Full-Time
Automates SOC 2 compliance checks via SaaS
No salary listed
London, UK
Hybrid
Hybrid role; some on-site in London.
Find people who can refer or advise you
Vanta provides a SaaS platform that helps small to mid-sized organizations obtain and maintain SOC 2 certification through automated checks and continuous monitoring. The product integrates with a company’s systems to run checks, track control effectiveness, and generate ready evidence, reports, and submission-ready documentation. It differentiates itself by offering ongoing compliance instead of one-off audits, with scalable checks and automated workflows tailored to SMEs and tech companies. The goal is to make SOC 2 faster, cheaper, and easier to sustain so organizations can focus on their core business while keeping strong security controls.
Company Size
1,001-5,000
Company Stage
Series D
Total Funding
$503M
Headquarters
San Francisco, California
Founded
2018
Find people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
100% Benefits Coverage
Flexible & Remote Work
Paid Parental Leave
Unlimited PTO
Health & Wellness
401(k)
Vanta vs Drata vs TrailProof - which SOC 2 tool is right for your stage? An honest comparison of Vanta, Drata, and TrailProof for SOC 2 compliance. What each tool actually does, what it costs, and which one makes sense depending on where your company is. If you are a startup researching SOC 2 tools, you will run into Vanta and Drata within the first hour. They are well funded, well marketed, and they show up everywhere. You will also probably flinch when you see the pricing. Here is an honest breakdown of what each tool does, what it actually costs, and which one makes sense depending on where your company is right now. Vanta. Vanta is the market leader and for good reason. It covers a wide range of compliance frameworks beyond SOC 2 - ISO 27001, HIPAA, PCI DSS, GDPR. It has deep integrations, a polished interface, and an established reputation with auditors. What it does well: Broad framework coverage, strong vendor integrations, a large customer base means your auditor has likely seen Vanta evidence packages before. What it costs: Pricing is not published but typically starts around $10,000 to $15,000 per year for SOC 2. Larger companies pay significantly more. There is usually a sales process involved. Who it is built for: Companies with a dedicated compliance person or team, typically Series A and beyond. The onboarding is thorough but it takes time. The gap: Vanta automates the technical controls well but does not deeply address the manual side of SOC 2 - incident logs, risk registers, vendor assessments, access review records. You still need to manage those separately. Drata. Drata is Vanta's main competitor and competes directly on features and price. It has a strong reputation, continuous monitoring, and good integrations across cloud providers and SaaS tools. What it does well: Continuous automated monitoring, good evidence collection across AWS and other platforms, solid customer support. What it costs: Similar to Vanta. Pricing starts around $10,000 per year and scales with company size. Also requires a sales conversation to get a quote. Who it is built for: Similar to Vanta - companies with compliance resources and budget. Drata has been making a push toward smaller companies but the pricing still reflects an enterprise product. The gap: Same as Vanta - the manual compliance work sits outside the tool. And at $10,000 per year, it is a hard spend to justify before your first enterprise contract. TrailProof. TrailProof is built specifically for early-stage startups. The focus is narrower - SOC 2 for AWS-based companies - but it handles both the automated scanning and the manual compliance work in one product. What it does well: Continuous evidence collection across AWS, GitHub, Google Workspace and Okta. AI executive summaries and remediation steps after every scan. All 8 SOC 2 policy documents generated by AI in 60 seconds. The Audit Preparation module covers incident logging, risk register with AI suggestions based on your actual failing checks, vendor register, quarterly access review tracking and policy acknowledgment management. Everything exports to PDF for your auditor. The security questionnaire analyzer is worth calling out separately - it takes enterprise vendor questionnaires in PDF, DOCX or Excel and auto-fills answers from your AWS evidence and policy documents. That alone saves hours on enterprise deals. Who it is built for: Startups going through SOC 2 for the first time, typically pre-Series A or early Series A. One founder or one engineer can run the whole thing without a compliance background. The gap: TrailProof does not cover ISO 27001, HIPAA, or PCI DSS. If you need multi-framework coverage, Vanta or Drata are the better fit. TrailProof is SOC 2 focused. Which one to choose. If you are pre-Series A or just starting SOC 2: TrailProof. The price difference is significant - $3,600 per year versus $10,000 to $15,000 - and you do not need the enterprise features Vanta and Drata offer until you have a compliance team to use them. If you are Series A or beyond with a compliance budget: Vanta or Drata. The broader framework coverage, deeper integrations and auditor familiarity are worth the price at that stage. If you need multiple compliance frameworks at once: Vanta or Drata. TrailProof is SOC 2 only. If you are trying to close your first enterprise deal and need SOC 2 fast: TrailProof. You can be up and running in an afternoon, start collecting continuous evidence immediately, and have policy documents the same day. The question most founders do not ask. The comparison most teams make is features versus price. The better question is: what do you actually need right now? Vanta and Drata are excellent tools. They are also built for companies with more resources, more people, and more compliance requirements than most early-stage startups have. Paying for enterprise compliance software before you have an enterprise compliance problem is how startups burn money they do not need to. Get the tool that matches your stage. Upgrade when you outgrow it. TrailProof - SOC 2 compliance automation for AWS startups. $299 per month, no per-seat fees. Ready to check your SOC 2 readiness? Free interactive checklist - 65 controls, saves progress, no signup required.
