Video summary

A Conversation With Jeremy Epling

Main summary

Key takeaways

Technology

Key technological concepts (AI + security/GRC)

  • Unified “entity context” for the whole company: Vanta’s agent vision is to centralize “everything about the company” so AI can answer security and governance questions grounded in real organizational data (vendors, assets, personnel, access, etc.).
  • “Trust graph” as the context substrate: Vanta describes its core approach as a trust graph that ingests data from many systems and links it to security controls, frameworks, and organizational structure.
  • AI intelligence layer that turns context into action: An agent (the Vanta agent) can answer questions or run workflows (e.g., vendor reviews, questionnaires, framework adoption analysis) using that trust graph.

Product features and capabilities highlighted

Large integration + test coverage

  • 400+ integrations
  • 1,400+ tests being added
  • The agent can access data to build a comprehensive context model.

Context & memory features (launched in the fall)

Agent context can include:

  • Crawled data after signing with Vanta
  • Manually managed business priorities (via a markdown/CloudMD-like workflow)
  • Automatically linked risk objects from the system (e.g., “high priority risks”)

Human-in-the-loop write actions

  • The agent typically performs read-only analysis and requires approval before modifying security policies/controls or taking write actions.
  • The goal is to progressively earn trust so the agent can do more drafting/remediation safely.

Automated analysis workflows

Example shown:

  • Running an access review
  • Automatically discovering policy-to-resource access logic
  • Mapping it to HR/IDP groups (e.g., from HiBob/Okta) to find gaps
  • Proposing removals

Readout and routing via chat tools

  • Uses an MCP server so engineers can use Vanta intelligence from tools like:
    • Claude / ChatGPT
    • Coding environments such as Cursor
  • Routes security questionnaires and workflows into Slack, enabling non-Vanta users (e.g., legal) to engage without logging into Vanta.

Proactive, continuous monitoring direction (“shift-left”)

Moves from reactive “answer last-minute audit questions” to continuous/triggered agents that re-evaluate risks and controls when:

  • Jira changes
  • risks change
  • backlog/PRDs/RFCs update

Also mentions custom agent “skills” running on triggers to detect deviations between:

  • current state and ideal state earlier in development.

Risk register agent integration

A recent release adds risk infrastructure into the agent context:

  • Ties risks to vendors, controls, assets
  • Supports risk treatment plans and risk quantification workflows

Data inventory / privacy enablement (GDPR/Europe)

  • The agent can generate records of processing activities
  • Can generate privacy impact assessments
  • Can connect privacy artifacts to risk

Contract analysis (“customer commitments”)

  • Extracts and monitors security-related contract redlines/custom commitments
  • Supports automation of incident notification workflows when commitments are triggered (e.g., subprocessor changes)

Remediation support through coding agents

  • Provides remediation instructions for failing tests (example: encryption failures)
  • Coding agents can analyze codebases (e.g., Terraform/AWS CLI preferences)
  • Mentions a Claude plugin for remediation assistance

Scoping to avoid “messy soup”

Introduces workspaces/business units/framework scoping so answers are correct for subsets like:

  • PCI scope
  • product families
  • acquired companies / M&A separation

Emphasizes scoping as critical to avoid inaccurate generalized guidance.

Analysis and guidance themes (how customers use it)

  • Business goals → security requirements mapping

    • Interprets OKRs / business expansion plans (e.g., entering Europe)
    • Produces a differential analysis of required standards and controls (e.g., SOC 2 → ISO 27001 → GDPR → EU AI Act)
  • Gap analysis and prioritization

    • For “where are our gaps,” the agent can use context to identify:
      • missing controls/policies
      • high-priority risk systems and access issues
      • questionnaire-derived control changes
  • Procurement / vendor management

    • Vendor reviews and questionnaire-style workflows are highlighted as agent use cases.
  • Access review, onboarding/offboarding, attestation, framework adoption

    • Mentioned as common areas where the agent helps automate repeated GRC tasks.
  • Transforming reporting

    • Example: the agent pulls risk/goal data while Claude generates Google Slides / board-ready decks
    • Demonstrates a “best-of-breed” multi-agent/tool approach

Conceptual framing: current vs ideal state and continuous “loops”

  • Discusses “current-to-ideal state” as the final AI objective:
    • AI deeply understands current company state and the desired ideal state
    • Continuously manages the delta as deviations appear
  • References loop engineering (goal-driven, deviation detection, continuous running) as aligned with the direction Vanta describes.

Main speakers / sources

  • Jeremy Epling (guest; primary speaker)
  • Unspecified interviewer / host (“All right, Jeremy…”)

Original video