RXed AI News

AI to the bone.
@RXed_EU
SCORE 7/1014/20 elements Audited 2026-08-06 · RXed table v1.0

Vanta

“SOC 2, HIPAA, ISO 27001, PCI, and GDPR Compliance” — the vendor’s own words

16,000 customers and $300M ARR buy the most auditor-familiar compliance platform there is, and an agent that is better engineered than most AI products twice its price — then year two arrives and G2 reviewers report 30-50% uplifts.

Enterprise platformSecurity & ComplianceAutomation & AgentsProductivityPaid
Vendor
Vanta Inc. · www.vanta.com
Origin
US — San Francisco
Pricing
Essentials Get personalized pricing · Plus Get personalized pricing · Professional Get personalized pricing · Enterprise Get personalized pricing
Users (official only)
More than 16,000 companies; $300M ARR crossed April 2026 (source, 2026-06-03)
EssentialsGet personalized pricingentry tier, typically one framework; observed ~$10K-$15K/yr
PlusGet personalized pricingadds access reviews, workflows, limited questionnaire automation; observed $15K-$30K/yr
ProfessionalGet personalized pricingcustom controls, SCIM, higher questionnaire volume; observed $30K+/yr
EnterpriseGet personalized pricingall frameworks, Organizations Center, premium SLA; observed $50K-$80K+/yr

Every price cell on Vanta's own pricing page reads 'Get personalized pricing'. The most-cited complaint in G2 and r/soc2 threads is year-two uplift, self-reported in the 30-50% range, triggered by headcount growth moving you a tier or by trial-included modules becoming paid add-ons. Negotiate a multi-year cap before signing.

checked 2026-08-06 · vendor pricing page

Element scores

Reactive
Retrieval & Memory
Orchestration
Validation
Models
Primitives
Pr5
Prompts
Em5
Embeddings
Cx8
Context
Tr6.5
Tracing
Lg6
LLM
Compositions
Fc7.5
Function calling
Vx
Vector store
Rg8
RAG
Gr7.5
Guardrails
Mm
Multimodal
Deployment
Ag8
Agents
Ft
Fine-tuning
Fw8
Frameworks & harnesses
Ev5
Evaluations
Sm
Small models
Emerging
Ma4
Multi-agent
Sy
Synthetic data
Pc8
Protocols
In4
Interpretability
Th
Thinking models
Tap or hover any element to see why it got that score.

Strengths

The engineering behind the agent is better than the category deserves: an E2B sandbox so the agent runs scripts over full datasets instead of sampling inside a context window, agent memory, and the Trust Graph as a continuously-refreshed grounding layer across 400+ integrations. The protocol surface is the best in GRC — hosted MCP with a dedicated EU endpoint, an open-source self-hosted server, and an official Claude Code plugin that generates Terraform fixes and opens draft PRs against your repo. Governance is real, not decorative: informed consent with a global AI off switch, DPAs forbidding vendor training, ISO 42001 certification, and the AARM runtime-agent-security spec authored at Vanta and donated to the Cloud Security Alliance.

Honest dings

Almost every AI control stays on Vanta's side of the line. No model is named, no model can be chosen, no eval can be run by you, no agent trace can be opened by you — the quality argument rests entirely on Vanta's own published discipline. MCP is still beta and admin-only, so the agentic workflows are closed to everyone below org admin. The three module agents don't coordinate. And the commercial pattern is well documented: usage caps on questionnaires and vendors trigger mid-contract upsells, and year-two renewals come in 30-50% higher in self-reported buyer threads.

Best for: Growth-stage and enterprise teams that need SOC 2 or ISO 27001 to close deals, run a standard cloud stack, and will use the MCP server to pull compliance context into the coding agent they already have open.
Visit vanta.com Prices and details change — this passport is re-verified at least quarterly.

Sources

Every audit lists the research it rests on — transparency and traceability are the product. Tools evolve: each audit is a snapshot of its audit date, and re-audits supersede older versions (kept below for reference).