Labsco
MCP SERVER · OFFICIAL PROJECT

Vanta MCP Server

by VantaInc

Turn a failing compliance test into a remediation plan without leaving the editor.

Regulatory Compliance & AI Governance
Summary
The compliance backlog, read where the fix would be written.

Listing failing tests is the easy half; the useful half is that the agent has your repository open at the same time, so a failing check can become an infrastructure-as-code change rather than a ticket. The remote server is in beta and Admin-only, which makes it a lead's tool rather than one you hand to the whole team.

What it is

Vanta's remote server — https://mcp.vanta.com/mcp for US tenants, with separate Europe and Australia endpoints — letting Claude Code, Cursor, Perplexity, Codex and other MCP clients call the Vanta API on your behalf.

What you get
  • Failing compliance tests listed, with which entities are out of scope and the context needed to fix them
  • Controls browsed with their framework mappings, associated tests and linked evidence documents
  • Vendor risk work: vendors reviewed, security assessments run, risk attributes and compliance documentation tracked
  • Vulnerable assets surfaced and remediation progress monitored
  • Policy documents listed, downloaded and uploaded across the program
  • Framework requirements enumerated and coverage gaps identified across SOC 2, ISO 27001 and more
Requirements

Vanta Admin — the server is not accessible to non-Admin users — and one of the supported AI tools. Setup is a URL plus an OAuth sign-in, with no key to paste. The Claude Code plugin bundles the same server with the /vanta:fix-test and /vanta:list-tests commands and a remediation skill.

Setup effort

One command plus a key — npx @vantasdk/vanta-mcp-server, then supply credentials