11, s15] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | Fortune reports the company's own account that customer growth accelerated in each of the past four quarters to roughly 60% year over year, and Forrester published a governance, risk, and compliance platforms evaluation in May 2026. The enabler is employee AI adoption outrunning security review, which Fast Company reported in June 2026 as the problem Vanta's risk agent addresses. Forrester's own write-up says AI in this category delivers minimal value today, which caps the timing case. [s19, s23, s21] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | Vanta's about page records a chief product officer who ran GitHub Actions, Codespaces, npm, and Packages and a chief revenue officer from Twilio's mid-market sales organization, and Forbes places Cacioppo on its list of America's Richest Self-Made Women. The reviewed biographies record no prior security exit for either founder, and Forbes reports the co-founder is no longer involved. [s3, s20, s21] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 5/5 | Fortune and Fast Company both report $300 million in recurring revenue as of April 2026 across more than 16,000 customers, and Fortune names Snowflake, Atlassian, Duolingo, Ramp, Cursor, and Harvey. A compliance manager at Snyk and a customer-assurance director at GitHub speak for the product in published accounts. [s19, s21, s26, s6] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 4/5 | Fast Company reports Vanta reached $10 million in revenue without having taken on any venture funding, and later recorded $300 million in recurring revenue. The lead investor of the 2025 round told Forbes that Vanta had not touched the $150 million raised a year earlier or most of the 2023 round. Against roughly $500 million raised, third-party-reported revenue confirms output per dollar, and no margin or cash-generation figure appears in the reviewed record. [s21, s20, s19] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Forrester runs a named governance, risk, and compliance platforms evaluation and Fortune places Vanta in that field. The Leader placement is known only from Vanta's own announcement and those of other vendors, and outside Vanta's own pages the reviewed record carries its lead marketing term, Agentic Trust Platform, only in a rewritten product announcement. [s23, s19, s13, s28] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | A FedRAMP-certified government cloud package, an audit-partner arrangement, and a catalog of more than 400 available integrations create friction a platform vendor would have to work through. None of that is beyond a funded rival, and Forrester's write-up describes a category whose vendors are all moving toward the same automation. [s25, s2, s21, s23] |
Vanta sells against the spreadsheet-and-screenshot version of compliance. Forbes describes the process the company set out to replace as one that ran largely through spreadsheets and screenshots collected in folders and shown to accountants and auditors.
An independent read of the tools meant to fix that reaches a matching conclusion. Forrester's write-up of its 2026 governance, risk, and compliance platforms evaluation says many platforms in the category still require too much manual data entry, offer only basic workflow automation, and are too complex, unwieldy, and expensive for the function they perform.
The demand Vanta points at now is AI adoption inside its customers. Fortune reports that Vanta's own data, drawn from its third-party risk product, found 70% of companies have tools employees adopted without a security review. Fast Company reports Vanta's finding that companies review only 7% of such vendors while Vanta rates 30% of them critical or high risk. [s20, s23, s19, s21]
Vanta's platform reads a customer's own systems and turns what it finds into audit evidence. Fast Company reports more than 400 integrations feeding it and quotes chief product officer Jeremy Epling saying over 1,400 tests continuously assess the security controls in a customer's organization.
The products around that core cover the rest of a compliance program. Vanta sells a risk register with treatment workflow, third-party vendor assessment, staff onboarding and access reviews, and a customer-facing Trust Center that publishes a company's security posture to its own prospects.
The AI work divides between what ships and what does not. Help Net Security records an agent launched in July 2025 that automates evidence collection and policy management, Vanta's chief product officer writes that 20 agentic workflows shipped last year against a target above 90 for 2026, and the separate AI Governance product, which maps AI agents across laptops and production code, asks visitors to join a waitlist. [s21, s7, s16, s8, s17, s9, s26, s13, s10]
Vanta's closest named rival is smaller on the one figure both are measured by. Forbes calls Drata Vanta's biggest startup rival and reports it crossed $100 million in recurring revenue in 2025, against the $220 million Forbes estimated for Vanta in the same article.
