Compliance at scale and why TAM is a distraction with Christina Cacioppo of Vanta

31 Mar 2026 · 57 min · 34 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

Christina Cacioppo (Vanta) explains why “compliance” is the buying moment for startups, how Vanta automates SOC 2/ISO 27001-style trust management, and how AI is shifting compliance from manual prep to continuous control monitoring and evidence generation.

Guest background

Christina Cacioppo founded Vanta in 2018 after prior work at Dropbox (including launching Dropbox Paper) and later researching why startups struggle with security/compliance processes driven by enterprise contracts.

Key claims

Compliance is what customers ask for (not security), especially early; Vanta defines “trust management” for 15,000+ customers and supports ongoing audit readiness. SOC 2’s policy goal is protecting customer data. SOC 2 is not a fixed checklist like PCI; it requires logging useful events and proving controls. LLMs can help map messy inputs (policies, Jira, AWS evidence) into audit-ready artifacts, but continuous monitoring still needs real system integration. AI will reduce hourly compliance labor and let humans focus on strategy/risk.

Notable examples

Dropbox Paper lacked “secure/compliant/pen tested” contract language; Equifax data loss illustrates investor/cost cynicism; GitHub reportedly answers 92% of questionnaires via Vanta with human approval. Vanta “tests” controls like unit tests by scanning PRs in GitHub/GitLab.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

The Vanta Story and Compliance Need

0:46 to 2:16

Christina explains the necessity of compliance in security programs for startups.

“But they know that they have to do it this quarter.”

The Compliance Moment for Startups

2:17 to 3:56

Discussion on how compliance is often the trigger for startups to enhance security.

“I worked on what at the time was a new product, Dropbox Paper.”

Founding Vanta: A Personal Journey

3:57 to 5:18

Christina shares her journey from Dropbox to founding Vanta, focusing on compliance challenges.

“I mean, it was our experience with Stripe as well, where we had just run into the problem before.”

Target Audience and Product Layers

5:19 to 7:21

Christina discusses Vanta's diverse customer base and the product's layered structure.

“Our growth rate's actually quickened the last couple of years and quarters and months.”

Compliance and Control Mechanisms

7:22 to 8:50

Insights on how Vanta helps companies manage compliance controls and testing.

“Well, you know, in some ways it's like if control door with monitor, you just pass the logs to an auditor.”

Marketing and Messaging Strategies

8:51 to 10:40

Discussion on Vanta's marketing strategies, including memorable advertising campaigns.

“You're the battery of unit tests for the compliance rules.”

Compliance Regulations and Market Needs

10:41 to 14:01

Overview of various compliance regulations and their importance for different markets.

“And then go back to the other part of the question.”

Understanding SOC 2 Policy Goals

14:01 to 14:50

Explore the objectives behind SOC 2 compliance and its implications.

“Can you describe the policy goals that something like SOC 2 seems to accomplish?”

The Impact of Data Breaches

14:50 to 15:36

Discusses the consequences of significant data breaches and public perception.

“And so when they invented JavaScript, they wanted to kind of ride off the Java halo as an easy-to-do programming language, despite the fact Java and JavaScript share no exactly commonality at all.”

Investor Attitudes Towards Data Security

15:36 to 16:29

Analyzes how data breaches affect investor confidence and corporate value.

“It's very hard to find that moment in the Equifax stock price chart.”
Show all 34 chapters

Regulatory Changes and Their Effects

16:30 to 17:39

Examines the rising costs and regulatory changes related to data breaches.

“Because Europe in particular is getting very strict about notifications and sometimes fines around these breaches.”

The Role of FedRAMP in Compliance

17:40 to 18:52

Discusses FedRAMP and its significance for federal compliance standards.

“But also I have my own internal bar, which is more the European take.”

Modernizing FedRAMP for Better Standards

18:52 to 19:59

Explores the efforts to update FedRAMP for contemporary compliance needs.

“How do you realize state and local governments also use FedRAMP as kind of their?”

Challenges with SOC 2 Compliance

20:00 to 21:27

Addresses the complexities and challenges faced in achieving SOC 2 compliance.

“Yeah, I feel like your life is the XKCD of, you know, we have 15 standards.”

The Insider Threat and SOC 2 Controls

21:27 to 22:31

Analyzes the role of insider threats in the context of SOC 2 compliance.

“And how does this work with agentic coding where the honest answer to the number of human reviewers this code is zero?”

Navigating SOC 2 Without Clear Guidelines

22:31 to 23:49

Discusses the ambiguity in SOC 2 guidelines and its impact on startups.

“having two reviewers is kind of one way to do it.”

Leveraging AI for Compliance Solutions

24:42 to 26:18

Explores how AI can assist in achieving compliance and streamlining processes.

“You know, the kind of joking reference that everyone makes as they talk about kind of competition from cloud code for software products is, yeah, you know, you're not just going to vibe code your X in a weekend.”

The Future of Compliance with AI

26:18 to 28:00

Discusses potential advancements in compliance processes through AI integration.

“And then in a like Cloudware and LM, it's like, okay, cool.”

The Power of Data in Auditing

28:00 to 29:15

Explore how AI leverages data from audits to enhance compliance processes.

