AptlyStar

Vanta

Query compliance status and manage evidence in Vanta

Instructions d'utilisation

Integrate Vanta into the workflow. Monitor compliance frameworks, controls, and automated tests; find failing test entities; manage evidence documents including file upload, download, and submission; and track people, policies, vendors, monitored computers, vulnerabilities, and risk scenarios. Requires Vanta OAuth client credentials.

Outils

vanta_list_frameworks

List the compliance frameworks (e.g., SOC 2, ISO 27001) available in a Vanta account with completion counts

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
pageSizenumberNonMaximum number of items per page (1-100, default 10)
pageCursorstringNonPagination cursor: pass the endCursor from the previous response to fetch the next page

Sortie

ParamètreTypeDescription
frameworksarrayFrameworks in the Vanta account
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_get_framework

Get a Vanta compliance framework by ID, including its requirement categories and mapped controls

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
frameworkIdstringOuiUnique ID of the framework (e.g., soc2)

Sortie

ParamètreTypeDescription
frameworkjsonThe requested framework with requirement categories

vanta_list_framework_controls

List the controls that belong to a specific Vanta compliance framework

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
frameworkIdstringOuiUnique ID of the framework (e.g., soc2)
pageSizenumberNonMaximum number of items per page (1-100, default 10)
pageCursorstringNonPagination cursor: pass the endCursor from the previous response to fetch the next page

Sortie

ParamètreTypeDescription
controlsarrayControls belonging to the framework
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_list_controls

List the security controls in a Vanta account, optionally filtered by framework

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
frameworkMatchesAnystringNonComma-separated framework IDs to filter controls by (e.g., soc2,iso27001)
pageSizenumberNonMaximum number of items per page (1-100, default 10)
pageCursorstringNonPagination cursor: pass the endCursor from the previous response to fetch the next page

Sortie

ParamètreTypeDescription
controlsarrayControls matching the filters
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_get_control

Get a Vanta security control by ID, including its status and evidence pass/fail counts

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
controlIdstringOuiUnique ID of the control

Sortie

ParamètreTypeDescription
controljsonThe requested control with status and evidence counts

vanta_list_control_tests

List the automated tests mapped to a specific Vanta control

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
controlIdstringOuiUnique ID of the control
pageSizenumberNonMaximum number of items per page (1-100, default 10)
pageCursorstringNonPagination cursor: pass the endCursor from the previous response to fetch the next page

Sortie

ParamètreTypeDescription
testsarrayTests mapped to the control
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_list_control_documents

List the evidence documents mapped to a specific Vanta control

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
controlIdstringOuiUnique ID of the control
pageSizenumberNonMaximum number of items per page (1-100, default 10)
pageCursorstringNonPagination cursor: pass the endCursor from the previous response to fetch the next page

Sortie

ParamètreTypeDescription
documentsarrayDocuments mapped to the control
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_list_tests

List the automated compliance tests in a Vanta account, with filters for status, framework, integration, control, owner, and category

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
statusFilterstringNonFilter by test status: OK, DEACTIVATED, NEEDS_ATTENTION, IN_PROGRESS, INVALID, or NOT_APPLICABLE
frameworkFilterstringNonFilter by framework ID (e.g., soc2)
integrationFilterstringNonFilter by integration ID (e.g., aws)
controlFilterstringNonFilter by control ID
ownerFilterstringNonFilter by owner user ID
categoryFilterstringNonFilter by test category (e.g., ACCOUNTS_ACCESS, COMPUTERS, INFRASTRUCTURE, POLICIES, VULNERABILITY_MANAGEMENT)
isInRolloutbooleanNonFilter by whether the test is in rollout
pageSizenumberNonMaximum number of items per page (1-100, default 10)
pageCursorstringNonPagination cursor: pass the endCursor from the previous response to fetch the next page

Sortie

ParamètreTypeDescription
testsarrayTests matching the filters
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_get_test

Get a Vanta automated compliance test by ID, including its status and remediation info

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
testIdstringOuiUnique ID of the test (e.g., test-aws-cloudtrail-enabled)

