Vanta doing things that don't scale
The origination story and tactics used to gain initial traction
Summary
- Vanta began by offering manual compliance audits using spreadsheets.
- The founders personally conducted security reviews for clients.
- This service-first approach built domain expertise.
- They productized their manual processes over time.
- The team focused intensely on solving immediate pain points.
- This hands-on strategy created strong customer relationships.
- It demonstrates how services can bootstrap product development.
- Eventually, these experiences informed their automation strategy.
Key Points
| Key Problem | Compliance complexity |
| Unconventional Solution | Manual spreadsheet audits for clients |
| Execution | Founders conducted security reviews |
| Outcome | Service-first approach built product insights |
In the world of startups, there’s a well-known piece of advice from Y Combinator’s Paul Graham: “Do things that don’t scale.” This counterintuitive wisdom suggests that in the early days of building a company, founders should embrace labor-intensive, manual processes that could never work at scale—but might be exactly what’s needed to get initial traction. Few companies embody this principle more vividly than Vanta, the security compliance automation platform that grew from manual spreadsheet consultations to a $1.6 billion unicorn by starting with some decidedly unscalable methods.
The Security Compliance Puzzle
The story of Vanta begins with a puzzle that intrigued founder Christina Cacioppo in 2017. At the time, high-profile data breaches were making headlines—Equifax, Uber, Sony, Target—and the 2016 U.S. election had put cybersecurity in the spotlight. As Cacioppo observed these incidents, she noticed something curious: many of these breaches seemed to happen for surprisingly simple reasons, like someone not enabling two-factor authentication or leaving a cloud storage bucket publicly accessible.
“Why are they leaving the front door open?” she wondered. These weren’t incompetent organizations; they were staffed with smart, motivated people. Yet they were still experiencing security failures that, in retrospect, seemed easily preventable.
This puzzle led Cacioppo to start investigating the state of security in the tech industry, particularly among startups and growing companies. What she discovered was a significant gap between intention and execution. Founders and executives knew they should take security seriously—both for normative reasons and business purposes—but they faced two major obstacles.
First, many didn’t know exactly what “good security” looked like for a company at their stage. What specific measures should a seed-stage or Series A startup implement? Second, even when they did know what to do, security work competed for priority with more immediate business needs like finding product-market fit, growing revenue, and retaining customers.
As Cacioppo explained in an interview, “While security was objectively very important, it was really hard to trade that off against building a feature to save your biggest customer or pushing your roadmap forward so you can earn more business. And so security got caught in this gap where founders wanted to take it seriously, knew they should, but couldn’t, from a business perspective, feel like they could justify prioritizing it.”
The Path to Founding Vanta
Christina Cacioppo’s journey to founding Vanta wasn’t a straight line. Despite harboring entrepreneurial ambitions since her undergraduate days, she initially didn’t see herself as someone who could start a company. Growing up in the Midwest and not studying computer science, she felt that the founder path wasn’t for someone like her.
Her perspective changed dramatically when she worked at Union Square Ventures (USV), an early-stage venture firm in New York, right after college. For two years, her job was essentially to meet with founders all day long. Through these encounters, she realized that all sorts of people start companies, and while there were some common traits, there was no single founder archetype.
This realization was transformative, but Cacioppo still felt she needed to develop her technical skills. She taught herself to code to gain confidence in her technical abilities, worked at Dropbox, and eventually found herself puzzling over the security compliance challenges that would lead to Vanta.
The Manual Beginnings: Consultants with Spreadsheets
When Vanta started in 2018, there were no products like it on the market. SOC 2 compliance—a security framework that has become increasingly important for B2B software companies—was a completely manual process handled by consultants with spreadsheets. If you asked these consultants whether “compliance automation” was possible, they would tell you it wasn’t.
As Cacioppo later wrote on LinkedIn, “When we started Vanta, there were no products like it. SOC 2 was a manual process with consultants and spreadsheets, and if you asked them, they’d tell you ‘compliance automation’ wasn’t possible. (Trust me…)”
This manual, consultant-driven approach to compliance was not only time-consuming but also expensive, putting it out of reach for many startups. The typical process involved hiring specialized consultants who would create custom spreadsheets to track security controls, collect evidence manually, and guide companies through the lengthy audit process.
