21 documented complaints against Vanta — paraphrased from BBB filings, Trustpilot reviews, Reddit threads, and public forum posts. Newest complaints first.
Sourced from public platforms across US, UK, and global markets — each report links to the original source.
Misleading Marketing
HIGH
Source: Reddit · Nov 12, 2024
Added 1d ago
Vanta Markets SOC 2 Automation But Audit Fees Still Land on You
Vanta's core pitch is that it automates compliance work and gets companies SOC 2-ready fast. What the homepage language obscures is that the platform fee — which ran $7,500 to $15,000+ annually for startups as of 2024-2025 — is entirely separate from the auditor's bill, which typically adds another $10,000 to $30,000. Buyers coming from Vanta's marketing often expect a more bundled solution and are blindsided when they realize the audit relationship and cost are entirely their problem to manage. The distinction between 'audit-ready' and 'audited' is real, and Vanta's promotional copy has historically made that line harder to see than it should be.
"We signed up thinking Vanta handled the audit too. Nobody made it clear we'd still need to find and pay an auditor separately — that ended up costing us more than the platform itself."
Billing Problems
HIGH
Source: G2 · Mar 4, 2025
Added 1d ago
Aggressive Annual Contract Lock-In with Little Refund Flexibility
Multiple G2 and Capterra reviewers from 2024 and 2025 describe Vanta's contracts as strictly annual, with no prorated refunds after the billing period begins. Several small startups reported paying the full year's fee even after being acquired or pivoting away from the compliance use case within weeks of signing. The sales team reportedly pushes annual commitments hard during the close process, and the no-refund position is enforced by a contract clause reviewers say was not emphasized during demos. For a product targeting early-stage companies whose plans change fast, this is a recurring sore point.
"We got acquired three months into our annual contract. Vanta kept every dollar and offered nothing — not even a credit toward a future account."
Churn & Retention
MEDIUM
Source: Hacker News · Jun 9, 2025
Added 1d ago
Customers Drop Vanta After First Audit Cycle, Citing Diminishing Value
A notable churn pattern shows up in SaaS community discussions on Reddit and Hacker News: companies that complete their first SOC 2 Type II report through Vanta frequently question whether renewing at full price makes sense. The argument is that the heavy lift is in year one — after that, most of the controls are established and evidence collection becomes more routine. Several founders have posted that they moved to cheaper alternatives or handled year-two surveillance audits with manual processes, saving $8,000 to $12,000 annually. This suggests Vanta's value proposition has a natural expiration point for smaller companies.
"Year one was worth it. Year two, we were paying fifteen grand for a dashboard that auto-collected stuff we could pull ourselves in an afternoon."
Billing Problems
MEDIUM
Source: G2 · Feb 14, 2025
Added 1d ago
Opaque Pricing Tiers Make True Cost Hard to Assess Before Sales Call
Vanta publishes no public pricing on its website as of 2025-2026, requiring a sales call to get any number — a friction point that draws complaints from startup founders who just want to budget quickly. Once in the sales process, multiple reviewers describe being quoted different prices depending on company size, integrations needed, and frameworks sought (SOC 2, ISO 27001, HIPAA combinations add cost). G2 reviewers from 2025 describe sticker shock when add-on frameworks like ISO 27001 were priced at several thousand dollars on top of the base SOC 2 plan, a cost not clearly conveyed until deep in negotiation.
"The sales rep quoted us one number, then the contract showed the ISO 27001 add-on as a separate line that added nearly four thousand dollars. That wasn't in any of the early conversations."
Customer Complaints
MEDIUM
Source: Capterra · Apr 7, 2025
Added 1d ago
Vendor Risk Management Module Draws Criticism for Shallow Assessments
Vanta expanded beyond SOC 2 prep to include a vendor risk management feature that sends questionnaires and tracks third-party compliance status. Reviews from 2024 and 2025 on Capterra and G2 describe the module as superficial — questionnaire logic is rigid, follow-up automation is limited, and the scoring methodology is opaque enough that procurement and legal teams at larger organizations won't accept Vanta's vendor risk scores as authoritative. Several reviewers say they ended up maintaining a parallel spreadsheet process anyway, effectively paying for a feature they couldn't trust.
"We tried using their vendor risk module for a procurement review and our legal team rejected it outright. They had no confidence in how the scores were calculated and neither did I, honestly."
Support Failures
MEDIUM
Source: Capterra · Oct 22, 2024
Added 1d ago
Slow Support Response Times During Pre-Audit Crunch Periods
A consistent thread across Capterra and G2 reviews involves support tickets going unanswered for three to seven business days precisely when customers are under audit deadline pressure. Vanta's lower-tier plans appear to route to async email support only, with no live chat or dedicated CSM unless you're on an enterprise plan. Reviewers from late 2024 specifically mention that the in-app policy templates had errors and that getting corrections confirmed by support took longer than the audit timeline allowed. When the product's primary value is eliminating compliance stress, slow support during audits undermines the entire proposition.
