
I think the practicality of being able to integrate things simply is a great advantage. Vanta has several integrations with the systems we already use here at Zenvia, which makes it easier to connect my MDM tools, for example. Additionally, it already provides compliance evidence, such as encrypted hard drives and screen lock policies, and also checks if antivirus is installed. The more I integrate, the more I can automate the collection of compliance evidence for the next audit, which greatly optimizes the entire process. The support team is very effective, with service via support@vanta.com in just a few minutes. The use of embedded Artificial Intelligence in the tool is a great differentiator, as it analyzes risk scopes and suggests ISO 27001 controls, as well as analyzes policies and collects controls and documents for compliance with ISO 27001 in an automated way. I notice a significant performance gain with all these Vanta functionalities compared to my old processes. Review collected by and hosted on G2.com.
I don't like the way the policy management module is implemented. Today, it basically functions as a general repository: all policies are in the same place, everyone can view and also edit them, and this is not granular at all.
In my opinion, there should at least be a more structured document management, by area or by type of document. There are documents with different levels of confidentiality, so it would make sense to allow limiting both access and, especially, editing. It would also be important to be able to control editing based on approving groups, with features more akin to document management tools.
I understand that it is a multidisciplinary tool, but for this type of need, I consider the document management model to be very simplistic. Review collected by and hosted on G2.com.