Video summary
A Conversation With Jeremy Epling
Main summary
Key takeaways
Key technological concepts (AI + security/GRC)
- Unified “entity context” for the whole company: Vanta’s agent vision is to centralize “everything about the company” so AI can answer security and governance questions grounded in real organizational data (vendors, assets, personnel, access, etc.).
- “Trust graph” as the context substrate: Vanta describes its core approach as a trust graph that ingests data from many systems and links it to security controls, frameworks, and organizational structure.
- AI intelligence layer that turns context into action: An agent (the Vanta agent) can answer questions or run workflows (e.g., vendor reviews, questionnaires, framework adoption analysis) using that trust graph.
Product features and capabilities highlighted
Large integration + test coverage
- 400+ integrations
- 1,400+ tests being added
- The agent can access data to build a comprehensive context model.
Context & memory features (launched in the fall)
Agent context can include:
- Crawled data after signing with Vanta
- Manually managed business priorities (via a markdown/CloudMD-like workflow)
- Automatically linked risk objects from the system (e.g., “high priority risks”)
Human-in-the-loop write actions
- The agent typically performs read-only analysis and requires approval before modifying security policies/controls or taking write actions.
- The goal is to progressively earn trust so the agent can do more drafting/remediation safely.
Automated analysis workflows
Example shown:
- Running an access review
- Automatically discovering policy-to-resource access logic
- Mapping it to HR/IDP groups (e.g., from HiBob/Okta) to find gaps
- Proposing removals
Readout and routing via chat tools
- Uses an MCP server so engineers can use Vanta intelligence from tools like:
- Claude / ChatGPT
- Coding environments such as Cursor
- Routes security questionnaires and workflows into Slack, enabling non-Vanta users (e.g., legal) to engage without logging into Vanta.
Proactive, continuous monitoring direction (“shift-left”)
Moves from reactive “answer last-minute audit questions” to continuous/triggered agents that re-evaluate risks and controls when:
- Jira changes
- risks change
- backlog/PRDs/RFCs update
Also mentions custom agent “skills” running on triggers to detect deviations between:
- current state and ideal state earlier in development.
Risk register agent integration
A recent release adds risk infrastructure into the agent context:
- Ties risks to vendors, controls, assets
- Supports risk treatment plans and risk quantification workflows
Data inventory / privacy enablement (GDPR/Europe)
- The agent can generate records of processing activities
- Can generate privacy impact assessments
- Can connect privacy artifacts to risk
Contract analysis (“customer commitments”)
- Extracts and monitors security-related contract redlines/custom commitments
- Supports automation of incident notification workflows when commitments are triggered (e.g., subprocessor changes)
Remediation support through coding agents
- Provides remediation instructions for failing tests (example: encryption failures)
- Coding agents can analyze codebases (e.g., Terraform/AWS CLI preferences)
- Mentions a Claude plugin for remediation assistance
Scoping to avoid “messy soup”
Introduces workspaces/business units/framework scoping so answers are correct for subsets like:
- PCI scope
- product families
- acquired companies / M&A separation
Emphasizes scoping as critical to avoid inaccurate generalized guidance.
Analysis and guidance themes (how customers use it)
-
Business goals → security requirements mapping
- Interprets OKRs / business expansion plans (e.g., entering Europe)
- Produces a differential analysis of required standards and controls (e.g., SOC 2 → ISO 27001 → GDPR → EU AI Act)
-
Gap analysis and prioritization
- For “where are our gaps,” the agent can use context to identify:
- missing controls/policies
- high-priority risk systems and access issues
- questionnaire-derived control changes
- For “where are our gaps,” the agent can use context to identify:
-
Procurement / vendor management
- Vendor reviews and questionnaire-style workflows are highlighted as agent use cases.
-
Access review, onboarding/offboarding, attestation, framework adoption
- Mentioned as common areas where the agent helps automate repeated GRC tasks.
-
Transforming reporting
- Example: the agent pulls risk/goal data while Claude generates Google Slides / board-ready decks
- Demonstrates a “best-of-breed” multi-agent/tool approach
Conceptual framing: current vs ideal state and continuous “loops”
- Discusses “current-to-ideal state” as the final AI objective:
- AI deeply understands current company state and the desired ideal state
- Continuously manages the delta as deviations appear
- References loop engineering (goal-driven, deviation detection, continuous running) as aligned with the direction Vanta describes.
Main speakers / sources
- Jeremy Epling (guest; primary speaker)
- Unspecified interviewer / host (“All right, Jeremy…”)