"I had an auditor waiting on a corrected control description and Vanta support took five days to confirm what I needed. That's not a compliance tool — that's a liability."
Customer Complaints
MEDIUM
Source: Reddit · Jan 18, 2025
Added 1d ago
Integration Failures with Core Developer Toolchains Frustrate Engineering Teams
Vanta's automated evidence collection depends heavily on integrations with AWS, GitHub, Heroku, Google Workspace, and similar tools. Reviewers on G2 and Reddit have documented cases where integrations silently stopped syncing after provider API changes, causing evidence to go stale without any in-app alert. In several reported cases from 2024, companies discovered broken integrations only when an auditor flagged missing evidence — at which point they had to manually collect months of historical data. Vanta has pushed integration reliability fixes in updates, but the silent-failure mode remains a complaint pattern as recently as early 2025.
"Our AWS integration broke after an update and we had no idea until our auditor said the access logs were two months old. There was no notification, no alert — nothing."
Customer Complaints
LOW
Source: Reddit · Aug 30, 2024
Added 1d ago
Policy Template Quality Criticized as Generic and Legally Undercooked
Vanta ships a library of pre-written security and privacy policies meant to give smaller teams a compliance baseline fast. But security engineers and GRC professionals posting on Reddit and LinkedIn through 2024 and 2025 routinely flag that the templates are generic to the point of being almost meaningless for companies with non-standard architectures — think multi-cloud, edge deployments, or AI/ML pipelines. Some reviewers hired outside counsel to rewrite what Vanta generated, spending $3,000 to $7,000 on legal cleanup. The templates work fine for cookie-cutter SaaS stacks; for anything more complex, they're a starting point at best.
"Vanta's policies read like they were written for a five-person Shopify app. We had to gut and rewrite about sixty percent of them before our auditor would accept them."
BBB Complaints
LOW
Source: BBB
Updated 1d ago
BBB Complaints on File for Vanta
Vanta has a BBB rating of on record. The company holds BBB Accreditation. Consumers have raised concerns about this company through the Better Business Bureau.
Billing Problems
HIGH
Source: G2 · Mar 14, 2025
Added 7d ago
Opaque Pricing Leaves Buyers Blindsided After Signing Contracts
Vanta publishes no public pricing tiers, forcing prospects through a sales call before learning that annual contracts typically run $7,000–$30,000+ depending on integrations and employee count. Multiple G2 and Capterra reviewers noted that add-on features — including additional frameworks like ISO 27001 or HIPAA on top of SOC 2 — carry separate license fees that weren't surfaced until renewal negotiations. The discovery that the auditor still charges $15,000–$40,000 on top of the platform fee catches first-time buyers off guard.
"We signed thinking Vanta was an all-in-one cost. Turns out the auditor was a completely separate bill, and adding HIPAA to our existing plan nearly doubled our annual spend."
Misleading Marketing
HIGH
Source: Hacker News · Jan 15, 2024
Added 7d ago
Automated Compliance Claims Obscure Substantial Manual Work Still Required
Vanta markets its platform as 'automated security and compliance,' but engineers at multiple companies have reported on Hacker News and Reddit that the automation handles evidence collection, not remediation — meaning teams still spend weeks writing policies, closing control gaps, and responding to auditor questions manually. The disconnect between 'weeks not months' marketing language and actual timelines of 3–6 months to first report is a recurring complaint across review platforms. For companies with complex AWS or multi-cloud stacks, the number of controls that require manual evidence uploads regularly surprises buyers.
"Their marketing implies you plug it in and get a certificate. What you actually get is a dashboard that tells you how much work you still have to do yourself."
Billing Problems
MEDIUM
Source: Capterra · Sep 4, 2025
Added 7d ago
Per-Employee Pricing Model Punishes Fast-Growing Startups at Renewal
Vanta's pricing scales with headcount, which means a startup that doubles from 50 to 100 employees between contract years can see their renewal cost jump by 50–80% with no corresponding increase in the scope of compliance work being done. This has generated a specific pattern of negative reviews on Capterra from Series A and Series B companies who describe the pricing model as punishing growth rather than rewarding it. The lack of a headcount cap or a 'startup tier' that survives past initial onboarding is a common frustration.
"We hired 40 people in a good year and our Vanta renewal came in at nearly double what we budgeted. The platform didn't get twice as useful."
Billing Problems
MEDIUM
Source: Capterra · Nov 8, 2024
Added 7d ago
Auto-Renewal Clauses Trap Customers Who Deprioritized Compliance Work
Several Capterra and G2 reviewers flagged that Vanta's annual contracts include auto-renewal clauses with 60–90 day cancellation notice windows. Startups that paused their SOC 2 efforts mid-year — often because a key compliance hire left or fundraising priorities shifted — found themselves locked into a second year at full price. One recurring complaint pattern involves companies that completed their audit in year one but wanted to downgrade to a lower-tier monitoring plan and were told no mid-cycle changes were permitted.
