{"record":"Vanta evidence record","url":"https://nexalign.io/vendors/vanta","vendor":{"slug":"vanta","name":"Vanta","domain":"vanta.com","category":"grc","categoryLabel":"Governance, risk and compliance"},"lastChecked":"2026-07-18T10:20:32.528Z","coverage":{"earliest":"2022-09-26T15:10:26.000Z","latest":"2026-07-18T10:20:32.528Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":50,"kindsOfSource":5,"attributedAdvisories":0,"knownExploited":0,"registerEntriesNotAttributable":35,"practitionerThreads":6,"independentItems":2,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":33,"latest":"2026-07-01T22:35:10.000Z"},{"source":"Known Exploited Vulnerabilities catalogue","operator":"CISA, United States","classification":"authoritative","items":2,"latest":"2025-03-03T00:00:00.000Z"},{"source":"Engineering discussions","operator":"Hacker News, public threads","classification":"independent","items":12,"latest":"2026-07-07T18:49:51.000Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":2,"latest":"2026-07-18T10:20:32.528Z"},{"source":"Practitioner discussions","operator":"Reddit, public threads","classification":"independent","items":1,"latest":"2026-05-09T14:19:42.000Z"}],"advisories":{"shown":0,"total":0,"truncated":false,"items":[]},"practitionerThreads":{"shown":5,"total":6,"truncated":true,"items":[{"title":"Audit your Claude Code permissions with Vanta","context":"Hacker News","url":"https://news.ycombinator.com/item?id=48821932","date":"2026-07-07T18:49:51.000Z"},{"title":"Vanta's Agent Development Principles","context":"Hacker News","url":"https://news.ycombinator.com/item?id=48661736","date":"2026-06-24T15:51:39.000Z"},{"title":"The Vanta AI Quality Eval Maturity Model","context":"Hacker News","url":"https://news.ycombinator.com/item?id=48478761","date":"2026-06-10T16:28:14.000Z"},{"title":"Trustcraft: How we build AI products at Vanta","context":"Hacker News","url":"https://news.ycombinator.com/item?id=48394581","date":"2026-06-04T05:58:21.000Z"},{"title":"Vanta bug exposed customers' data to other customers","context":"Hacker News","url":"https://news.ycombinator.com/item?id=44161130","date":"2025-06-02T17:29:25.000Z"}]},"independentCoverage":{"shown":2,"total":2,"truncated":false,"items":[{"title":"Vanta (company)","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/Vanta_(company)","date":null},{"title":"Vanta Reviews & Ratings 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/product/vanta-859163126","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["35 register entries mention Vanta, but none of them could be attributed to a product of Vanta. They describe other vendors' software and are not shown here.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}