The analyst field is wider than the startup one. Forrester evaluated 12 vendors in its 2026 governance, risk, and compliance platforms Wave, LogicGate's announcement says four of them were named Leaders, and Diligent's announcement claims one of those places. Vanta's own post claims another, on first inclusion.
What that report says Vanta lacks is the risk depth Forrester says the category is moving toward. Vanta's chief product officer records three cautions from his own vendor profile: enterprise risk management still developing, risk quantification and scenario modeling not yet natively supported, and a vision the report called more compliance-oriented than risk-oriented. [s20, s23, s28, s27, s13]
Vanta's revenue figures come from reporters rather than from the company alone. Fortune reported in April 2026 that it crossed $300 million in recurring revenue, roughly triple two years earlier, and Fast Company recorded the same figure as up from $200 million nine months before.
The customer list is named and most of the titles are security and compliance roles. Fortune names Snowflake, Atlassian, Duolingo, Ramp, Cursor, and Harvey among more than 16,000 customers, Help Net Security quotes a lead compliance manager at Snyk, and Vanta's own case study quotes a director of customer assurance at GitHub.
The value those references describe is revenue rather than risk. Vanta's customer story on GitHub records more than 300 security questionnaires arriving after the Copilot launch and 93% of inbound questionnaires automated in six months, and the Trust Center page frames the product as turning security into a revenue driver. [s19, s21, s5, s26, s6, s9]
Vanta's founders came from Dropbox rather than from security. Fast Company records that Christina Cacioppo was once a product manager overseeing Dropbox's document-editing tool Paper, and that she founded Vanta with a Dropbox colleague, Erik Goldman, in Y Combinator's Winter 2018 batch. Forbes reports Goldman is no longer involved with the company.
The executives hired since bring enterprise product and sales records of their own. Vanta's about page records that chief product officer Jeremy Epling joined from GitHub, where he was VP of Product for Actions, Codespaces, npm, and Packages, and that chief revenue officer Stevie Case joined from Twilio after more than fifteen years in sales and business development.
Scale is now the management problem. Fortune reports Cacioppo oversees roughly 1,000 employees, and Vanta's about page records a remote-first company with offices in San Francisco, New York, Sydney, Dublin, and London. [s21, s20, s3, s19, s15]
Vanta holds the credentials it sells. Its security page records a SOC 2 Type II attestation and an ISO 27001 certification, and its trust center lists ISO/IEC 42001, a February 2026 penetration test summary including retest, and a certificate of liability insurance.
The federal record goes further than a badge. The FedRAMP Marketplace lists Vanta Government Cloud as FedRAMP Certified at Class C under package ID FR2525556241XM, in ongoing certification, and files it under cybersecurity and risk management.