“And both QuickBooks and Xero, to some extent, really grew off accountants becoming familiar with those pieces of software.”

Third Party Risk and Vendor Reviews

29:15 to 30:48

Discuss the importance of vendor reviews in software procurement and security.

“And just like, you know, Stripe's an advantage because we have all the fraud data.”

AI's Role in Security Questionnaires

30:48 to 32:14

Understand how AI can automate the completion of security questionnaires.

“they might work at a tech company and be quite savvy and up to date on those threats.”

The Future of Compliance Workflows

32:14 to 34:25

Learn about the evolving role of compliance teams and AI integration.

“The counter argument you could say is maybe Jevon's paradox will show up and there'll be even more exhaustive and elaborate and custom, you know, security questionnaires.”

Evolving IT and Compliance Roles

34:25 to 36:24

Examine the shifting landscape of IT and compliance roles in modern companies.

“And so you're like, OK, there's a questionnaire piece.”

New Standards in Compliance

36:24 to 39:40

Explore current trends and future standards in compliance within AI and security.

“Is that basically where compliance is going?”

Trust Centers and Their Importance

39:40 to 42:00

Discuss the role of trust centers in enhancing security communication with clients.

“we will support them all because we have built a machine.”

The Changing Landscape of Outbound Selling

42:00 to 42:59

Learn about the evolving effectiveness of outbound sales tactics amidst AI spam.

“It's like, here's the binder of information.”

Innovations in On-Demand Software

43:00 to 44:50

Discover how Vanta is exploring on-demand software solutions with agentic UI.

“But why are you using software that someone coded five years ago rather than just the computer deciding what to render to you at that moment?”

Marketing Success and Lessons Learned

44:51 to 46:35

Examine Vanta's marketing strategies and the unexpected success of podcast advertising.

“In a way that we don't, we have tried to, but brand spend, honestly.”

Market Size Insights and Challenges

46:36 to 48:38

Understand the pitfalls of market sizing and its implications for startups.

“I feel like I've heard you on the Acquired podcast.”

Collaboration at Union Square Ventures

48:39 to 50:36

Explore the dynamic partnership between Fred Wilson and Brad Burnham at USV.

“my best estimate was there was$10 million spent globally and you would never start a startup on that.”

Lessons from Founders and Successful Traits

50:37 to 53:12

Identify key traits of successful founders and common pitfalls to avoid.

“And so many of the ideas of the firm were back and forth by them.”

Future Directions for Vanta

53:13 to 56:00

Discuss Vanta's potential expansion beyond security into other compliance areas.

“Yeah, the version of this I talked about with Des Traynor is I feel like investor updates with a lot of words and no metrics.”

Exploring Internal and Financial Audits in Security

56:00 to 56:41

Learn about the integration of internal and financial audits in security practices.

“I think right now we do think about, especially in this world where, in theory, code has become much cheaper, which was two things.”

Building ERP Integrations for Auditing

56:41 to 57:21

Discover the importance of ERP integrations for effective auditing.

“It's like we have all of this and, you know, currently we're packaging material and sending it to the auditor.”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:01Christina Cacioppo founded Vanta in 2018 to solve a problem most founders didn't even know they had, compliance. Under her leadership, the company has defined the trust management category going to over 15 ,000 customers.

0:13Christina Cacioppo:Cheers. Cheers. Good to see you. Good to see you. Tell the Vanta story. We help companies start or build out their security programs and then get credit for all that work through an audit, through a security questionnaire, a trust center. But it's basically like do all the work to improve your security and then go get credit for that with your customers. All the Fanta billboards I see use the word compliance rather than security. Yes. What's going on there? It is one of those where you're like, well, vitamin and painkiller, I think, right? And I think compliance is, SOC 2 is a word that no one knows what the heck it means until they deeply know and then they want it.

0:52Christina Cacioppo:But they know that they have to do it this quarter. Exactly. Yeah. And so it's kind of like, and one of the original founding hypotheses of the company is if you want to start a security company for startups, you should actually start a compliance company. Because your customers never ask you for security, but they do ask you for compliance. So compliance is like the buying moment for startups. I see. Exactly. And then when you're going through that, you have to implement a bunch of, like, do a bunch of best practices, maybe buy some tooling. Yes. But you don't, even if you want to, you don't do it before that moment.

1:20Yeah, yeah.

1:20Christina Cacioppo:Because you're doing the thing the customer wants. And I guess at a later stage, the buyer would be Spliss, where security would be the CISO versus compliance would be the CFO, GC, something like that. So I actually think Stripe is like a little, I don't know, in what I see, which is biased, but different. In that usually compliance is, there's this unified GRC, governance, risk, and compliance function, and that lives in the CISO org. Okay. And that will centralize internal audit. It'll centralize like enterprise risk. Okay, so you're mostly. You put those teams together. Yes. Third-party risk.

1:50Christina Cacioppo:Those teams are all together in CISO org. So you're mostly selling CISOs. Yes. Okay. How did you, you woke up in the morning and you decided you were passionate about starting a compliance company? When I was three years old, it was my first word. Yeah, yeah, exactly. Yes, we joked in the early days, we'd like never be able to pull that story off. I don't know, I heard training businesses are good. I've heard more absurd founding myths, so I think you could just go for it. Yeah, go. No, it's, the real story is twofold. So one, prior to Vanta, I worked at Dropbox. I worked on what at the time was a new product, Dropbox Paper.

