Vanta Integration with DefectDojo
Vanta Integration with DefectDojo
Vanta is a compliance automation and trust management platform used to prepare for and maintain frameworks such as SOC 2, ISO 27001, and HIPAA. It connects to the systems a company runs on, such as cloud providers, identity providers, and code hosting, through what it calls integrations, then runs automated tests against those systems to check whether controls are in place. A failing test lists the resources that do not pass. Vanta offers an API with OAuth client credentials, which the DefectDojo Pro Vanta connector uses.
Vanta Integration with DefectDojo
We connected Vanta to DefectDojo Pro because compliance gaps were being tracked in one place and security findings in another, and the people fixing them were often the same engineers. The connector imports failing compliance tests from Vanta. Each failing resource of a failing test becomes a finding, grouped under a Record for the Vanta integration it belongs to, plus an organization-wide catch-all for tests that belong to no integration. Once those Records map to Assets, a cloud bucket without encryption or an account without MFA is tracked like any other finding: assigned, given an SLA, and closed when the next sync no longer reports it.
Why Vanta Matters
Compliance controls fail quietly between audits, and every failure is usually a security issue as well.
- Vanta tests run against live systems, so they catch configuration drift that a once-a-year audit would only find late.
- A failing test names the specific resources that fail, which is what an engineer needs to act.
- Tests are tied to the systems Vanta is connected to, which points each failure at the team that runs that system.
- Compliance teams work in Vanta, while engineering triages security work somewhere else. Without a bridge, fixes are coordinated by email and screenshots.
Advantages of This Integration
What we gained by syncing Vanta into DefectDojo Pro:
- Compliance failures next to security findings. Failing tests land on the same Assets as scanner findings, so a team sees all of its open risk in one queue.
- Per-resource findings. Each failing resource of a failing test is its own finding. One control failing across 25 resources produces 25 findings that can be assigned, accepted, or closed separately.
- Grouped by Vanta integration. The connector creates a Record per Vanta integration, plus an organization-wide catch-all, so findings follow the system they came from.
- Scheduled syncs. Discover and Sync run every 6, 12, or 24 hours, so a test that starts failing reaches DefectDojo without anyone exporting it.
- Lifecycle on every sync. Each Sync adds new findings and marks findings that no longer appear as inactive, so a fixed resource drops out on its own.
- DefectDojo workflow on top. SLAs, risk acceptance, notes, assignment, metrics, and Downstream Connector or Jira ticketing all apply to compliance findings.
How This Integration Works
Vanta is a DefectDojo Pro Upstream Connector. Connectors are not part of Community Edition, and there is no file parser for Vanta data, so this connector is the supported path.
1. Create OAuth credentials in Vanta. In Vanta, open Settings > Developer Console and create an app of the Manage Vanta type. Note its client ID and client secret. The connector docs warn that other app types will not have the access this connector needs.
2. Add the connector. In the Pro UI, open Connect > Upstream, find Vanta under Available Connectors, and click Add Configuration. Enter:
- Location: your Vanta API URL.
- Client ID and Client Secret: the OAuth credentials from step 1.
- Minimum Severity (optional): a floor below which findings are not imported.
- Label: a name that tells this configuration apart from others.
Then set the Discovery and Synchronization schedules, choose whether to enable Auto-Mapping, and submit. DefectDojo checks what the credentials can see and warns you if the account reports no data.
3. Discover integrations. Discover creates a Record for each Vanta integration and one for the organization-wide catch-all. With Auto-Mapping on, each Record is matched to an Asset with the same name or a new Asset is created. With it off, Records wait in the Unmapped list for you to assign them.
4. Sync failing tests. For every mapped Record, Sync imports findings into an Engagement named Global Connectors under the mapped Asset, with a separate Test for this connector. Later syncs update that Test.
Data Granularity: What Gets Imported
The connector documentation describes the structure of what is imported rather than a field-by-field mapping, so the table sticks to what is documented.
| DefectDojo Object or Field | Source in Vanta | Notes |
|---|---|---|
| Record | Vanta integration | One per integration |
| Catch-all Record | Tests that belong to no integration | Organization-wide |
| Finding | Failing resource of a failing test | One finding per failing resource |
| Severity filter | Minimum Severity setting | Findings below the floor are not imported |
| Engagement and Test | Created by DefectDojo | Global Connectors Engagement, one Test for this connector |
| Status changes | Sync comparison | New findings added, absent findings marked inactive |
| Field adjustments | Connector Field Mappings | Rearrange or combine fields the connector sends, per scan type |
Field mappings under Connect > Field Mappings can change how values the connector sends land in DefectDojo fields. They cannot add data the connector does not send.
Use Cases
Closing audit gaps before the auditor finds them: Failing tests on the cloud provider integration are mapped to the platform team's Asset. The team works them alongside its CVEs, and the compliance lead can see in DefectDojo which failures are still open and how long they have been open.
Routing by system owner: The identity provider's Record maps to the IT Asset and the code hosting Record maps to the engineering Asset, so each failure reaches the people who can change that system.
Tickets for compliance work: Findings on mapped Assets are pushed to Jira or a Downstream Connector, so compliance fixes appear in the backlog with a link back to DefectDojo.
Accepting known exceptions: Where a control failure is a documented exception, the finding is risk-accepted in DefectDojo with an expiration date, so the exception is reviewed again instead of being forgotten.
Operational Tips
- Create a Manage Vanta app in the Developer Console. Other app types will not have the access the connector needs.
- Expect one finding per failing resource. A broad test failing across hundreds of resources creates hundreds of findings, so review the first sync before mapping every Record.
- Decide where the catch-all Record goes. Tests that belong to no integration land there, so map it to an Asset owned by the compliance or security team.
- Start with a Minimum Severity setting if the first import is large, then lower it as the backlog shrinks.
- Use Ignored rather than Delete for Records you do not want. Deleted Records return on the next Discover.
- Turn on the Connector Health Warning notification under Connections in your notification settings, so a revoked client secret is reported instead of syncs silently stopping.