The failure is on the record too. TechCrunch reported in June 2025 that a Vanta code change exposed customer data to other customers, affecting fewer than 4% of customers by the company's account, and Vanta published a root cause analysis naming the removed domain ID filter and stating that existing tests and code review did not detect the bug before deployment. That analysis records the incorrect data surfacing in its compliance monitoring, personnel management, access review, and vulnerability management products, so the failure reached the outputs customers buy the platform for. [s4, s15, s25, s22, s14]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Drata | competes with | Forbes calls it Vanta's biggest startup rival and reports it crossed $100 million in recurring revenue in 2025. | |
| Diligent | competes with | Diligent's own announcement names it a Leader in the same Forrester governance, risk, and compliance platforms evaluation Vanta's announcement names. | |
| LogicGate | competes with | LogicGate's own announcement places it among four Leaders in the Forrester governance, risk, and compliance platforms evaluation Vanta also announces. |
Add analyzed competitors to compare them side by side with Vanta.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
Vanta has one asset a rival would have to obtain from a regulator. The federal marketplace records Vanta Government Cloud as certified at Class C, and a federal buyer cannot swap that for an unauthorized product. Its cross-customer vendor risk data is a head start rather than a second such asset, and Fortune reported shadow-AI figures drawn from its third-party risk product. Everything else is reproducible by a funded rival. The connectors, the continuous tests, and the agent that drafts policies are engineering a well-capitalized competitor can staff. A customer that leaves has to reconnect its systems to a replacement and re-point its trust page, and no reviewed source describes what that migration costs.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Vanta delivers software that the customer's own team operates, and the attestation comes from third-party auditors rather than from Vanta. Forbes describes auditors going through the data Vanta compiles and certifying the company, which puts the delivered artifact at the software-product level. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | The cited record documents connections to a customer's cloud, code, and identity systems to rebuild and a customer-facing trust page to re-point, which is the ordinary integration and workflow friction of leaving. It documents no state that cannot be moved and does not size the migration, so the switching mechanism is documented and the exit is not sized. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 2/3 | The FedRAMP Marketplace records Vanta Government Cloud as certified at Class C, so a federal buyer cannot substitute an unauthorized alternative for that deployment. The certification is a regulator-mediated authorization a determined operator can pursue, and the reviewed record shows no liability Vanta retains for a customer's own compliance outcome. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 2/3 | The engineering is integration breadth rather than algorithmic depth. Fast Company records more than 400 connectors and over 1,400 tests continuously reading customer systems, and Forbes reports Vanta refines its AI on pre-existing large language models plus labeled and synthetic data rather than training a model of its own on customer data. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | The evidenced buyers include regulated enterprises and government. The FedRAMP Marketplace records a certified government cloud offering, Vanta's government page addresses federal agencies and state and local organizations, and Forbes reports Vanta has a handful of public-sector customers that work with government data. A single-framework plan aimed at startups is the lower end of the same product line. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Vanta is a platform with application features rather than infrastructure other software depends on to run. It exposes an API and connects to a customer's cloud, code, and identity systems, and no cited source shows another product depending on Vanta at runtime. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 2/3 | Vanta accumulates vendor risk data across its customer base, and Fortune reports figures drawn from its third-party risk product, including that 70% of companies have tools adopted without a security review. The cited record does not size that corpus, and a funded rival could accumulate comparable data with time and reach. |
Vanta's four plan tiers mark its segment boundaries. The plans page opens with an Essentials tier aimed at companies that want to stay focused on building, and closes with an Enterprise tier it describes as a trust program tailored to a customer's own needs.
The named references skew to companies with dedicated security and compliance staff. Fortune lists Snowflake, Atlassian, Duolingo, Ramp, Cursor, and Harvey among more than 16,000 customers, and the published customer accounts quote a lead compliance manager at Snyk and a director of customer assurance at GitHub.
Government is a declared segment with a registry entry behind it. Vanta's government page addresses federal agencies, government vendors, and state, local, and education organizations, and the FedRAMP Marketplace records Vanta Government Cloud as certified at Class C.
What Vanta does is read other systems and score what it finds. Fast Company reports more than 400 integrations feeding the platform and quotes chief product officer Jeremy Epling describing over 1,400 tests that continuously assess security controls.
The AI layer ships inside the products customers buy and stays pending in the one named for it. Help Net Security records an agent launched in July 2025 that automates evidence collection and policy management, Vanta's chief product officer records 20 agentic workflows shipped last year against a target above 90 for 2026, and the AI Governance product asks visitors to join a waitlist.
Forrester's own read of the category tempers the AI claim. Its 2026 governance, risk, and compliance write-up says the current AI functionality across the vendors it evaluated boosts existing capabilities rather than delivering the promised transformational change.
Vanta's pitch runs through the buyer's own sales cycle. The Trust Center page frames the product as turning security into a revenue driver by automating the security reviews a prospect would otherwise run by questionnaire.
The customer evidence follows the same line. Vanta's customer story on GitHub records more than 300 questionnaires arriving after the Copilot launch and 93% of inbound questionnaires automated within six months. Its customer index carries a second story, about cutting three to four weeks from DocGo's sales cycles.
