Listing failing tests is the easy half; the useful half is that the agent has your repository open at the same time, so a failing check can become an infrastructure-as-code change rather than a ticket. The remote server is in beta and Admin-only, which makes it a lead's tool rather than one you hand to the whole team.
Vanta's remote server — https://mcp.vanta.com/mcp for US tenants, with separate Europe and Australia endpoints — letting Claude Code, Cursor, Perplexity, Codex and other MCP clients call the Vanta API on your behalf.
- Failing compliance tests listed, with which entities are out of scope and the context needed to fix them
- Controls browsed with their framework mappings, associated tests and linked evidence documents
- Vendor risk work: vendors reviewed, security assessments run, risk attributes and compliance documentation tracked
- Vulnerable assets surfaced and remediation progress monitored
- Policy documents listed, downloaded and uploaded across the program
- Framework requirements enumerated and coverage gaps identified across SOC 2, ISO 27001 and more
Vanta Admin — the server is not accessible to non-Admin users — and one of the supported AI tools. Setup is a URL plus an OAuth sign-in, with no key to paste. The Claude Code plugin bundles the same server with the /vanta:fix-test and /vanta:list-tests commands and a remediation skill.
One command plus a key — npx @vantasdk/vanta-mcp-server, then supply credentials