2:22Christina Cacioppo:We were trying to take it to market and didn't take it to market as well as we could have for several reasons. One of which was, turned out at the time, all the Dropbox contracts had written into them, like we're secure, we're compliant, we're pen tested, we're XYZ. Our new thing had none of those. And so it was like, in order to talk to someone with a Dropbox account, which was, you know, 100 million people or whatever it was, we had to go through this process. This was Dropbox 2015. So like the height of its Silicon Valley power, you know, year and a half, 10 engineers, no feature building, all that.

2:58Christina Cacioppo:I like, that all happened. I was not smart enough to then be like, aha, startup idea. And instead, like this, like Dropbox, what are you doing? This sounds bad. It was about a year and a half later, just talking to startups and founders about security, trying to figure out, like, why is there a company to be built here? How do you get more startups to care about security? How do you be able to do it? And kind of came across basically companies that either sort of did nothing for security but felt really badly about it sometimes, but still did nothing. And then companies that had a lot of stuff in place.

3:33Christina Cacioppo:and the lot of stuff in place was because they'd gotten a questionnaire they'd gotten to talk to because of an enterprise customer. And that was kind of the like, oh, that thing. I remember that being crazy and onerous and sort of terrible. But also kind of if you do it, like, you know, that is like Pasco collect$200, like huge benefit on the other side. And it was kind of the combo of those two things. What you're describing, I think, is just so commonly the experience in founders who start companies. I mean, it was our experience with Stripe as well, where we had just run into the problem before.

4:06But it's funny, I often run into people in university who are excited about starting a startup. And that's generally, and you know, obviously there's lots of sexy stories of people who dropped out of college to start something. It's generally a bad time because you talk to university students and often their ideas for companies are pretty half-baked. Find my friends. Yeah, it's for Find My Friends. It's like a college textbook exchange app. You know, it was like the five apps or whatever. Whereas so frequently what happens is people go out and they build successful products in the world and they do Dropbox paper or they get some experience.

4:41And it turns out there are huge markets available with problem spaces that most normal people have not heard of with things like SOC 2. But you have to kind of spend a while seeing how the value flows in the real world work to discover those big opportunities.

4:55Christina Cacioppo:Okay, so how do you feel when you go to YC now and you have these founders who've like dropped out and been like, my passion is sales enablement. But they actually kind of do know surprisingly much about it. Yeah. Kind of. I mean, if you truly manage to learn enough about sales enablement to be, you know, to be able to field a strong product there, then good on you. I just think you're more likely to discover those areas after, you know, five or 10 years. What's changed the business at now? We have 15 ,000 customers. Our growth rate's actually quickened the last couple of years and quarters and months.

5:27Christina Cacioppo:And so it's been 60 % annual plus for the last couple of years since that milestone. So a bullpick number there. Yeah, yeah, yeah. Yeah, it's a proper business. Yeah. Mostly. And you go to market, it's all sold. All sales. Yeah. Yeah, yeah. It's just one of the blessings and curses of them. With what company sizes? So we do the, like, we call them the two founders on the couch. But it's like the two founders on the couch are building their thing. and someone asks them for Sock 2 and they're working on it on Friday night because when else are you going to do the thing? All the way up to at least one member of the Fortune 50.

6:00I would have thought that compliance is very different for founders who have never even heard of it versus companies who have a lot of existing teams here with opinions and stuff built out. So how does that work? Yeah, that is true.

6:14Christina Cacioppo:So down market, we're not quite TurboTax, But I think that is the kind of experience of founder wants. It's like, this is high stakes and I don't want to get it wrong and I don't really know, but just guide me through. And then so that's more of the product experience. And then the output is like, here's a set of controls, but like security rules you follow that are monitored on an ongoing basis. And because of that, whenever you're kind of constantly audit ready, you always have everything in place. Great. And so that's sort of the experience of founder wants, but the output is still a security program that's monitored all the time.

6:49Christina Cacioppo:upmarket, especially when I'm talking to an engineer, it's like, it's more data dog for your compliance controls, right? You're like, I have my program, I have my thing, but it lives in a spreadsheet, it lives in Jira, custom Jira, it lives in something like that. And I want real-time dashboards and visibility. I see. And like, you know, deviations and auto-remediation and like, I want that world. Okay, so there's almost like two layers to Vanta. There is what your controls should be and then how the controls are monitored and implemented and kind of early stage companies want both later stage companies may want more of the latter.

7:21Exactly.

7:21Christina Cacioppo:And then the tie to audit is like, great. Well, you know, in some ways it's like if control door with monitor, you just pass the logs to an auditor. It's more complicated than that, but that's the base model. Okay. You're getting to a question I had, which was like, compliance at some level is not a thing you can just buy. It's a thing you have to do. And so like, if you actually talk about all these rules, like I don't know about SOC 2 in particular, but for example, a lot of compliance regimes have this notion of, you know, doer and approver being separate for something. And so it's like the, you know, the...