An audit partner makes the same case. Vanta's plans page quotes a global strategic alliances lead at A-LIGN saying organizations that use Vanta for automated compliance reduce audit completion times by half, and it sells access to expert partners for additional compliance services.
Vanta publishes no price. Its plans page lists four tiers and asks the reader to request a free demo to discuss business needs and get personalized pricing.
The tier boundaries show what the company treats as upmarket. Essentials covers one compliance framework with an agentic policy generator. Risk management with customization, dashboards, and reporting arrives higher up, along with automated access management. Enterprise is a fully customizable package for advanced governance, risk, and compliance needs.
The return case comes from a report about Vanta. The plans page cites IDC's 2025 Business Value of Vanta report for a three-month payback period and a 526% return on investment over three years, a report named for the vendor it measures.
Customers run Vanta themselves and keep the outcome. The platform connects to a customer's cloud infrastructure, version control, productivity tools, and identity provider, and the customer's own team owns the compliance program the evidence supports.
The attestation comes from third-party auditors. Forbes describes the sequence. After Vanta helps a company compile the documentation, auditors go through the data and certify the company against standards such as SOC 2, ISO 27001, HIPAA, and GDPR.
Vanta's root cause analysis describes what went wrong in that path. It records that a performance change removed a domain ID filter on the APIs customers use to sync data from third-party tools, that data from one customer's integrations landed in another customer's tenant, and that existing tests and code review did not catch it before deployment.
Vanta holds the credentials it sells. Its security page records a SOC 2 Type II attestation and an ISO 27001 certification, and its trust center lists ISO/IEC 42001, a February 2026 penetration test executive summary including retest, and a certificate of liability insurance.
The federal registry carries the strongest of them. The FedRAMP Marketplace records Vanta Government Cloud as FedRAMP Certified at Class C under package ID FR2525556241XM, in ongoing certification, and files it under cybersecurity and risk management.
Transparency after failure belongs in the same record. Vanta published a root cause analysis of the May 2025 cross-tenant exposure with a timeline, the removed filter, and a commitment to engage a third party to review its code base. That account names what could have been exposed, metadata about training records and about access to tools, devices, and vulnerabilities, and records that MFA credentials, passwords, API keys, financial information, and healthcare information were not.
Integrations are the platform's surface area. Vanta's integrations directory frames the connection set as cloud infrastructure, version control, productivity tools, and identity providers, and Fast Company reports more than 400 of them feeding the agent's reports.
Vanta buys as well as builds. Forbes reports the July 2025 acquisition of the Israeli startup Riskey for an undisclosed sum to support continuous AI-driven risk monitoring, and Vanta's third-party risk page carries the acquisition announcement.
A published API extends the same surface. The plans page lists custom integration development through the Vanta API alongside the prebuilt connectors.
Vanta's leadership is one founder plus a hired bench. Fast Company records that Christina Cacioppo was once a product manager overseeing Dropbox's document-editing tool Paper, and that she founded Vanta with a Dropbox colleague, Erik Goldman, in Y Combinator's Winter 2018 batch. Forbes reports Goldman is no longer involved with the company.
The hires carry enterprise product and sales records of their own. Vanta's about page records that chief product officer Jeremy Epling joined from GitHub, where he was VP of Product for Actions, Codespaces, npm, and Packages, and that chief revenue officer Stevie Case joined from Twilio after more than fifteen years in sales and business development.