"We finished our audit, didn't need the full platform for another year, and missed the cancellation window by three weeks. They wouldn't prorate anything."
Support Failures
MEDIUM
Source: Trustpilot · Jun 22, 2025
Added 7d ago
Customer Support Response Times Worsen Significantly Post-Onboarding
A consistent thread across Trustpilot and G2 reviews is that Vanta's onboarding support is attentive, but post-launch support quality drops sharply. Users report waiting 3–7 business days for responses on technical integration questions, particularly around custom integrations built with Vanta's API. The problem appears more acute for customers on lower-tier plans, who describe being routed to documentation rather than live help when debugging control failures ahead of audit deadlines.
"During sales and setup, we had a dedicated CSM who answered same-day. Six months in, our tickets were sitting for a week with no response and an audit coming up."
Customer Complaints
MEDIUM
Source: Reddit · Feb 3, 2025
Added 7d ago
Integration Breakages After Third-Party Updates Cause Compliance Gaps
Vanta's value proposition depends on live integrations with cloud providers, identity managers, and HR systems. Reviewers on Reddit's r/sysadmin and r/netsec have documented cases where a Google Workspace API change, an Okta policy update, or an AWS IAM config shift caused Vanta integrations to silently break — leaving controls marked 'passing' in the dashboard when the underlying data had stopped syncing. The risk is that a company can show a clean Vanta dashboard while an auditor finds stale evidence, potentially invalidating a control.
"Our Okta integration broke silently for six weeks. We found out during an auditor sample pull, not from Vanta alerting us."
Churn & Retention
MEDIUM
Source: Hacker News · Apr 29, 2024
Added 7d ago
Post-Audit Retention Problem: Many Customers Question Year-Two Value
Multiple Hacker News and Reddit discussions reveal a common pattern: companies pay for Vanta to get their initial SOC 2 Type I or Type II, then question whether the platform justifies $10,000+ annually for ongoing monitoring when cheaper alternatives or internal tooling could handle continuous compliance checks. This post-audit churn signal suggests the product's value is front-loaded, and the renewal pitch — centered on monitoring, vendor questionnaire automation, and multi-framework coverage — doesn't always close the gap. Competitors like Drata and Secureframe are frequently named as alternatives buyers are evaluating at renewal time.
"Year one was worth it for the audit prep. Year two we're asking what we're actually paying for that a junior security engineer and some scripting couldn't do."
Customer Complaints
LOW
Source: G2 · Jan 18, 2025
Added 7d ago
Vendor Risk Management Module Criticized as Shallow and Labor-Intensive
Vanta upsells a vendor risk management feature that promises to automate third-party security questionnaire collection and scoring. G2 reviewers from 2024 and 2025 consistently rate this module below the core compliance platform, noting that vendor response rates are low, follow-up is entirely manual, and the risk scoring rubric offers little customization. Buyers who purchased Vanta partly on the strength of this feature have reported feeling misled about its maturity.
"The vendor risk piece felt like a beta feature being sold as enterprise-ready. Half our vendors ignored the automated requests and we ended up chasing them by email anyway."
Support Failures
LOW
Source: Reddit · Aug 11, 2024
Added 7d ago
Policy Template Library Criticized as Generic and Legally Unvetted
One of Vanta's headline features is a library of pre-built security policy templates designed to accelerate SOC 2 readiness. Security professionals on Reddit and Hacker News have pointed out that the templates, while usable as starting points, are generic enough that auditors frequently flag them as insufficiently tailored to the company's actual environment. At least a dozen reviewers across G2 and Capterra between 2024 and 2025 noted their auditors required substantial rewrites, negating much of the time savings the templates were supposed to provide.
"The policy templates are a decent skeleton, but our auditor marked half of them as boilerplate and sent us back to customize. It still took our legal team several weeks."
Misleading Marketing
MEDIUM
Source: Reddit
Added 3mo ago
Marketing implies faster compliance than the audit timeline permits
Vanta has promoted getting SOC 2 'in weeks' — which applies to evidence collection setup, not the full audit. The audit itself (choosing an auditor, scheduling, fieldwork, report) takes 3–6 months regardless of how fast Vanta collects evidence.
Customer Complaints
MEDIUM
Source: Capterra
Added 3mo ago
Integration gaps require manual evidence for some controls
Companies using less common cloud services or internal tools describe significant portions of their SOC 2 evidence needing manual upload — reducing the automation value proposition for organizations with non-standard tech stacks.
Billing Problems
MEDIUM
Source: G2
Added 3mo ago
Annual contract pricing increases at renewal with limited negotiation
Multiple companies describe Vanta renewals coming in 20–40% higher than the initial contract, with limited room to negotiate given the cost of migrating compliance evidence history to a competitor.