Rather than immediately trying to build a fully automated solution, Vanta started by essentially becoming those consultants themselves—but with a vision for eventual automation. They began by working directly with companies, helping them prepare for SOC 2 compliance using the same manual spreadsheet-based processes that were standard in the industry.
This hands-on approach allowed the Vanta team to deeply understand the pain points in the compliance process. They could see firsthand what parts were most frustrating for companies, where the most time was spent, and what aspects could potentially be automated.
The Research Phase: Six Months of Interviews and Testing
Before writing a single line of code for their product, the Vanta team spent six months interviewing people, testing approaches, and iterating on their ideas. This extensive research phase was crucial for ensuring they were building the right solution.
They spoke with founders, CTOs, security professionals, and compliance consultants to understand the various perspectives on security compliance. They learned about the technical challenges, the business pressures, and the regulatory requirements that shaped how companies approached security.
Initially, Vanta tried offering CTOs checklists for what good security means, but they didn’t find much traction with this approach. However, when they pivoted to focusing specifically on preparing companies for compliance certification, they struck a chord.
They discovered that while security in the abstract was important to companies, compliance certification provided a concrete business benefit: it helped companies close deals faster. Especially for B2B startups selling to larger enterprises, having a SOC 2 certification could significantly accelerate the sales process by addressing security concerns upfront.
As Cacioppo explained, “We believed startups would get SOC 2s because they were such a sales accelerant—almost a cheat code to closing big customers.”
This insight became central to Vanta’s value proposition. They weren’t just helping companies improve their security; they were helping them grow their business by removing a significant barrier to sales.
The Unscalable Approach: Manual Gap Assessments
One of the most labor-intensive aspects of Vanta’s early work was conducting gap assessments for companies. A gap assessment identifies the differences between a company’s current security practices and the requirements of a compliance framework like SOC 2.
Traditionally, these assessments were done by consultants who would interview stakeholders, review documentation, and manually check systems to identify gaps. Vanta started by doing these assessments themselves, working closely with early customers to understand their security posture.
What made this approach particularly unscalable was that each company had unique systems, processes, and security challenges. There was no one-size-fits-all template that could be applied. The Vanta team had to deeply engage with each company’s specific situation, often spending hours in meetings and reviewing documentation.
However, this manual process provided invaluable insights. As they worked with more companies, they began to identify patterns and common challenges. They could see which security controls were most difficult for startups to implement, which evidence was hardest to collect, and which aspects of the process caused the most friction.
According to reports, Cacioppo validated Vanta’s early concepts by adapting one company’s gap assessment for others, a process that confirmed the need for a more streamlined approach to compliance. This manual adaptation of assessments from one company to another was exactly the kind of unscalable work that would inform their eventual product.
Building the Product: From Spreadsheets to Software
After six months of research and manual consulting work, the Vanta team had a clear understanding of the problem they were solving and began building their software product. Their goal was to automate as much of the compliance process as possible, turning what had been a manual, spreadsheet-driven exercise into a streamlined, software-enabled workflow.
The product they built connected directly to a company’s infrastructure and systems—cloud providers, code repositories, HR systems, and more—to automatically collect evidence of security controls. This eliminated much of the manual work involved in preparing for a compliance audit.
They also created a dashboard that showed companies their progress toward compliance, highlighting gaps that needed to be addressed and providing guidance on how to fix issues. This transformed compliance from a black box into a transparent, manageable process.
What made Vanta’s approach particularly powerful was that it wasn’t just automating the collection of evidence; it was also providing ongoing monitoring. Rather than compliance being a point-in-time assessment, Vanta made it a continuous process, alerting companies when something changed that might affect their compliance status.
The Funding Challenge: Building Without Validation
When Cacioppo pitched seed funds for Vanta in spring 2018, she faced significant skepticism. Smart investors turned them down because, as she recalls, “startups just don’t get SOC 2s”—which was accurate at the time. The conventional wisdom was that only larger, more established companies needed compliance certifications.
This lack of external validation made the early days particularly challenging. The Vanta team was building a product for a market that many people didn’t believe existed. They had to have conviction in their vision even when others didn’t see it.