An investor sits on the board. Fast Company identifies Andrew Reed as the Sequoia Capital partner who led that firm's investment in Vanta and now serves on its board, and the Form D that Vanta Inc. filed with the SEC in 2023 carries Christina Cacioppo's signature for the company.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Vanta: Automated Compliance product page | official | 2026-08-18 |
| f2 | Fortune: Vanta hits $300 million ARR as shadow AI explodes across corporate America | press | 2026-08-18 |
| f3 | Forbes: Vanta raised new funds at a $4 billion valuation despite not needing the money | press | 2026-08-18 |
| f4 | Vanta: plans page | official | 2026-08-18 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Vanta: homepage “Earn and prove it with 35+ compliance frameworks, automated and continuously monitored.” | official | 2026-08-18 |
| s2 | Vanta: plans page “Request a free demo today to discuss your business needs and get personalized pricing.” | official | 2026-08-18 |
| s3 | Vanta: about and leadership page “Vanta was founded in 2018, in the wake of several high-profile data breaches.” | official | 2026-08-18 |
| s4 | Vanta: security and privacy page “Vanta maintains a SOC 2 Type II attestation and an ISO 27001 compliance certification. Our SOC 2 Type II report and ISO 27001 certificate are available on our Trust Center.” | official | 2026-08-18 |
| s5 | Vanta: customer stories index “More than 16,000 companies choose Vanta” | official | 2026-08-18 |
| s6 | Vanta: GitHub customer story “GitHub experienced firsthand how AI raises the bar for trust after it launched GitHub Copilot.” | official | 2026-08-18 |
| s7 | Vanta: Automated Compliance product page “Get compliant without the chaos—Vanta automatically gathers the evidence you’ll need to get compliant, and continuously monitors your systems to make sure you stay compliant and secure.” | official | 2026-08-18 |
| s8 | Vanta: Third Party Risk Management product page “Vanta has acquired Riskey! Say hello to the future of continuous third party risk monitoring in Vanta” | official | 2026-08-18 |
| s9 | Vanta: Trust Center product page “Turn security into a revenue driver. Trust Center helps you automate time-consuming security reviews and gives your prospects the info they need to make a purchase decision.” | official | 2026-08-18 |
| s10 | Vanta: AI Governance product page “Stop guessing what your AI is doing. Vanta automatically maps agents across your whole stack—giving you the visibility and control to deploy with confidence.” | official | 2026-08-18 |
| s11 | Vanta: FedRAMP product page “FedRAMP certification is required to sell cloud services to U.S. federal agencies. Vanta simplifies the process with pre-mapped controls, centralized evidence, and real-time visibility.” | official | 2026-08-18 |
| s12 | Vanta: government solution page “Vanta’s AI-powered platform helps government vendors, federal agencies, and SLED organizations automate compliance, strengthen security posture, and support mission-critical work with confidence.” | official | 2026-08-18 |
| s13 | Vanta: chief product officer's post on the Forrester GRC Wave “Vanta is named a Leader on our first-ever inclusion in the evaluation.” | official | 2026-08-18 |
| s14 | Vanta: published root cause analysis of product bug Inc-868 “On May 22, 2025 at 5:11pm PDT, we deployed a code change that caused a subset of data synced via Vanta’s third-party integration APIs to be written into the wrong customers’ tenants.” | official | 2026-08-18 |
| s15 | Vanta: trust center “Founded in 2018, Vanta serves customers in 58 countries with offices in Dublin, New York, San Francisco, Sydney, and London.” | official | 2026-08-18 |
| s16 | Vanta: Risk Management product page “Vanta simplifies and automates your risk processes, helping you work more efficiently and make informed risk decisions—all from one central platform.” | official | 2026-08-18 |
| s17 | Vanta: Personnel and Access product page “Vanta makes it easy to keep your personnel, and the systems and devices they have access to, secure and compliant—without you having to chase down every device and deadline.” | official | 2026-08-18 |
| s18 | Vanta: integrations directory “Connect Vanta with your cloud infrastructure, version control, productivity tools, identity provider, and much more to give you a complete and automated view of your security and compliance.” | official | 2026-08-18 |