7:50Proverview is the famous one.

7:52Christina Cacioppo:Yeah, exactly. The nuclear submarine where, you know, you have to have the two keys turned simultaneously to launch the PR, I guess, in this analogy. And again, Vantacant do that for you. You have to do this. And so what you do is one for, say, a startup, you actually just let them know the complete list of things they actually need to do. And I presume there's some, maybe you can talk about, there's some logic of only telling them the stuff that actually applies to them. Yep, exactly. And then there's actually, how do you enforce, say, separatist doers and approvers in something like code review?

8:22Christina Cacioppo:Yeah, so for something like, so this is where, so the first thing we built, and we call it test. So it's advanced. We're like modeled after unit tests. You're like, turn each of these controls into a unit test. Yes. And so pull from version, you know, GitHub, GitLab, whatever. Look at every pull request and check, you know, these fields or this thing or some run some logic over it. And that is our test for the control. Ah. And so that was kind of the first thing we built were these tests. But tests are just ways to prove control. Ah, so you're just a test suite. You're the battery of unit tests for the compliance rules.

8:54Christina Cacioppo:Exactly. Ah, why don't you just say that? Why don't you just billboard say that? There's a niche audience of San Francisco that would be like, oh, now I understand. Yeah, but I think for the 101 billboards. Yeah, yeah. Oh, what's the controversy with your 101 billboard? Oh, my goodness. How much do we want to do this? We had a great 101. Great billboard. You just drive by it every day. Yeah, yeah. Compliance, it doesn't suck too much. Arguably, you know, hundreds of millions of dollars in market cap attributed to that billboard. It's funny, that was just in the, you know, annuals of Antelope startups.

9:25Christina Cacioppo:The person who came up with that billboard, very pleased with herself, as she should have been. Yeah, yeah. 100 % right. Yeah, yeah. Her manager at the time was very skeptical of that billboard. That's a can level tagline. Are we negging our users? Yeah, yeah. Is this okay? Are we too far over the line? Yeah. Anyway, you can guess which one of those people is still at Vanta today. Not just because of that. Yeah, yeah, yeah. It's kind of a cultural test. Exactly. Yeah, yeah, yeah. Anyway, so we had this billboard. It was great. For many years. For many years. Yeah. I used to joke that we've had it locked up for years.

9:56Christina Cacioppo:Turns out we didn't, and I'm an idiot. Oh, you forgot to renew it. Not even. You should have had a little Vanta check for that. I know. It was like your domain, and you're just like that thing you're not supposed to. Yeah. It was slightly better, but still bad. The agency we worked with, one, I should have caught this, our contract was just written in crayon. And we got a lot to be able to ask about our billboard. We introduced them to lots of startups. You know, some of those startups were also buying with that agency. Wow. And so that agency. A startup you introduced to them went and took your billboard.

10:27They didn't even do it on purpose.

10:28Christina Cacioppo:The agency went to them and was like, oh, we have this great inventory. Would you like it? And then we found out. Okay. That's rough. But people will learn about Vanta in other ways. They do. We do like to market. Yeah. Yeah. Okay. And then go back to the other part of the question. So how does the layer work for, you know, the rule book might be a thousand pages long. Compiling that rule book into the steps that are actually actionable for me because I am not a farm. And so all the farm parts of the rule book don't remind me. Yeah. Okay. So the initial version of it actually was, this is like back when we were founders on a couch.

11:07Christina Cacioppo:was getting like as many SOC twos as we could. So it's like Salesforce, Slack, AWS, right? Yeah. Whatever. And actually opening them all and just comparing them. Yes. And trying to extract out what was common and sort of doing it that way. So that was the first cut. What we do now is hopefully more advanced, but there's a bit of, now that we have probably 30 ,000 audits completed. Yes. We can just go back and be like, okay, for a company that looks like you and board this auditor often, what sorts of controls are there. Yep. So we have that input in. Then we can also layer in, both for a company in particular and in general, it's like you get questionnaires.

11:46Christina Cacioppo:What are the themes and the questions you're being asked? Yes. We just launched a new commitments product that ingests contracts and scans the contracts for like things that are contracted. That's cool. So you can then like both pull them out and say, hey, this should be a control. Yes. And, you know, God forbid something happens, but you're like, what are my obligations to my customers? Yes. And you can just have, you know, you basically have all that structured data. But one of the most important things, they just want to see progression over time and increase maturity over time. And you've probably had this at Stripe where you want to do some cool new tool that like had no security posture.

12:20Christina Cacioppo:Yes. And a contingent, say, heck that baby. But like, you know, one part of it was like, oh, can you just like walk this up over time and show me you're making progress? Yes, yes. Is SOC 2 the main Bible, you know? Basically. I mean, we don't, it's funny, we don't, we don't break it out by framework anymore because it's all just, you're like, they're all just inputs into the system for us. Sure, but like ultimately you need to comply with some specific thing. Yeah, yeah, yeah. But like, yes, most customers will come to us for that first. Number two is ISO 2701, which is, if you pardon, like you're a part of, like you're a part of, like you're a part of, European enterprises.

12:58Okay.

