Compliance Integrations / Vanta

Vanta Integration

Push security findings to Vanta as compliance evidence. OAuth connection, continuous sync every few minutes, auto-created tests.

Overview

AttackerView connects to Vanta as a vulnerability scanning integration. Once connected, AttackerView automatically syncs all your security findings to Vanta every few minutes. Vanta uses this data to power automated compliance tests across SOC 2, ISO 27001, PCI DSS, and HIPAA.

The integration is one-directional: AttackerView pushes data to Vanta. Vanta handles SLA tracking, remediation deadlines, and audit evidence from there.

Prerequisites

  • An active AttackerView account on the Watchtower plan or higher
  • A Vanta account with permission to connect integrations
  • At least one domain added to AttackerView

Setup

Vanta uses OAuth, so you never share API keys or secrets. The entire setup takes about 30 seconds.

Connect from AttackerView

  1. Go to Settings in your AttackerView dashboard
  2. Under Compliance Integrations, click Connect to Vanta
  3. You'll be redirected to Vanta's authorization page
  4. Review the permissions and click Allow
  5. You'll be redirected back to AttackerView. The connection is live immediately.

Connect from Vanta

You can also start the connection from Vanta's side:

  1. In Vanta, go to Integrations
  2. Search for AttackerView under the Vulnerability Scanner category
  3. Click Connect and follow the authorization flow

Both paths end the same way: an OAuth handshake that securely links your accounts.

What gets synced

AttackerView syncs three resource types to Vanta:

Vulnerable Components

One per domain. Represents the asset being scanned.

FieldValue
Display nameYour domain (e.g., example.com)
VersionTimestamp of the latest completed scan
SeverityHighest severity across open findings for this domain
LinkDeep link to the domain in AttackerView

API Endpoint Vulnerabilities

One per non-CVE finding. Configuration and header issues like missing security headers, CORS misconfigurations, etc.

FieldValue
TitleFinding title (e.g., "Missing Content-Security-Policy Header")
SeverityCVSS score (0-10), categorical mapping
URLThe affected endpoint or domain URL
DescriptionTechnical evidence from the scan
RemediationPlatform-specific fix steps when available (e.g., Cloudflare, Nginx, Apache), with a link to full guidance
LinkDeep link to the specific finding in AttackerView

Package Vulnerabilities

One per CVE finding. Known software vulnerabilities with CVE identifiers detected in your tech stack.

FieldValue
Package nameThe affected software (e.g., "Apache HTTP Server")
CVE IDCVE identifier (e.g., CVE-2021-41773)
SeverityReal NVD CVSS score when available
ResolvableWhether a fix version exists
ReachableWhether the vulnerability was actively confirmed exploitable (verified CVEs only)
LinkDeep link to the specific finding in AttackerView

Domains with zero open findings are still synced as components (severity 0). This keeps your asset inventory accurate in Vanta even when everything is clean.

Sync behavior

  • Syncs run every few minutes, automatically in the background
  • Each sync sends the complete state of all your domains and all open findings. Vanta replaces its previous data entirely.
  • When a finding is fixed and no longer in the sync, Vanta automatically marks it as remediated
  • Risk-accepted findings are excluded (they represent acknowledged risks, not open vulnerabilities)
  • The sync is tenant-wide: all domains across your account are included in every sync, regardless of which domain was scanned most recently

This "full state" approach means you don't need to worry about stale data. Every sync is a complete picture of your current vulnerability posture.

Severity mapping

AttackerView maps finding severity to CVSS scores that Vanta classifies into its own severity buckets:

AttackerView severityCVSS score sentVanta classification
Critical9.5Critical
High7.5High
Medium5.0Medium
Low2.5Low
Info0.5Low

For CVE findings with known CVSS scores in the NVD database, the real score is used instead of the categorical mapping above.

SLA tracking

Vanta calculates its own remediation SLAs. You don't need to configure anything on the AttackerView side.

  • The SLA clock starts when Vanta first sees a vulnerability (the first sync that includes it)
  • Deadlines are based on severity (Critical ~15-30 days, High ~30 days, Medium ~60 days, Low ~90 days). Your Vanta admin can customize these.
  • When AttackerView stops sending a finding (because it's been fixed), Vanta marks it as remediated and records whether it met the SLA deadline
  • Vanta sends email alerts as SLA deadlines approach

What your auditor sees

Once connected, Vanta automatically:

  • Creates ~32 automated compliance tests in Vanta, mapped to SOC 2 (CC7.1, CC6.1), ISO 27001 (A.8.8), PCI DSS, and HIPAA controls
  • Shows pass/fail status on each test based on your current vulnerability state
  • Tracks remediation timelines with SLA compliance metrics
  • Provides audit-ready evidence exports with full metadata and timestamps

Each vulnerability in Vanta links back to AttackerView, so auditors can click through to the full technical detail, evidence, and remediation guidance.

You do not need to manually create tests, map controls, or configure anything in Vanta. The predefined vulnerability scanner resource type handles all of this automatically.

Disconnecting

You can disconnect from either side:

  • From AttackerView: Go to Settings and click "Disconnect" next to the Vanta integration. This revokes the OAuth tokens and stops all syncing.
  • From Vanta: Remove AttackerView from Vanta's Integrations page. AttackerView detects the revoked access on the next sync attempt and disables the integration.

Vulnerability data already in Vanta is retained per Vanta's data retention policies. Reconnecting starts a fresh sync of your current state.

Troubleshooting

"Connection expired. Please reconnect."

Vanta OAuth tokens expire if unused for more than 3 hours. This can happen if the background sync is interrupted for an extended period (e.g., a maintenance window). Click "Disconnect" then "Connect to Vanta" to re-authorize.

Findings aren't appearing in Vanta

The sync runs every few minutes. Check the "Last synced" timestamp in Settings. If there's an error message, the sync may have failed. Common causes: expired tokens (reconnect), or no open findings to sync (expected if everything is clean).

Some findings are missing

Only findings with open status are synced. Risk-accepted findings and fixed findings are excluded. If a finding was recently fixed, it will disappear from Vanta on the next sync.

Vanta shows different severity than AttackerView

Vanta maps the CVSS score we send into its own severity buckets. The boundaries may differ slightly from our label-based severity. For CVE findings, Vanta receives the real NVD CVSS score, which may differ from AttackerView's categorical label.

FAQ

Can I use Vanta and Drata at the same time?

Yes. Each integration operates independently. The same findings appear in both platforms.

What happens if I downgrade from a paid plan?

The integration is paused, not deleted. Syncs stop until you re-upgrade. Vanta retains the last-synced data. Re-upgrading resumes syncing automatically.

Does Vanta send data back to AttackerView?

No. The integration is one-directional. AttackerView pushes findings to Vanta. Vanta does not send webhooks or data back.

How do I know the sync is working?

Check Settings for the last sync timestamp and any error messages. In Vanta, you can verify by checking the Vulnerabilities page or the Evidence tab on any auto-created test.

See also