Vanta reached $300M ARR just 9 months after hitting $200M, with growth rate increasing each of the past four quarters. 16,000 companies now use the platform.
LiteLLM drops Delve after security compliance dispute. LiteLLM is replacing Delve and redoing its security certifications after a malware incident and escalating allegations around Delve's compliance practices. The company plans to use Vanta and an independent third-party auditor to verify its controls. LiteLLM, makers of a popular Artificial Intelligence gateway used by millions of developers, said it is severing ties with compliance startup Delve and will redo its security certifications with another provider and auditor. The move follows a damaging week in which LiteLLM's open source version was hit by credential-stealing malware. Before that incident, LiteLLM had obtained two security compliance certifications by hiring Artificial Intelligence compliance startup Delve. Those certifications are meant to confirm that a company has procedures in place to reduce the likelihood of security incidents. The reversal now raises fresh questions about the reliability of the earlier compliance work and about how LiteLLM intends to validate its controls going forward. Delve has been accused of misleading customers about their actual compliance status by allegedly generating fake data and relying on auditors that rubber-stamped reports. Delve's founder has denied those allegations and offered free re-tests and audits to all customers. The dispute intensified after an anonymous whistleblower renewed the claims and released alleged supporting receipts over the weekend. On Monday, LiteLLM CTO Ishaan Jaffer posted on X that his company will be using Delve competitor Vanta to re-certify and will find its own, independent third-party auditor to verify its compliance controls. The decision signals a clear break from Delve as LiteLLM responds to both the fallout from the malware incident and the broader controversy surrounding Delve's certification process. 52. Impact score. April 1, 2026 OpenAI says GPT-5 produces fewer false claims than earlier models, especially when it can browse the web. The gains look smaller without web access, underscoring how much reliability still depends on live sourcing. April 1, 2026 ARC-AGI-3 introduces interactive, instruction-free environments designed to test whether frontier Artificial Intelligence systems can adapt to genuinely novel situations. Early results show top models performing near zero, highlighting a sharp gap between pattern recognition and open-ended exploration. April 1, 2026 NVIDIA is reportedly running into manufacturing problems with Rubin Ultra as its planned package pushes beyond current TSMC capabilities. The issue centers on CoWoS-L packaging for a much larger multi-die, high-bandwidth memory design. April 1, 2026 Intel's Binary Optimization Tool is changing how executable applications run on Arrow Lake Refresh systems, with measurable gains in some workloads. Primate Labs found that the tool cuts instruction counts and aggressively shifts execution from scalar code to vector instructions, prompting Geekbench to label BOT-enhanced results. April 1, 2026 Medical chatbots from major tech companies are arriving quickly as questions grow about how little outside testing they receive before public release. A judge has also temporarily halted the Pentagon's effort to label Anthropic a supply chain risk, exposing a dispute escalated outside normal government channels.
Popular AI gateway startup LiteLLM ditches controversial startup Delve. LiteLLM, makers of popular AI gateway used by millions of developers, has publicly announced that it is ditching compliance startup Delve and will redo its security certifications with another company and auditor. The announcement comes after LiteLLM's open source version fell victim to some horrific credential-stealing malware last week. Prior to the incident, LiteLLM had obtained two security compliance certifications by hiring AI compliance startup Delve. Such certifications are intended to verify that a company has procedures in place to minimize potential incidents. Delve has been accused of misleading its customers about their true compliance by allegedly generating fake data and using auditors that rubber-stamped their reports. Delve's founder has denied those allegations and offered free re-tests and audits to all of its customers. That denial encouraged the anonymous Delve whistleblower to double down, including releasing alleged receipts over the weekend. On Monday, LiteLLM CTO Ishaan Jaffer posted on X that his company will be using Delve competitor Vanta to re-certify and will find its own, independent third-party auditor to verify its compliance controls. After such a harsh week, LiteLLM is voting with its feet.
Vanta, a trust management platform, has announced new AI agents and enterprise controls designed to automate compliance and security workflows. The suite includes context-aware agents for compliance, third-party risk management and customer trust, alongside privacy automation features for data governance. The company's agents operate as 24/7 GRC engineers, coordinating tasks, collecting evidence and surfacing material risks whilst keeping humans in decision-making roles. New enterprise capabilities include adaptive business unit scoping and a standardised control framework to reduce redundancy across multi-framework programmes. Vanta's privacy automation integrates data governance into broader compliance systems, centralising Record of Processing Activities management, data inventories and Data Protection Impact Assessments. The platform serves over 15,000 businesses, including Atlassian, Duolingo and Ramp.