AptlyStar

Vanta

Query compliance status and manage evidence in Vanta

使用说明

Integrate Vanta into the workflow. Monitor compliance frameworks, controls, and automated tests; find failing test entities; manage evidence documents including file upload, download, and submission; and track people, policies, vendors, monitored computers, vulnerabilities, and risk scenarios. Requires Vanta OAuth client credentials.

工具

vanta_list_frameworks

List the compliance frameworks (e.g., SOC 2, ISO 27001) available in a Vanta account with completion counts

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
pageSizenumber否Maximum number of items per page (1-100, default 10)
pageCursorstring否Pagination cursor: pass the endCursor from the previous response to fetch the next page

输出

参数类型描述
frameworksarrayFrameworks in the Vanta account
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_get_framework

Get a Vanta compliance framework by ID, including its requirement categories and mapped controls

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
frameworkIdstring是Unique ID of the framework (e.g., soc2)

输出

参数类型描述
frameworkjsonThe requested framework with requirement categories

vanta_list_framework_controls

List the controls that belong to a specific Vanta compliance framework

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
frameworkIdstring是Unique ID of the framework (e.g., soc2)
pageSizenumber否Maximum number of items per page (1-100, default 10)
pageCursorstring否Pagination cursor: pass the endCursor from the previous response to fetch the next page

输出

参数类型描述
controlsarrayControls belonging to the framework
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_list_controls

List the security controls in a Vanta account, optionally filtered by framework

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
frameworkMatchesAnystring否Comma-separated framework IDs to filter controls by (e.g., soc2,iso27001)
pageSizenumber否Maximum number of items per page (1-100, default 10)
pageCursorstring否Pagination cursor: pass the endCursor from the previous response to fetch the next page

输出

参数类型描述
controlsarrayControls matching the filters
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_get_control

Get a Vanta security control by ID, including its status and evidence pass/fail counts

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
controlIdstring是Unique ID of the control

输出

参数类型描述
controljsonThe requested control with status and evidence counts

vanta_list_control_tests

List the automated tests mapped to a specific Vanta control

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
controlIdstring是Unique ID of the control
pageSizenumber否Maximum number of items per page (1-100, default 10)
pageCursorstring否Pagination cursor: pass the endCursor from the previous response to fetch the next page

输出

参数类型描述
testsarrayTests mapped to the control
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_list_control_documents

List the evidence documents mapped to a specific Vanta control

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
controlIdstring是Unique ID of the control
pageSizenumber否Maximum number of items per page (1-100, default 10)
pageCursorstring否Pagination cursor: pass the endCursor from the previous response to fetch the next page

输出

参数类型描述
documentsarrayDocuments mapped to the control
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_list_tests

List the automated compliance tests in a Vanta account, with filters for status, framework, integration, control, owner, and category

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
statusFilterstring否Filter by test status: OK, DEACTIVATED, NEEDS_ATTENTION, IN_PROGRESS, INVALID, or NOT_APPLICABLE
frameworkFilterstring否Filter by framework ID (e.g., soc2)
integrationFilterstring否Filter by integration ID (e.g., aws)
controlFilterstring否Filter by control ID
ownerFilterstring否Filter by owner user ID
categoryFilterstring否Filter by test category (e.g., ACCOUNTS_ACCESS, COMPUTERS, INFRASTRUCTURE, POLICIES, VULNERABILITY_MANAGEMENT)
isInRolloutboolean否Filter by whether the test is in rollout
pageSizenumber否Maximum number of items per page (1-100, default 10)
pageCursorstring否Pagination cursor: pass the endCursor from the previous response to fetch the next page

输出

参数类型描述
testsarrayTests matching the filters
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_get_test

Get a Vanta automated compliance test by ID, including its status and remediation info

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
testIdstring是Unique ID of the test (e.g., test-aws-cloudtrail-enabled)