| s19 | Fortune: Vanta hits $300 million ARR as shadow AI explodes across corporate America “The San Francisco-based security and compliance company has crossed $300 million in annual recurring revenue, Fortune exclusively learned. This milestone represents a tripling of ARR in two years.” | press | 2026-08-18 |
| s20 | Forbes: Vanta raised new funds at a $4 billion valuation despite not needing the money “The new round brings Vanta’s total funding raised to around $500 million.” | press | 2026-08-18 |
| s21 | Fast Company: Shadow AI is real and Vanta wants to help manage it “He first took notice of the startup when it reached $10 million in revenue without having taken on any venture funding, a rare accomplishment.” | press | 2026-08-18 |
| s22 | TechCrunch: Vanta bug exposed customers' data to other customers “Compliance company Vanta has confirmed that a bug exposed the private data of some of its customers to other Vanta customers.” | press | 2026-08-18 |
| s23 | Forrester: announcing The Forrester Wave for Governance, Risk, And Compliance Platforms, Q2 2026 “We’ve evaluated 12 vendors in this iteration and are grateful to all of them for their participation in the process.” | research | 2026-08-18 |
| s24 | SEC EDGAR: Vanta Inc. Form D/A rendering, signed 2023-08-23 “Notice of Exempt Offering of Securities” | regulatory | 2026-08-18 |
| s25 | FedRAMP Marketplace: Vanta Government Cloud package record “Vanta Government Cloud is an end-to-end security and compliance platform powered by AI and automation.” | regulatory | 2026-08-18 |
| s26 | Help Net Security: Vanta's Agentic Trust Platform industry news item “Vanta unveiled a number of new products that redefine how enterprises earn and prove trust at scale.” | press | 2026-08-18 |
| s27 | Diligent: announcement of its own placement in the same Forrester GRC evaluation “New York, NY, May 27, 2026 – Diligent , the AI leader in governance, risk and compliance ( GRC ), today announced that it has been named a Leader in The Forrester Wave™: Governance, Risk, and Compliance Platforms Q2 2026 report .” | official | 2026-08-18 |
| s28 | LogicGate: announcement of its own placement in the same Forrester GRC evaluation “LogicGate is recognized as one of only four Leaders in The Forrester Wave™: Governance, Risk, And Compliance Platforms, Q2 2026.” | official | 2026-08-18 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Vanta: homepage “Earn and prove it with 35+ compliance frameworks, automated and continuously monitored.” | official | 2026-08-18 |
| s2 | Vanta: plans page “Request a free demo today to discuss your business needs and get personalized pricing.” | official | 2026-08-18 |
| s3 | Vanta: about and leadership page “Vanta was founded in 2018, in the wake of several high-profile data breaches.” | official | 2026-08-18 |
| s4 | Vanta: security and privacy page “Vanta maintains a SOC 2 Type II attestation and an ISO 27001 compliance certification. Our SOC 2 Type II report and ISO 27001 certificate are available on our Trust Center.” | official | 2026-08-18 |
| s5 | Vanta: customer stories index “More than 16,000 companies choose Vanta” | official | 2026-08-18 |
| s6 | Vanta: GitHub customer story “GitHub experienced firsthand how AI raises the bar for trust after it launched GitHub Copilot.” | official | 2026-08-18 |
| s7 | Vanta: Automated Compliance product page “Get compliant without the chaos—Vanta automatically gathers the evidence you’ll need to get compliant, and continuously monitors your systems to make sure you stay compliant and secure.” | official | 2026-08-18 |
| s8 | Vanta: Third Party Risk Management product page “Vanta has acquired Riskey! Say hello to the future of continuous third party risk monitoring in Vanta” | official | 2026-08-18 |
| s9 | Vanta: Trust Center product page “Turn security into a revenue driver. Trust Center helps you automate time-consuming security reviews and gives your prospects the info they need to make a purchase decision.” | official | 2026-08-18 |
| s10 | Vanta: AI Governance product page “Stop guessing what your AI is doing. Vanta automatically maps agents across your whole stack—giving you the visibility and control to deploy with confidence.” | official | 2026-08-18 |
