{
 "categories": [
  "devsecops",
  "enterprise"
 ],
 "deployment": "saas",
 "evidence": [
  {
   "date": "2026-10-09",
   "fact": "homepage",
   "note": "The developer index describes Vanta as a trust platform with APIs, an MCP server, and integration guides for compliance, risk, and proof.",
   "source": "https://developer.vanta.com/llms.txt",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "license",
   "note": "The MCP guide says the beta server is released to all customers and requires a Vanta Admin. That is a paid customer product, not a public free tier.",
   "source": "https://developer.vanta.com/docs/vanta-mcp",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.api.exists",
   "note": "Vanta documents a RESTful JSON API with Manage Vanta, Build Integrations, and Auditor surfaces.",
   "source": "https://developer.vanta.com/reference/overview",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.api.kinds[0]",
   "note": "The overview calls the Vanta API a RESTful JSON API.",
   "source": "https://developer.vanta.com/reference/overview",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.api.auth[0]",
   "note": "Manage Vanta, private integrations, and the Auditor API use grant_type client_credentials at POST https://api.vanta.com/oauth/token.",
   "source": "https://developer.vanta.com/docs/concepts/authentication",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.api.auth[1]",
   "note": "Public integrations use grant_type authorization_code, then refresh_token. The browser host is regional.",
   "source": "https://developer.vanta.com/docs/concepts/authentication",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.api.coverage",
   "note": "Three APIs cover tenant automation, partner data push, and auditor access. Tokens last one hour, one active token is allowed per application, and token issuance is 5 requests per minute.",
   "source": "https://developer.vanta.com/reference/overview",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.api.docs",
   "note": "Opened the Vanta API overview, including base URLs and OpenAPI spec links.",
   "source": "https://developer.vanta.com/reference/overview",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.sdk.exists",
   "note": "Vanta publishes official SDKs for the Auditor API. Manage Vanta and Build Integrations are not covered.",
   "source": "https://developer.vanta.com/docs/sdks",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.sdk.official",
   "note": "The SDK page says Vanta publishes the libraries and labels them beta until 1.0.0.",
   "source": "https://developer.vanta.com/docs/sdks",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.sdk.languages[0]",
   "note": "The TypeScript SDK is installed with npm add vanta-auditor-api-sdk.",
   "source": "https://developer.vanta.com/docs/sdks",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.sdk.languages[1]",
   "note": "The Java SDK is com.vanta:vanta-auditor-api:0.3.0 on Maven Central and requires JDK 11 or later.",
   "source": "https://developer.vanta.com/docs/sdks",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.mcp.first_party",
   "note": "Vanta hosts a remote MCP server in beta. US, EU, and Australia URLs are documented. The caller must be a Vanta Admin. Auth is OAuth.",
   "source": "https://developer.vanta.com/docs/vanta-mcp",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.extensibility.webhooks",
   "note": "Settings, Webhooks registers an HTTPS endpoint. Vanta POSTs events and signs them with Svix headers svix-id, svix-timestamp, and svix-signature.",
   "source": "https://developer.vanta.com/docs/webhooks",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.data_access.export[0]",
   "note": "The overview describes a JSON API and links OpenAPI 3.0 specifications for each API.",
   "source": "https://developer.vanta.com/reference/overview",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.agent_docs.llms_txt",
   "note": "Opened a text/plain developer index that links API quickstarts, the MCP guide, webhooks, and SDK pages.",
   "source": "https://developer.vanta.com/llms.txt",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "verdict.scores.api",
   "note": "OAuth bearer access is documented for tenant, partner, and auditor work. The one-hour token, single active token, and 5-per-minute token endpoint are operational limits.",
   "source": "https://developer.vanta.com/docs/concepts/authentication",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "verdict.scores.mcp",
   "note": "The hosted server is official and lists controls, tests, vendors, vulnerabilities, and policies. It is beta and admin-only.",
   "source": "https://developer.vanta.com/docs/vanta-mcp",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "freshness.watch[0].url",
   "note": "Opened the Vanta API overview.",
   "source": "https://developer.vanta.com/reference/overview",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "freshness.watch[1].url",
   "note": "Opened the Vanta MCP guide, including regional URLs and the Admin requirement.",
   "source": "https://developer.vanta.com/docs/vanta-mcp",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "freshness.watch[2].url",
   "note": "Opened the Vanta authentication concepts page.",
   "source": "https://developer.vanta.com/docs/concepts/authentication",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-10-09",
  "volatility": "high",
  "watch": [
   {
    "type": "docs",
    "url": "https://developer.vanta.com/reference/overview"
   },
   {
    "type": "docs",
    "url": "https://developer.vanta.com/docs/vanta-mcp"
   },
   {
    "type": "docs",
    "url": "https://developer.vanta.com/docs/concepts/authentication"
   }
  ]
 },
 "homepage": "https://www.vanta.com/",
 "id": "vanta",
 "license": "commercial",
 "modalities": {
  "agent_docs": {
   "llms_txt": true
  },
  "api": {
   "auth": [
    "oauth2-client-credentials",
    "oauth2-authorization-code"
   ],
   "coverage": "partial",
   "docs": "https://developer.vanta.com/reference/overview",
   "exists": true,
   "kinds": [
    "rest"
   ]
  },
  "cli": {
   "exists": "unknown"
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "json"
   ],
   "import": []
  },
  "extensibility": {
   "scripting": [],
   "webhooks": true
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": true,
   "third_party": [],
   "verdict": "official"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No UI probe was run. Vanta documents a REST API, webhooks, and a beta remote MCP server for Vanta Admins.\n",
   "ui_stack": [],
   "vendor_support": []
  },
  "sdk": {
   "exists": true,
   "languages": [
    "typescript",
    "java"
   ],
   "official": true
  }
 },
 "name": "Vanta",
 "platforms": [
  "web"
 ],
 "related": {
  "alternatives": [
   "drata",
   "onetrust"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "Vanta",
 "verdict": {
  "best_path": "api",
  "scores": {
   "api": 7,
   "cli": null,
   "computer_use": null,
   "integrations": null,
   "mcp": 6,
   "overall": 7,
   "rpa": null
  },
  "summary": "Vanta is automatable today through its REST API. This record is Vanta compliance operations. It is not Drata or OneTrust. The API is JSON at https://api.vanta.com for standard tenants and https://api.vanta-gov.com for Vanta Gov. Manage Vanta, private integrations, and the Auditor API use OAuth client credentials. Public integrations use the authorization-code grant. Access tokens last one hour. One active token per application is allowed, and /oauth/token is limited to 5 requests per minute. Vanta says it does not support API keys for the API. Webhooks are HTTPS POSTs signed with Svix. Official SDKs exist for the Auditor API only, in TypeScript and Java, and Vanta labels those SDKs beta. The remote MCP server is beta, released to all customers, and limited to Vanta Admins. Regional MCP URLs are https://mcp.vanta.com/mcp, https://mcp.eu.vanta.com/mcp, and https://mcp.aus.vanta.com/mcp. Auth is OAuth. Documented agent tasks include failing tests, controls, vendors, vulnerabilities, policies, and framework gaps. A supported CLI was not opened. Connector catalogs were not opened. Computer-use viability is unassessed. The API scores 7 and is the best path. The MCP scores 6.\n"
 }
}