输出

参数类型描述
testjsonThe requested test

vanta_list_test_entities

List the failing or deactivated resource entities for a specific Vanta test, useful for finding exactly which resources need remediation

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
testIdstring是Unique ID of the test (e.g., test-aws-cloudtrail-enabled)
entityStatusstring否Filter entities by status: FAILING or DEACTIVATED
pageSizenumber否Maximum number of items per page (1-100, default 10)
pageCursorstring否Pagination cursor: pass the endCursor from the previous response to fetch the next page

输出

参数类型描述
entitiesarrayResource entities for the test
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_list_documents

List the evidence documents in a Vanta account, optionally filtered by framework or document status

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
frameworkMatchesAnystring否Comma-separated framework IDs to filter documents by (e.g., soc2,iso27001)
statusMatchesAnystring否Comma-separated document statuses to filter by: "Needs document", "Needs update", "Not relevant", "OK"
pageSizenumber否Maximum number of items per page (1-100, default 10)
pageCursorstring否Pagination cursor: pass the endCursor from the previous response to fetch the next page

输出

参数类型描述
documentsarrayDocuments matching the filters
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_get_document

Get a Vanta evidence document by ID, including its renewal schedule and deactivation status

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
documentIdstring是Unique ID of the document

输出

参数类型描述
documentjsonThe requested document

vanta_list_document_uploads

List the files uploaded to a specific Vanta evidence document

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
documentIdstring是Unique ID of the document
pageSizenumber否Maximum number of items per page (1-100, default 10)
pageCursorstring否Pagination cursor: pass the endCursor from the previous response to fetch the next page

输出

参数类型描述
uploadsarrayFiles uploaded to the document
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_upload_document_file

Upload an evidence file to a Vanta document. Requires credentials with the vanta-api.documents:upload scope.

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
documentIdstring是Unique ID of the document to attach the file to
filefile否The evidence file to upload
fileContentstring否Base64-encoded file content (alternative to file)
fileNamestring否Optional file name override
mimeTypestring否MIME type of the file (e.g., application/pdf); used when uploading base64 content, since uploaded files already carry their own type
descriptionstring否Description of the uploaded evidence (e.g., "Q3 access review evidence")
effectiveAtDatestring否ISO 8601 date indicating when the document is effective from

输出

参数类型描述
uploadjsonMetadata of the uploaded file

vanta_download_document_file

Download a file previously uploaded to a Vanta evidence document and store it in execution files

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
documentIdstring是Unique ID of the document
uploadedFileIdstring是Unique ID of the uploaded file (from List Document Uploads)

输出

参数类型描述
filefileDownloaded file stored in execution files
namestringName of the downloaded file
mimeTypestringMIME type of the downloaded file
sizenumberSize of the downloaded file in bytes

vanta_submit_document

Submit a Vanta document collection for review so uploaded evidence becomes visible to auditors. Requires credentials with write access.

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
documentIdstring是Unique ID of the document to submit

输出

参数类型描述
documentIdstringID of the submitted document
submittedbooleanWhether the document collection was submitted

vanta_list_people

List the people tracked in a Vanta account with employment status, group membership, and security task completion

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
emailAndNameFilterstring否Filter people by email address or name
employmentStatusstring否Filter by employment status: UPCOMING, CURRENT, ON_LEAVE, INACTIVE, or FORMER
groupIdsMatchesAnystring否Comma-separated group IDs to filter people by
tasksSummaryStatusMatchesAnystring否Comma-separated task summary statuses to filter by: NONE, DUE_SOON, OVERDUE, COMPLETE, PAUSED, OFFBOARDING_DUE_SOON, OFFBOARDING_OVERDUE, OFFBOARDING_COMPLETE
taskTypeMatchesAnystring否Comma-separated task types to filter by: COMPLETE_TRAININGS, ACCEPT_POLICIES, COMPLETE_CUSTOM_TASKS, COMPLETE_CUSTOM_OFFBOARDING_TASKS, INSTALL_DEVICE_MONITORING, COMPLETE_BACKGROUND_CHECKS
taskStatusMatchesAnystring否Comma-separated task statuses to filter by: COMPLETE, DUE_SOON, OVERDUE, NONE
pageSizenumber否Maximum number of items per page (1-100, default 10)
pageCursorstring否Pagination cursor: pass the endCursor from the previous response to fetch the next page