Sortie

ParamètreTypeDescription
testjsonThe requested test

vanta_list_test_entities

List the failing or deactivated resource entities for a specific Vanta test, useful for finding exactly which resources need remediation

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
testIdstringOuiUnique ID of the test (e.g., test-aws-cloudtrail-enabled)
entityStatusstringNonFilter entities by status: FAILING or DEACTIVATED
pageSizenumberNonMaximum number of items per page (1-100, default 10)
pageCursorstringNonPagination cursor: pass the endCursor from the previous response to fetch the next page

Sortie

ParamètreTypeDescription
entitiesarrayResource entities for the test
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_list_documents

List the evidence documents in a Vanta account, optionally filtered by framework or document status

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
frameworkMatchesAnystringNonComma-separated framework IDs to filter documents by (e.g., soc2,iso27001)
statusMatchesAnystringNonComma-separated document statuses to filter by: "Needs document", "Needs update", "Not relevant", "OK"
pageSizenumberNonMaximum number of items per page (1-100, default 10)
pageCursorstringNonPagination cursor: pass the endCursor from the previous response to fetch the next page

Sortie

ParamètreTypeDescription
documentsarrayDocuments matching the filters
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_get_document

Get a Vanta evidence document by ID, including its renewal schedule and deactivation status

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
documentIdstringOuiUnique ID of the document

Sortie

ParamètreTypeDescription
documentjsonThe requested document

vanta_list_document_uploads

List the files uploaded to a specific Vanta evidence document

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
documentIdstringOuiUnique ID of the document
pageSizenumberNonMaximum number of items per page (1-100, default 10)
pageCursorstringNonPagination cursor: pass the endCursor from the previous response to fetch the next page

Sortie

ParamètreTypeDescription
uploadsarrayFiles uploaded to the document
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_upload_document_file

Upload an evidence file to a Vanta document. Requires credentials with the vanta-api.documents:upload scope.

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
documentIdstringOuiUnique ID of the document to attach the file to
filefileNonThe evidence file to upload
fileContentstringNonBase64-encoded file content (alternative to file)
fileNamestringNonOptional file name override
mimeTypestringNonMIME type of the file (e.g., application/pdf); used when uploading base64 content, since uploaded files already carry their own type
descriptionstringNonDescription of the uploaded evidence (e.g., "Q3 access review evidence")
effectiveAtDatestringNonISO 8601 date indicating when the document is effective from

Sortie

ParamètreTypeDescription
uploadjsonMetadata of the uploaded file

vanta_download_document_file

Download a file previously uploaded to a Vanta evidence document and store it in execution files

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
documentIdstringOuiUnique ID of the document
uploadedFileIdstringOuiUnique ID of the uploaded file (from List Document Uploads)

Sortie

ParamètreTypeDescription
filefileDownloaded file stored in execution files
namestringName of the downloaded file
mimeTypestringMIME type of the downloaded file
sizenumberSize of the downloaded file in bytes

vanta_submit_document

Submit a Vanta document collection for review so uploaded evidence becomes visible to auditors. Requires credentials with write access.

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
documentIdstringOuiUnique ID of the document to submit

Sortie

ParamètreTypeDescription
documentIdstringID of the submitted document
submittedbooleanWhether the document collection was submitted

vanta_list_people

List the people tracked in a Vanta account with employment status, group membership, and security task completion

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
emailAndNameFilterstringNonFilter people by email address or name
employmentStatusstringNonFilter by employment status: UPCOMING, CURRENT, ON_LEAVE, INACTIVE, or FORMER
groupIdsMatchesAnystringNonComma-separated group IDs to filter people by
tasksSummaryStatusMatchesAnystringNonComma-separated task summary statuses to filter by: NONE, DUE_SOON, OVERDUE, COMPLETE, PAUSED, OFFBOARDING_DUE_SOON, OFFBOARDING_OVERDUE, OFFBOARDING_COMPLETE
taskTypeMatchesAnystringNonComma-separated task types to filter by: COMPLETE_TRAININGS, ACCEPT_POLICIES, COMPLETE_CUSTOM_TASKS, COMPLETE_CUSTOM_OFFBOARDING_TASKS, INSTALL_DEVICE_MONITORING, COMPLETE_BACKGROUND_CHECKS
taskStatusMatchesAnystringNonComma-separated task statuses to filter by: COMPLETE, DUE_SOON, OVERDUE, NONE
pageSizenumberNonMaximum number of items per page (1-100, default 10)
pageCursorstringNonPagination cursor: pass the endCursor from the previous response to fetch the next page