12:58Christina Cacioppo:Yeah, yeah, yeah. And so if you're, if you're a European company selling to Europeans, you will start with that. If you're a European company selling to Americans, you'll start with SOC2. Okay. How aligned are they? I think our fish mapping is like 60-ish, 65%. Okay. And the additional ASOS stuff is often documentation. Okay. Which is like a great place for software to help out. Sounds like Europe, yeah. Yeah, yeah, yeah. Exactly. Yeah. There's like less, you know, please implement these six more rules. Okay, so is it SOC 2 and its international equivalents is basically that captures most of what you're doing?

13:27It is probably plurality, not majority. Okay.

13:31Christina Cacioppo:And so we see a lot of growth. There's this, like, whole host thousand flowers bloom of AI standards right now. It's, like, the whole thing there. There's the healthcare-specific things. Sure. There's the PCI piece, which I know you're very familiar with. There's that. On healthcare, is this which? There's HIPAA, which is U.S. law. You can just declare yourself compliant with HIPAA. Yeah, self-security. Yeah, exactly. The downside of doing that is if you do that and are breached, the fines are enormous. And so that's the check. There's a semi-market check there. Can you describe the policy goals that something like SOC 2 seems to accomplish?

14:11And you might say, oh, it's simple. It's just security. But yeah, like as we know, there's many different facets to that. And so it could be preventing information leaks, or it could be preventing fraud against the customer, or it could be all these different things. And so if you're at a stack rank, what is SOC 2 actually trying to accomplish at a policy level?

14:30Christina Cacioppo:I would say it is trying to ensure customer data is protected. I think that is what it is trying to do. And just to round out the point, your JavaScript comparison is that Java was a very popular language before the emergence of web browsers with JavaScript. And so when they invented JavaScript, they wanted to kind of ride off the Java halo as an easy-to-do programming language, despite the fact Java and JavaScript share no exactly commonality at all. But it was just good branding. And what you're saying, is that a similar with SOC 2 here? Okay, so you're saying the primary goal is to ensure that the data that you are giving this company.

15:11Christina Cacioppo:Your software provider, whatever. Is adequately protected. Many companies have had humongous data breaches. Equifax was a great, easy version. AT &T, I believe. Kind of all of them. Exactly. Assume every big company as a SOC 2. Yeah, but there's a difference between kind of some data was leaked in some context versus like in the Equifax case. Sorry, we lost all of your data. Exactly. We didn't fix the database. Which data did you lose? Like all of it. Yeah. It's very hard to find that moment in the Equifax stock price chart. Yes. What's going on there? As in, we think society cares. Society should care.

15:52It's valuable to not lose this data. and yet it does not seem to impair what investors deem to be the terminal value of the company.

16:00Christina Cacioppo:Yes. What are investors betting on? They're betting on like, will anyone turn off of Equifax because this happens? And I think the cynical but correct take is no. Sometimes because you're like, you know, Equifax or Delta, you're not like, am I going to stop? You know, like I'm not going to stop playing Delta, especially 10 to 15 years into this where you're like, oh, another one. I'll add an eighth credit monitoring service, right? And I think there is a cynicism there that is probably correct. Yes. Yes. The other thing that feels like it's changing in this ecosystem is that the costs of having data breaches are going up.

16:43Because Europe in particular is getting very strict about notifications and sometimes fines around these breaches. How is that changing your world?

16:55Christina Cacioppo:We see more. So we also cover some of the data privacy standards. So your GDPR, your CCPA, there's, you know, whole, again, alphabet soup of acronyms here. It goes, honestly, we see demand for that that goes in waves. And it kind of tracks what you expect. It's higher in Europe. I mean, Vanta as a product in general does kind of even better in Europe and better than you would guess for an American. for a California company that doesn't have European roots. And I do think there's some cultural affinity and just seriousness there. Yes, yes. Versus the easy critique of Americans in compliance is like, I'm just checking.

Read the full transcript

17:34Christina Cacioppo:You tell me where the bar is and I'll meet your bar. But like. It's a box checking. Exactly. Or it is just kind of culturally something that is like more important. You can tell me where the bar is. I'll meet it. But also I have my own internal bar, which is more the European take. But we see like demand for, say, CCPA, which is a California version of GDPR. quote unquote go in waves. And right now it is definite. I mean, all the American regulation is kind of at a total nadir, but it's down right now. Yeah. Well, it's down at a federal level. Is it also down at a state level, the kind of energy around the CCPA type things?

18:08Yes, it is.

18:08Christina Cacioppo:Even with, you know, it's not clear what California is going to do and it could go multiple ways. But I think I still think the national politics casts a larger shadow, even over like a state like California. Oh, that's interesting. Yeah. OK. And on the national side, you know, current administration is very into streamlining regulation through automation and AI. But that is the catchphrase that they deeply believe in and are driving. I would have thought that this kind of stuff is just too boring to be caught up in any reform initiative or will this be streamlined? I think there's very hardworking folks in D.C.