| s11 | Vanta: FedRAMP product page “FedRAMP certification is required to sell cloud services to U.S. federal agencies. Vanta simplifies the process with pre-mapped controls, centralized evidence, and real-time visibility.” | official | 2026-08-18 |
| s12 | Vanta: government solution page “Vanta’s AI-powered platform helps government vendors, federal agencies, and SLED organizations automate compliance, strengthen security posture, and support mission-critical work with confidence.” | official | 2026-08-18 |
| s13 | Vanta: chief product officer's post on the Forrester GRC Wave “Vanta is named a Leader on our first-ever inclusion in the evaluation.” | official | 2026-08-18 |
| s14 | Vanta: published root cause analysis of product bug Inc-868 “On May 22, 2025 at 5:11pm PDT, we deployed a code change that caused a subset of data synced via Vanta’s third-party integration APIs to be written into the wrong customers’ tenants.” | official | 2026-08-18 |
| s15 | Vanta: trust center “Founded in 2018, Vanta serves customers in 58 countries with offices in Dublin, New York, San Francisco, Sydney, and London.” | official | 2026-08-18 |
| s16 | Vanta: Risk Management product page “Vanta simplifies and automates your risk processes, helping you work more efficiently and make informed risk decisions—all from one central platform.” | official | 2026-08-18 |
| s17 | Vanta: Personnel and Access product page “Vanta makes it easy to keep your personnel, and the systems and devices they have access to, secure and compliant—without you having to chase down every device and deadline.” | official | 2026-08-18 |
| s18 | Vanta: integrations directory “Connect Vanta with your cloud infrastructure, version control, productivity tools, identity provider, and much more to give you a complete and automated view of your security and compliance.” | official | 2026-08-18 |
| s19 | Fortune: Vanta hits $300 million ARR as shadow AI explodes across corporate America “The San Francisco-based security and compliance company has crossed $300 million in annual recurring revenue, Fortune exclusively learned. This milestone represents a tripling of ARR in two years.” | press | 2026-08-18 |
| s20 | Forbes: Vanta raised new funds at a $4 billion valuation despite not needing the money “The new round brings Vanta’s total funding raised to around $500 million.” | press | 2026-08-18 |
| s21 | Fast Company: Shadow AI is real and Vanta wants to help manage it “He first took notice of the startup when it reached $10 million in revenue without having taken on any venture funding, a rare accomplishment.” | press | 2026-08-18 |
| s22 | TechCrunch: Vanta bug exposed customers' data to other customers “Compliance company Vanta has confirmed that a bug exposed the private data of some of its customers to other Vanta customers.” | press | 2026-08-18 |
| s23 | Forrester: announcing The Forrester Wave for Governance, Risk, And Compliance Platforms, Q2 2026 “We’ve evaluated 12 vendors in this iteration and are grateful to all of them for their participation in the process.” | research | 2026-08-18 |
| s24 | SEC EDGAR: Vanta Inc. Form D/A rendering, signed 2023-08-23 “Notice of Exempt Offering of Securities” | regulatory | 2026-08-18 |
| s25 | FedRAMP Marketplace: Vanta Government Cloud package record “Vanta Government Cloud is an end-to-end security and compliance platform powered by AI and automation.” | regulatory | 2026-08-18 |
| s26 | Help Net Security: Vanta's Agentic Trust Platform industry news item “Vanta unveiled a number of new products that redefine how enterprises earn and prove trust at scale.” | press | 2026-08-18 |
| s27 | Diligent: announcement of its own placement in the same Forrester GRC evaluation “New York, NY, May 27, 2026 – Diligent , the AI leader in governance, risk and compliance ( GRC ), today announced that it has been named a Leader in The Forrester Wave™: Governance, Risk, and Compliance Platforms Q2 2026 report .” | official | 2026-08-18 |
| s28 | LogicGate: announcement of its own placement in the same Forrester GRC evaluation “LogicGate is recognized as one of only four Leaders in The Forrester Wave™: Governance, Risk, And Compliance Platforms, Q2 2026.” | official | 2026-08-18 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.