Sortie

ParamètreTypeDescription
peoplearrayPeople matching the filters
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_get_person

Get a person tracked in Vanta by ID, including employment, leave, and security task status

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
personIdstringOuiUnique ID of the person

Sortie

ParamètreTypeDescription
personjsonThe requested person

vanta_list_policies

List the security policies in a Vanta account with approval status and version info

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
pageSizenumberNonMaximum number of items per page (1-100, default 10)
pageCursorstringNonPagination cursor: pass the endCursor from the previous response to fetch the next page

Sortie

ParamètreTypeDescription
policiesarrayPolicies in the Vanta account
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_get_policy

Get a Vanta security policy by ID, including its approval status and latest approved version documents

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
policyIdstringOuiUnique ID of the policy

Sortie

ParamètreTypeDescription
policyjsonThe requested policy

vanta_list_vendors

List the vendors tracked in a Vanta account with risk levels, contract dates, and security review schedules

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
namestringNonFilter vendors by name
statusMatchesAnystringNonComma-separated vendor statuses to filter by: MANAGED, ARCHIVED, IN_PROCUREMENT
pageSizenumberNonMaximum number of items per page (1-100, default 10)
pageCursorstringNonPagination cursor: pass the endCursor from the previous response to fetch the next page

Sortie

ParamètreTypeDescription
vendorsarrayVendors matching the filters
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_get_vendor

Get a Vanta vendor by ID, including risk levels, contract details, and authentication info

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
vendorIdstringOuiUnique ID of the vendor

Sortie

ParamètreTypeDescription
vendorjsonThe requested vendor

vanta_list_monitored_computers

List the monitored computers in a Vanta account with screenlock, disk encryption, password manager, and antivirus check outcomes

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
complianceStatusFilterMatchesAnystringNonComma-separated compliance issues to filter by: PWM_NOT_INSTALLED, HD_NOT_ENCRYPTED, AV_NOT_INSTALLED, SCREENLOCK_NOT_CONFIGURED, LAST_CHECK_OVER_14_DAYS
pageSizenumberNonMaximum number of items per page (1-100, default 10)
pageCursorstringNonPagination cursor: pass the endCursor from the previous response to fetch the next page

Sortie

ParamètreTypeDescription
computersarrayMonitored computers matching the filters
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_list_vulnerabilities

List the vulnerabilities detected across a Vanta account with filters for severity, fixability, SLA deadlines, package, and integration

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
qstringNonSearch query for vulnerabilities
severitystringNonFilter by severity: LOW, MEDIUM, HIGH, or CRITICAL
isFixAvailablebooleanNonFilter by whether a fix is available
isDeactivatedbooleanNonFilter by whether vulnerability monitoring is deactivated
includeVulnerabilitiesWithoutSlasbooleanNonInclude vulnerabilities that have no SLA deadline
packageIdentifierstringNonFilter by the affected package identifier
externalVulnerabilityIdstringNonFilter by external vulnerability ID (e.g., a CVE identifier)
integrationIdstringNonFilter by the integration that detected the vulnerability
vulnerableAssetIdstringNonFilter by the vulnerable asset ID
slaDeadlineAfterDatestringNonOnly include vulnerabilities with an SLA deadline after this ISO 8601 date
slaDeadlineBeforeDatestringNonOnly include vulnerabilities with an SLA deadline before this ISO 8601 date
pageSizenumberNonMaximum number of items per page (1-100, default 10)
pageCursorstringNonPagination cursor: pass the endCursor from the previous response to fetch the next page