18:46Christina Cacioppo:in special—well, kind of across the board, but in GSA, in the Agile Arc Office, trying to do this. And the primary lever they're using is FedRAMP. Yes, I remember this. And which broadly I would think of, I'm sought to for the federal government, but basically a very onerous set of both controls and requirements and documentation in order to begin trying to think about selling to federal and often states and sometimes even local governments. How do you realize state and local governments also use FedRAMP as kind of their? The state ramps. Yeah, yeah. So there's like literally Texas ramp. But they kind of conform to FedRAMP.

19:23Christina Cacioppo:Yeah, yeah. And there is a part of GSA and one team in particular led by a guy called Pete Wasserman who is trying to modernize FedRAMP. But I would say make a like 2020 version of FedRAMP where the current version feels a bit more 90s. And it is unclear if he will get the traction to succeed. But he's fighting the good fight and he gets it. But even if they do that, I find it hard to imagine the society of accountants just copying the new FedRAMP lock, stock, and barrel. I don't think they will. I think you're just going to have even more divergence between these things. There's just less control over that.

20:04Yeah, I feel like your life is the XKCD of, you know, we have 15 standards.

20:07Christina Cacioppo:It is standards, and the answer is the 16th. Yes. Yes, yes. Yeah, yeah. That is also my answer when people are like, well, is in Vance I going to make a standard? Couldn't you make a better one? Yeah, yeah, yeah. I mean, couldn't we have that posted on the office wall? Yeah, yeah, yeah, because it is your life. Yes. But OK, going back to the effects of the European strictness, it doesn't show up in the form of kind of maybe American companies previously were looking to kind of check the SOC 2 box versus now they're like, OK, it's really important I don't cross this actually quite strict European rule.

20:35Christina Cacioppo:Right, right. Whereas I think now, and I think in the, it's funny, we are starting Vanta, Vanta as what it is now today in spring of 2018, which is when GDPR was going into effect. And so I was kind of running around and being like, will you talk to me about compliance? And everyone said, yes, I was having this great luck. And then I'd show up and I'd be like, so suck too. And I'd be like, GDPR is a priority, like next please. Yeah. And that energy is like mostly dissipated, especially in the United States. Yes. I think it's like the theory at the time was GDPR is written by lawyers at a very high level.

21:09Christina Cacioppo:It's like not a spec you can handle an engineer, like comically kind of bad as an engineering spec. But like, it's fine. We will clarify that in court over the next 10 years. And now we're seven, eight years in. Hasn't really happened. Yes. Yes. It still is kind of hand wavy. Yeah. For an engineer, at least to go implement as it ever was. And how does this work with agentic coding where the honest answer to the number of human reviewers this code is zero? Yes. How should it work? Because right now it is like, well, somebody needs to be like, I did code well. I think right now it's like agent, you know, writes code.

21:46Christina Cacioppo:Human or agent puts up PR. Yes. Maybe human or agent reviews it. Yes. And I think to a, like, naive sock to audit, you're like, those seem like two user IDs had that conversation. Yeah, yeah, yeah. And so we can go forward. But it's more about having two throats to choke as opposed to, you know, we read the code of this, you know, ATM software and guaranteed this. You didn't introduce an infinite money glitch. Yes. My interpretation from talking to folks is some of the impetus behind that or the primary impetus was insider threat. And like that's what you're preventing against. Maybe that's my macro answer is just go through the SOC2 controls and be like, what are we trying to do here?

22:25Christina Cacioppo:and be like, okay, great, let's design for that. Yeah, yeah, yeah. And that may or may not be how it's written today. That's a good question because on all the insider threat stuff, having two reviewers is kind of one way to do it. Yes. Does it suck to mandate exactly a lot of other insider threat stuff because presumably you should be logging a lot of activity, auditing a lot of activity. You know, there should be process that you have in place. No, and I think this is where actually you get to the technical standard made by folks who often aren't as in their depth in engineering, let's say. Right.

22:56Christina Cacioppo:And so the controls for like, there are a bunch of logging and monitoring controls that are suggested. One thing maybe I also mentioned, unlike PCI, SOC 2 doesn't have a prescribed control list. So PCI is kind of different and it's like you must do X, like you must buy this tool whether or not it's useful to you. I'm sure you have your own story with that. Yes. SOC 2 is like you must log useful events and have a system to look at them. I see. But it is up to you to decide what the heck that means. Which sometimes it's helpful. Yeah, yeah. I think for a startup that's never done this, it is unhelpful because it sort of opens up, you know, a maze in a way that's just not great.

23:33Christina Cacioppo:That's where being prescriptive, like, is part of, I think, the, and Vant's initial product market fit. I think it's actually largely due to that. Yes, yes. In a way that that wasn't the plan. Yeah. But I think it's like figuring out how to take that high level guidance, bring it down in some places. Yes. In a way that actually makes sense.

23:53Christina and her team at Fanta are helping their users automate compliance, which for many companies is the thing standing between them and being able to sell to enterprises. We're very familiar with this category of products at Stripe, where you have a complex web of rules that businesses need to be able to comply with so they can move on to actually improving their products. Just take tax compliance and our product, Stripe Tax. As you start selling in more states and more countries, you discover there's thousands of rules you need to follow. For example, did you know Chicago actually has a lease tax, which applies to SaaS companies too, since you're leasing out software?