Rather than focusing on raising large amounts of funding, they concentrated on building their business with the idea that if they did so successfully, funding would take care of itself. As Cacioppo noted, “VCs want to fund businesses that don’t need their money as much as businesses that do.”
This bootstrap mentality forced them to be disciplined and focused. They couldn’t afford to build features that weren’t directly addressing customer needs or to pursue market segments that weren’t ready for their solution.
Creating a New Category: Compliance Automation
What Vanta was attempting was not just to build a better version of existing solutions; they were creating an entirely new category: compliance automation. This was a significant challenge because they had to convince the market not only that their product was good but that the category itself was viable.
The traditional compliance industry was skeptical. Consultants who had built careers on manual compliance processes were quick to dismiss the idea that software could automate significant portions of their work. They argued that compliance was too nuanced, too company-specific, and too judgment-dependent to be automated.
Vanta had to prove them wrong by demonstrating that automation could not only work but could produce better, more consistent results than manual processes. They did this by focusing on the most standardizable aspects of compliance first—the collection of evidence from systems and the monitoring of security controls—while still acknowledging the role of human judgment in the overall process.
The Snowball Effect: Making Compliance Accessible
By making SOC 2 compliance more accessible to smaller companies without in-house expertise, Vanta started what Cacioppo calls a “snowball rolling.” They lowered the barrier to entry for compliance certification, which meant more companies could obtain SOC 2, which in turn made it more expected in the market.
As more startups got SOC 2 certified with Vanta’s help, their customers began to expect the same from other vendors. This created a virtuous cycle where compliance certification became increasingly standard, even for early-stage companies.
The impact of this shift has been profound. As Cacioppo noted in 2023, “Now, proving trust via a SOC 2 or Trust Report is table-stakes for B2B companies. Three-quarters of the B2B startups in the current YC batch work with Vanta!”
This transformation of the market validated Vanta’s initial insight that startups would want compliance certification if it were more accessible and clearly tied to business growth. What had seemed like a niche need in 2018 had become a standard requirement by 2023.
Scaling Beyond the Unscalable
As Vanta grew, they had to transition from the hands-on, consultative approach that characterized their early days to a more scalable model. This transition wasn’t about abandoning their commitment to customer success but about finding ways to provide the same level of guidance and support through their product and specialized teams.
They built out educational resources, templates, and guided workflows that could provide much of the expertise that had previously required direct consultation. They created a network of audit partners who were familiar with their platform, streamlining the audit process for their customers.
They also expanded their product to support additional compliance frameworks beyond SOC 2, including ISO 27001, HIPAA, and GDPR. This allowed them to serve a broader range of companies and to support their existing customers as their compliance needs evolved.
Throughout this scaling process, they maintained their focus on the core value proposition: making compliance accessible and turning it into a business accelerator rather than just a checkbox exercise.
The Results: From Manual Spreadsheets to a $1.6 Billion Unicorn
The results of Vanta’s journey from manual spreadsheet consultations to automated compliance platform have been remarkable. By 2023, the company had:
- Raised over $200 million in funding
- Achieved a valuation of $1.6 billion
- Served more than 3,000 customers
- Helped companies complete thousands of compliance certifications
- Established compliance automation as a recognized category
What began as a puzzle about why smart companies were experiencing seemingly preventable security breaches had evolved into a platform that was fundamentally changing how companies approach security and compliance.
Lessons from Vanta’s Unscalable Beginnings
Vanta’s journey from manual spreadsheet consultations to automated compliance platform offers several valuable lessons for entrepreneurs:
- Start by doing things that don’t scale. Vanta’s willingness to work directly with companies using manual processes gave them the insights needed to build an effective automated solution. Don’t be afraid to start with labor-intensive approaches if they help you understand the problem deeply.
- Focus on a specific, valuable outcome. Rather than trying to solve all security problems, Vanta focused specifically on helping companies achieve compliance certification, which had a clear business benefit in accelerating sales.
- Be willing to create a new category. Sometimes the biggest opportunities involve not just building a better product in an existing category but creating an entirely new category. This is harder but can lead to category leadership if successful.
- Look for business benefits, not just technical ones. Vanta succeeded because they tied compliance to busin
(Content truncated due to size limit. Use line ranges to read in chunks)
Comments (0)
There are no comments yet :(