Sortie

ParamètreTypeDescription
vulnerabilitiesarrayVulnerabilities matching the filters
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_list_vulnerability_remediations

List remediated vulnerabilities in a Vanta account with detection, SLA deadline, and remediation dates

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
integrationIdstringNonFilter by the integration that detected the vulnerability
severitystringNonFilter by severity: LOW, MEDIUM, HIGH, or CRITICAL
isRemediatedOnTimebooleanNonFilter by whether the vulnerability was remediated before its SLA deadline
remediatedAfterDatestringNonOnly include remediations completed after this ISO 8601 date
remediatedBeforeDatestringNonOnly include remediations completed before this ISO 8601 date
pageSizenumberNonMaximum number of items per page (1-100, default 10)
pageCursorstringNonPagination cursor: pass the endCursor from the previous response to fetch the next page

Sortie

ParamètreTypeDescription
remediationsarrayVulnerability remediations matching the filters
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_list_vulnerable_assets

List the assets associated with vulnerabilities in a Vanta account (servers, repositories, workstations, and more)

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
qstringNonSearch query for vulnerable assets
integrationIdstringNonFilter by the integration scanning the asset
assetTypestringNonFilter by asset type: SERVER, SERVERLESS_FUNCTION, CONTAINER, CONTAINER_REPOSITORY, CONTAINER_REPOSITORY_IMAGE, CODE_REPOSITORY, MANIFEST_FILE, WORKSTATION, or OTHER
assetExternalAccountIdstringNonFilter by the external account ID the asset belongs to
pageSizenumberNonMaximum number of items per page (1-100, default 10)
pageCursorstringNonPagination cursor: pass the endCursor from the previous response to fetch the next page

Sortie

ParamètreTypeDescription
assetsarrayVulnerable assets matching the filters
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_get_vulnerable_asset

Get a vulnerable asset in Vanta by ID, including the scanners reporting it and per-scanner asset details

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
vulnerableAssetIdstringOuiUnique ID of the vulnerable asset

Sortie

ParamètreTypeDescription
assetjsonThe requested vulnerable asset

vanta_list_risk_scenarios

List the risk scenarios in a Vanta risk register with likelihood/impact scores, treatment decisions, and review status

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
searchStringstringNonSearch string to filter risk scenarios
includeIgnoredbooleanNonInclude ignored risk scenarios
typestringNonFilter by scenario type: "Risk Scenario" or "Enterprise Risk"
ownerMatchesAnystringNonComma-separated owner emails to filter by
categoryMatchesAnystringNonComma-separated risk categories to filter by
ciaCategoryMatchesAnystringNonComma-separated CIA categories to filter by: Confidentiality, Integrity, Availability
treatmentTypeMatchesAnystringNonComma-separated treatments to filter by: Mitigate, Transfer, Avoid, Accept
inherentScoreGroupMatchesAnystringNonComma-separated inherent score groups to filter by: "Very low", Low, Med, High, Critical
residualScoreGroupMatchesAnystringNonComma-separated residual score groups to filter by: "Very low", Low, Med, High, Critical
reviewStatusMatchesAnystringNonComma-separated review statuses to filter by: APPROVED, DRAFT, NOT_REVIEWED, AWAITING_SUBMISSION, PENDING_APPROVAL, REQUESTED_CHANGES
orderBystringNonField to order results by: description or createdAt
pageSizenumberNonMaximum number of items per page (1-100, default 10)
pageCursorstringNonPagination cursor: pass the endCursor from the previous response to fetch the next page

Sortie

ParamètreTypeDescription
riskScenariosarrayRisk scenarios matching the filters
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_get_risk_scenario

Get a Vanta risk scenario by ID, including its scores, treatment decision, and review status

Entrée

ParamètreTypeObligatoireDescription
clientIdstringOuiVanta OAuth application client ID
clientSecretstringOuiVanta OAuth application client secret
regionstringNonVanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
riskScenarioIdstringOuiUnique ID of the risk scenario

Sortie

ParamètreTypeDescription
riskScenariojsonThe requested risk scenario

On this page