24:25Stripe Tax is built to automate all of this. With one integration, it knows what you're selling, when and where you have to collect transactional taxes, and how to register and file on your behalf. So if you want to sell globally without becoming an expert in tax rules, check out Stripe Tax. You know, the kind of joking reference that everyone makes as they talk about kind of competition from cloud code for software products is, yeah, you know, you're not just going to vibe code your X in a weekend. But obviously, something like SOC 2 is actually the kind of thing that LMS or kind of coding agents are good at working with because there's just so much training data out there.

25:09and it's a, you know, codified set of rules. And so how is AI helping with what you're doing and kind of what is your plan for? You were describing some of the scale economies you have and having seen other customers, but I'm curious just kind of what the defenses are against. A customer could, in theory, say, hey, Claude, give me the plan for our SOC 2 compliance. Make no mistakes, you know? Like, that is a thing you can contemplate.

25:31Christina Cacioppo:Right. And I think, like, there's, you know, so you can do the sort of the very defensive thing, but I'm going to do the actual, the very defensive thing. It's like, wait, but like, this is a place where you don't want to get stuff wrong. Spending much time on it does not make your beer taste better. Right? Like, is this really the place? Even if you really want to vibe code a bunch of stuff, is this really what you want to vibe code? Fine. Whatever. There's all those arguments. Ignore them all. I think where the LLMs are excellent and a little dangerous in a build versus buy, but then we just need to build better experiences on top of this.

26:01Christina Cacioppo:Is like, hey, Claude, I'm going to give you a mess of data. you go make sense of it to me and like get me ready right i'm just gonna like give you a bunch of aws screenshots or api calls i'm gonna give you all my policy documentation like go i'm gonna give you my existing jira workflow go turn it into a thing and so you know you can go do that today we are building um this is our like onboarding flow or will be our onboarding flow which is oh you have an existing program that's already running that's cool give you all the stuff we will go map it into the Vanta world. Yes. And then in a like Cloudware and LM, it's like, okay, cool.

26:40Christina Cacioppo:Now you get, I don't know, files in a folder structure that you then, you know, box share that over to EY and like call that your audit. Fine. You can do that. In a Vanta world, the outcome is now hopefully we have your program mapped and is observable and monitored and alerted. And so you have continuous control monitoring. You get your dashboards. You always know what is in place and what is not. And yes, you can go, you know, send a share link to your auditor here too and they can log in and see everything. And so we sort of think about it as they have lowered the initial audit prep. Yeah. In a way, inside, outside Banta.

27:16Christina Cacioppo:Or like if they're not inside Banta, what are we kind of doing? So building that. But the continuous monitoring piece. Yes, yes. That you're not going to get out of at least LLM chat. You've got to go vibe code that whole system. Okay, so you're saying this. everyone just wants, like no one enjoys spending time in SOC 2, everyone wants to have been SOC 2 compliant as of yesterday. Yes. And so you're saying part of the advantage here in this new landscape is you can just take a whole bunch of unstructured stuff and just empty it into the Vanta hopper and Vanta will make sense of it. Yeah, we'll get widgets out.

27:49And I presume part of the defensibility comes from the fact that preference amongst practitioners, in this case, the auditors that are reviewing your SOC 2 materials is a very strong effect. And both QuickBooks and Xero, to some extent, really grew off accountants becoming familiar with those pieces of software. And companies could have opinions about what they were using, but those opinions were not that strong and they were overridden by the opinions of the auditors.

28:21Christina Cacioppo:We have a version of that. I don't think it's as strong as Zolde Fex yet, at least. But even again, we've seen 20 ,000 audits and thousands for particular firms. And so you're like, we now do AI evidence evals. So it's like, oh, you're going to provide this piece of evidence. We can just tell you, is it going to work for this auditor? Did you upload a cat picture? Did you upload a screenshot without a timestamp on it? And you're going to get told to put the timestamp back, you know, just like that feedback loop. We already have, and we've thought about doing things for auditors as well with that.

28:55Christina Cacioppo:But yeah, it sort of moves in the direction of like an AI internal audit at least. It feels like the data you have of anonymized prior audits is an incredibly powerful network effect that cannot be replicated because it doesn't exist in the public internet. Like the AIs don't have it available to them through just private data. And just like, you know, Stripe's an advantage because we have all the fraud data. We know what like a normal buying pattern looks like versus not. And so we can offer the best anti-fraud performance just because we're working with a larger data set than other people. Similarly, people going through an audit, you can tell them that this will work and this won't.

29:33Christina Cacioppo:This is our radar. Yeah, exactly. In a way that's just you cannot do it even if you decide to buy it yourself. Yes. Yeah. It's a big deal. Yeah, it's kind of cool. Where else have you seen that be useful? In relationships between a software vendor and buyer. Right. And so we so Vanta core, we think of ourselves as, you know, broadly and what we're best known for is serving software vendors, but people who make software and want to sell it to the world. Right. You know, security or is it secure? Grand. OK, then we have this third party risk product. But it's basically I think of like you're an organization.

