Trigger reviews from Vanta

onnect Vanta to MineOS so vendors approved in Vanta automatically get privacy reviews, with Vanta’s questionnaires and documents as context for Mira AI.

Many teams run vendor security reviews in Vanta. The Vanta integration connects those reviews to MineOS, so when a vendor reaches the right stage in Vanta, MineOS adds it to your inventory and starts the privacy work: processing activities, privacy assessments and any follow-up reviews. Vanta stays your source for security evidence, and MineOS becomes your system of record for privacy.

How it works

  1. A vendor's status changes in Vanta, for example from Procurement to Active.
  2. If the vendor meets your conditions, MineOS adds it to your inventory, or updates it if it's already there.
  3. MineOS pulls the vendor's details, questionnaires and documents from Vanta.
  4. Vendor scout researches the vendor to fill in anything still missing.
  5. Your workflow rules open the right assessments and assign owners.
  6. Mira AI drafts the assessments using what came from Vanta, and your team reviews and completes them.

Examples of what MineOS can bring in from Vanta

From VantaHow MineOS uses it
Vendor name, domain, status and ownerCreates or matches the vendor and fills in its core details
Headquarters and data storage locationsFills in location details and helps identify international transfers
Sub-processorsRecords who else handles the data
Integrations with your internal systemsShows how the vendor connects to the rest of your inventory
CertificationsAdds security and compliance credentials to the vendor's record
Questionnaires and answersSaved as context for Mira when it drafts assessments
Attached documents, such as DPAs and security reportsSaved as evidence for Mira's drafts

Because the full questionnaires and documents come across, your privacy team doesn't need to ask the vendor the same questions again. Mira reuses answers about data types, retention, purposes, sub-processors and AI use from Vanta's security review.

Trigger conditions

Choose which vendors start a workflow in MineOS, so only those that need a privacy review come across. For example:

  • Status change: only vendors that move to Active in Vanta
  • Custom field: only vendors where a field such as "Processes personal data" is set to Yes

Vendors that don't meet your conditions stay in Vanta only.

What happens next

Once the vendor is in MineOS, your workflow rules take over. For example:

  • Opening a privacy assessment for every vendor that processes personal data
  • Opening a transfer assessment when the vendor stores data outside your main region
  • Opening an AI assessment when the vendor uses AI
  • Assigning owners, inviting collaborators and notifying teams by email or Slack
  • Updating the vendor's status when all assessments are completed

See Automate privacy by design with workflows for how rules fit together.

Access and permissions

MineOS connects to Vanta with read-only access, so it never changes your data in Vanta. Review outcomes from MineOS aren't sent back to Vanta.

Set up the integration

The Vanta integration is set up together with your MineOS team. You'll need a Vanta API token with read access, and your team will help you choose trigger conditions and configure the rules for your workflow. Contact your customer success manager to get started.


Did this page help you?