Tracecat

Vanta MCP server

Inspect tests, controls, frameworks, and vulnerabilities across your Vanta tenant.

Compliance
stdio
Official docs

About

Connect Tracecat to Vanta to inspect tests, controls, and evidence for compliance leads and GRC engineers running SOC 2, ISO 27001, HIPAA, and PCI programs. You can pull failing tests and the underlying entities causing the failure for fast triage. From there, walk controls to their mapped frameworks, review evidence documents, and track vulnerabilities with precision.

Setup

  1. 1

    Sign in with OAuth

    You'll authorize Tracecat to access Vanta on your behalf. No API keys to manage.

  2. 2

    Select the Vanta tile in the Tracecat MCP catalog

    Open the MCP catalog in your workspace, select the Vanta tile, and complete the OAuth flow.

  3. 3

    Enable Vanta in your agent

    In your ai.agent action or Agents tools tab, select Vanta from the MCP integrations dropdown.

Tools

testsRetrieve security and compliance tests filtered by status, integration, or framework.
list_test_entitiesGet the resources monitored by a test, including failing entities.
controlsList security controls or fetch one by ID with framework mappings.
list_control_testsEnumerate the automated tests that validate a specific control.
list_control_documentsList documents providing evidence for a control.
documentsList or retrieve compliance documents by ID.
frameworksList compliance frameworks with completion metrics.
list_framework_controlsRetrieve the controls associated with a given framework.
vulnerabilitiesList detected vulnerabilities or retrieve one by ID with CVE metadata.
integrationsList connected Vanta integrations and inspect their resource kinds.

Deploy the Vanta MCP server in minutes

Connect your security agents to 50+ hosted MCP servers.

Self-host free