输出

参数类型描述
peoplearrayPeople matching the filters
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_get_person

Get a person tracked in Vanta by ID, including employment, leave, and security task status

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
personIdstring是Unique ID of the person

输出

参数类型描述
personjsonThe requested person

vanta_list_policies

List the security policies in a Vanta account with approval status and version info

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
pageSizenumber否Maximum number of items per page (1-100, default 10)
pageCursorstring否Pagination cursor: pass the endCursor from the previous response to fetch the next page

输出

参数类型描述
policiesarrayPolicies in the Vanta account
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_get_policy

Get a Vanta security policy by ID, including its approval status and latest approved version documents

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
policyIdstring是Unique ID of the policy

输出

参数类型描述
policyjsonThe requested policy

vanta_list_vendors

List the vendors tracked in a Vanta account with risk levels, contract dates, and security review schedules

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
namestring否Filter vendors by name
statusMatchesAnystring否Comma-separated vendor statuses to filter by: MANAGED, ARCHIVED, IN_PROCUREMENT
pageSizenumber否Maximum number of items per page (1-100, default 10)
pageCursorstring否Pagination cursor: pass the endCursor from the previous response to fetch the next page

输出

参数类型描述
vendorsarrayVendors matching the filters
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_get_vendor

Get a Vanta vendor by ID, including risk levels, contract details, and authentication info

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
vendorIdstring是Unique ID of the vendor

输出

参数类型描述
vendorjsonThe requested vendor

vanta_list_monitored_computers

List the monitored computers in a Vanta account with screenlock, disk encryption, password manager, and antivirus check outcomes

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
complianceStatusFilterMatchesAnystring否Comma-separated compliance issues to filter by: PWM_NOT_INSTALLED, HD_NOT_ENCRYPTED, AV_NOT_INSTALLED, SCREENLOCK_NOT_CONFIGURED, LAST_CHECK_OVER_14_DAYS
pageSizenumber否Maximum number of items per page (1-100, default 10)
pageCursorstring否Pagination cursor: pass the endCursor from the previous response to fetch the next page

输出

参数类型描述
computersarrayMonitored computers matching the filters
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_list_vulnerabilities

List the vulnerabilities detected across a Vanta account with filters for severity, fixability, SLA deadlines, package, and integration

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
qstring否Search query for vulnerabilities
severitystring否Filter by severity: LOW, MEDIUM, HIGH, or CRITICAL
isFixAvailableboolean否Filter by whether a fix is available
isDeactivatedboolean否Filter by whether vulnerability monitoring is deactivated
includeVulnerabilitiesWithoutSlasboolean否Include vulnerabilities that have no SLA deadline
packageIdentifierstring否Filter by the affected package identifier
externalVulnerabilityIdstring否Filter by external vulnerability ID (e.g., a CVE identifier)
integrationIdstring否Filter by the integration that detected the vulnerability
vulnerableAssetIdstring否Filter by the vulnerable asset ID
slaDeadlineAfterDatestring否Only include vulnerabilities with an SLA deadline after this ISO 8601 date
slaDeadlineBeforeDatestring否Only include vulnerabilities with an SLA deadline before this ISO 8601 date
pageSizenumber否Maximum number of items per page (1-100, default 10)
pageCursorstring否Pagination cursor: pass the endCursor from the previous response to fetch the next page

输出

参数类型描述
vulnerabilitiesarrayVulnerabilities matching the filters
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_list_vulnerability_remediations

