Compliance Integrations / Vanta
Push security findings to Vanta as compliance evidence. OAuth connection, continuous sync every few minutes, auto-created tests.
AttackerView connects to Vanta as a vulnerability scanning integration. Once connected, AttackerView automatically syncs all your security findings to Vanta every few minutes. Vanta uses this data to power automated compliance tests across SOC 2, ISO 27001, PCI DSS, and HIPAA.
The integration is one-directional: AttackerView pushes data to Vanta. Vanta handles SLA tracking, remediation deadlines, and audit evidence from there.
Vanta uses OAuth, so you never share API keys or secrets. The entire setup takes about 30 seconds.
You can also start the connection from Vanta's side:
Both paths end the same way: an OAuth handshake that securely links your accounts.
AttackerView syncs three resource types to Vanta:
One per domain. Represents the asset being scanned.
| Field | Value |
|---|---|
| Display name | Your domain (e.g., example.com) |
| Version | Timestamp of the latest completed scan |
| Severity | Highest severity across open findings for this domain |
| Link | Deep link to the domain in AttackerView |
One per non-CVE finding. Configuration and header issues like missing security headers, CORS misconfigurations, etc.
| Field | Value |
|---|---|
| Title | Finding title (e.g., "Missing Content-Security-Policy Header") |
| Severity | CVSS score (0-10), categorical mapping |
| URL | The affected endpoint or domain URL |
| Description | Technical evidence from the scan |
| Remediation | Platform-specific fix steps when available (e.g., Cloudflare, Nginx, Apache), with a link to full guidance |
| Link | Deep link to the specific finding in AttackerView |
One per CVE finding. Known software vulnerabilities with CVE identifiers detected in your tech stack.
| Field | Value |
|---|---|
| Package name | The affected software (e.g., "Apache HTTP Server") |
| CVE ID | CVE identifier (e.g., CVE-2021-41773) |
| Severity | Real NVD CVSS score when available |
| Resolvable | Whether a fix version exists |
| Reachable | Whether the vulnerability was actively confirmed exploitable (verified CVEs only) |
| Link | Deep link to the specific finding in AttackerView |
Domains with zero open findings are still synced as components (severity 0). This keeps your asset inventory accurate in Vanta even when everything is clean.
This "full state" approach means you don't need to worry about stale data. Every sync is a complete picture of your current vulnerability posture.
AttackerView maps finding severity to CVSS scores that Vanta classifies into its own severity buckets:
| AttackerView severity | CVSS score sent | Vanta classification |
|---|---|---|
| Critical | 9.5 | Critical |
| High | 7.5 | High |
| Medium | 5.0 | Medium |
| Low | 2.5 | Low |
| Info | 0.5 | Low |
For CVE findings with known CVSS scores in the NVD database, the real score is used instead of the categorical mapping above.
Vanta calculates its own remediation SLAs. You don't need to configure anything on the AttackerView side.
Once connected, Vanta automatically:
Each vulnerability in Vanta links back to AttackerView, so auditors can click through to the full technical detail, evidence, and remediation guidance.
You do not need to manually create tests, map controls, or configure anything in Vanta. The predefined vulnerability scanner resource type handles all of this automatically.
You can disconnect from either side:
Vulnerability data already in Vanta is retained per Vanta's data retention policies. Reconnecting starts a fresh sync of your current state.
Vanta OAuth tokens expire if unused for more than 3 hours. This can happen if the background sync is interrupted for an extended period (e.g., a maintenance window). Click "Disconnect" then "Connect to Vanta" to re-authorize.
The sync runs every few minutes. Check the "Last synced" timestamp in Settings. If there's an error message, the sync may have failed. Common causes: expired tokens (reconnect), or no open findings to sync (expected if everything is clean).
Only findings with open status are synced. Risk-accepted findings and fixed findings are excluded. If a finding was recently fixed, it will disappear from Vanta on the next sync.
Vanta maps the CVSS score we send into its own severity buckets. The boundaries may differ slightly from our label-based severity. For CVE findings, Vanta receives the real NVD CVSS score, which may differ from AttackerView's categorical label.
Yes. Each integration operates independently. The same findings appear in both platforms.
The integration is paused, not deleted. Syncs stop until you re-upgrade. Vanta retains the last-synced data. Re-upgrading resumes syncing automatically.
No. The integration is one-directional. AttackerView pushes findings to Vanta. Vanta does not send webhooks or data back.
Check Settings for the last sync timestamp and any error messages. In Vanta, you can verify by checking the Vulnerabilities page or the Evidence tab on any auto-created test.