What Vanta does
Vanta is a compliance automation platform. You connect it to the systems your company runs on, and it checks them continuously against the controls a SOC 2 auditor will test.
- Connects to your cloud provider, identity provider, HR system, code repository and company laptops.
- Runs automated tests, such as whether multi-factor authentication is on and whether laptops are encrypted.
- Provides policy templates you can adapt.
- Tracks tasks for each employee, such as accepting policies and completing security training.
- Gives your auditor one place to review the evidence.
That is a real saving. Before platforms like this, most of that evidence was collected by hand with screenshots and spreadsheets.
What Vanta doesn't do
The platform tells you what is wrong. It does not fix it, and it cannot see work that happens outside the systems it is connected to.
Connecting everything
Each integration has to be authorized by an administrator with the right permissions. Some of your systems will not have an integration at all, so their evidence has to be gathered and uploaded manually. Every company laptop needs the monitoring agent installed, which means following up with every employee until it is done.
Fixing failed tests
The first time everything is connected, most companies see a long list of failing tests. Each one is a real task: turn on multi-factor authentication for the people who don't have it, encrypt a database, remove access for someone who left months ago, get the last few employees to finish their training. Someone has to assign each task, follow up, and confirm the test now passes.
Writing policies that match reality
Templates are a starting point. An auditor tests you against what your policies say, so each one has to be edited to describe what your company actually does, approved by leadership, and accepted by every employee.
The work no tool can see
Some controls are carried out by people and documented afterward. These typically include:
- A risk assessment
- Reviews of your important vendors
- Periodic reviews of who has access to key systems
- An incident response exercise
- A penetration test, if your auditor or customers expect one
None of these are generated by the platform. Someone has to do them and upload the proof.
The audit period is where things get missed
A SOC 2 Type 2 report covers a period of time, commonly three months for a first report. Throughout that period the tests have to stay passing, and normal company life keeps creating new evidence to collect: people join, people leave, code ships, laptops get replaced.
Someone has to watch the dashboard every week and fix what drifts. We cover that in detail in what you have to prove during the SOC 2 audit period.
Who should own it
In most small companies the work lands on an engineer, who is pulled off the product, or on an operations manager who already has a full job. The third option is to hand the project to someone outside the company who has done it before.
We set up Vanta, clear the failing tests with your team, write and roll out the policies, and manage the audit through to the final report. See SOC 2 readiness and audit management.
