> To the extent they integrate with your cloud providers and security tools,
What happens when Vanta/Drata are compromised?
A mass-exploit of their customers?
What happens when Vanta/Drata are compromised?
A mass-exploit of their customers?
Edit: Their software should really check and refuse to work if someone does that but obviously Vanta doesn't care. They can begin scanning and billing.
Thanks for the feedback. What we should probably do is take the credential, start scanning, and then nag them with a failing test about overly-permissive roles. Our own role is an easy check because we know what to expect, but there's other best practices here we can check for (and in some cases do, though not 100% comprehensively across all clouds.)