List remediated vulnerabilities in a Vanta account with detection, SLA deadline, and remediation dates

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
integrationIdstring否Filter by the integration that detected the vulnerability
severitystring否Filter by severity: LOW, MEDIUM, HIGH, or CRITICAL
isRemediatedOnTimeboolean否Filter by whether the vulnerability was remediated before its SLA deadline
remediatedAfterDatestring否Only include remediations completed after this ISO 8601 date
remediatedBeforeDatestring否Only include remediations completed before this ISO 8601 date
pageSizenumber否Maximum number of items per page (1-100, default 10)
pageCursorstring否Pagination cursor: pass the endCursor from the previous response to fetch the next page

输出

参数类型描述
remediationsarrayVulnerability remediations matching the filters
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_list_vulnerable_assets

List the assets associated with vulnerabilities in a Vanta account (servers, repositories, workstations, and more)

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
qstring否Search query for vulnerable assets
integrationIdstring否Filter by the integration scanning the asset
assetTypestring否Filter by asset type: SERVER, SERVERLESS_FUNCTION, CONTAINER, CONTAINER_REPOSITORY, CONTAINER_REPOSITORY_IMAGE, CODE_REPOSITORY, MANIFEST_FILE, WORKSTATION, or OTHER
assetExternalAccountIdstring否Filter by the external account ID the asset belongs to
pageSizenumber否Maximum number of items per page (1-100, default 10)
pageCursorstring否Pagination cursor: pass the endCursor from the previous response to fetch the next page

输出

参数类型描述
assetsarrayVulnerable assets matching the filters
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_get_vulnerable_asset

Get a vulnerable asset in Vanta by ID, including the scanners reporting it and per-scanner asset details

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
vulnerableAssetIdstring是Unique ID of the vulnerable asset

输出

参数类型描述
assetjsonThe requested vulnerable asset

vanta_list_risk_scenarios

List the risk scenarios in a Vanta risk register with likelihood/impact scores, treatment decisions, and review status

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
searchStringstring否Search string to filter risk scenarios
includeIgnoredboolean否Include ignored risk scenarios
typestring否Filter by scenario type: "Risk Scenario" or "Enterprise Risk"
ownerMatchesAnystring否Comma-separated owner emails to filter by
categoryMatchesAnystring否Comma-separated risk categories to filter by
ciaCategoryMatchesAnystring否Comma-separated CIA categories to filter by: Confidentiality, Integrity, Availability
treatmentTypeMatchesAnystring否Comma-separated treatments to filter by: Mitigate, Transfer, Avoid, Accept
inherentScoreGroupMatchesAnystring否Comma-separated inherent score groups to filter by: "Very low", Low, Med, High, Critical
residualScoreGroupMatchesAnystring否Comma-separated residual score groups to filter by: "Very low", Low, Med, High, Critical
reviewStatusMatchesAnystring否Comma-separated review statuses to filter by: APPROVED, DRAFT, NOT_REVIEWED, AWAITING_SUBMISSION, PENDING_APPROVAL, REQUESTED_CHANGES
orderBystring否Field to order results by: description or createdAt
pageSizenumber否Maximum number of items per page (1-100, default 10)
pageCursorstring否Pagination cursor: pass the endCursor from the previous response to fetch the next page

输出

参数类型描述
riskScenariosarrayRisk scenarios matching the filters
pageInfojsonCursor pagination info for the returned page; pass endCursor as pageCursor to fetch the next page

vanta_get_risk_scenario

Get a Vanta risk scenario by ID, including its scores, treatment decision, and review status

输入

参数类型必填描述
clientIdstring是Vanta OAuth application client ID
clientSecretstring是Vanta OAuth application client secret
regionstring否Vanta API region: "us" (api.vanta.com, default) or "gov" (api.vanta-gov.com)
riskScenarioIdstring是Unique ID of the risk scenario

输出

参数类型描述
riskScenariojsonThe requested risk scenario

On this page