30:12Christina Cacioppo:Maybe it's tech. Maybe it's not tech. You're buying software and you're going to go put a bunch of your customers data in it. You want that software to be secure. Because if not, you have to turn around and tell your customers. Like, I lost your data, but it's actually our email provider. But you don't care if it's our email provider. Like, you think it's me and I've sent you an email. Anyway, right? Like, no one wants to send that email. So there's a whole world of, like, third-party risk or vendor reviews. And we build a product for those folks. But is there kind of a compliance versus security tension here as you're doing this stuff?

30:42Christina Cacioppo:We haven't seen as much. What we have seen is, so the person buying software, you know, they might work at a tech company and be quite savvy and up to date on those threats. They might work when our customer is, you know, a hotel, literally a hotel chain. Right. And so not that, and they certainly don't get compliance themselves because they don't build software. Right. But they buy it. Yep. Fine. And so what we generally see is some companies will come in with their set of questions they want to ask. And, you know, maybe I will read your sock to you, maybe I will not. But like, I really want to ask you questions one through ten.

31:14Christina Cacioppo:Some companies don't have that. And again, there's some part of the value proposition is like, we'll prescriptively guide you. And so we have a product principle just around reasonable defaults. And it's like, can we make the reasonable default questionnaire? In this case, something that leans into security versus compliance or versus, you know, do you have a policy to X? And you're like, can you just ask them if they X if you care? And so that's a place where we've tried to, on the margin, nudge the buyer questions toward more security, knowing that will change the economic incentive of the vendor.

31:45One of the big debates people are having right now is how AI productivity gains show up.

31:50Christina Cacioppo:Yes. And I feel like you could have an opinion on this because we have filled out a lot of security questionnaires at Stripe. And I think we'd be very happy if the machines could take over from here. We really don't. We filled out enough. We should talk about this. Exactly. Yeah. But so one case you could make is the machines are getting quite good. They can understand what Stripe, you know, is and isn't and can do and can't do. And so every time we get a security questionnaire, AI can fill it out. The counter argument you could say is maybe Jevon's paradox will show up and there'll be even more exhaustive and elaborate and custom, you know, security questionnaires.

32:27And so, you know, the total amount will increase. But so just how do you see AI productivity showing up here on the effect?

32:33Christina Cacioppo:So the questionnaire is actually a great example because the questionnaire is so that we tried to build this product in 2018, which is before SOC 2, because it seems easier actually, but the language models were not good enough. And then we try it again in like early 21. Like BERT came out and you're like, oh, is there a moment? It was not good enough. And now it is good enough. So to that actually GitHub gets 92 % of all of the questionnaires they receive answered through Vanta. And so you're like, not at 100, but you're like, it's GitHub. They have AI tools. Like they've copiled it. It's a lot.

33:04Christina Cacioppo:And so we're absolutely seeing this. Like the models are definitely good enough. People ask GitHub to fill out security questionnaires before using GitHub. GitHub, and now they can mostly turn around and return those security questionnaires. Yes, exactly. With a 92 % filled out. Filled out. And we have a, it's kind of human, but just it's review and approve. Yeah, yeah. Right. And then like the confidence scores on like prioritizing even for the reviewer. It's like, you probably want, you can look at the section if you want, but you kind of don't have to, whereas like, will you really look at these 10?

33:34Christina Cacioppo:Yeah, yeah, yeah. Yeah. And so like all of that work, like our product does that. Yes. Yes. That's cool. Okay. So where do you think it goes broadly? I think that so much of the work of a compliance team is, again, keeping things in sync, keeping and like different sorts of text in sync, right? Adding on new compliance regimes, which is just adding controls. And then you really want to map the like, you know, new ones to the old ones and figure out what the duplicates are. That's actually a huge part classically of the work of a compliance team. And so I think there's so many opportunities for LMs at agentic workflows in Vanta's business.

34:15Christina Cacioppo:And we've, you know, we probably have a couple dozen of them. And if I think about our roadmap, you know, knock on all the things like, well, like hundreds by the end of the year. But it's just and it's kind of what we've been doing is breaking down what folks do. Right. And so you're like, OK, there's a questionnaire piece. If you send out a questionnaire, someone has to read it on the other side. And then you have to think about it and figure out, you know, where does it work? Where does it doesn't? Oh, I have this new policy update. I need to put this thing in a policy. I need to, we're going to start doing, I don't know, ISO 42001, which is a new AI standard.

34:47Christina Cacioppo:And so how do I map that in? I need to rerun a risk assessment. I'm going to change my like risk score. Anyway, all of these things, all of these tasks are all just like workflows that you You could have an AI do, write an eval against with like subject matter experts, and then he'll climb until they're quite good. And so it feels like, you know, you can reason about the number of people in a profession, especially at a certain stage of company changing. Like if you think back to ancient times, I don't know, the year 2000, if you had a 10-person company with, you know, 10 Gateway 2000 beige workstations, they probably would have had an IT person.

35:29And that IT person would have had to...

35:30Christina Cacioppo:Had the servers in the closet. Yeah, exactly. They had servers in the closet. They had Microsoft Access database. They had to do software updates for all the machines. Occasionally, lint and stuff would get stuck in the mouse ball. And they'd have to take it out and clean it. I've thought of that in one time. And all those kind of stuff. So IT was a real job. Yes. Now, I don't think a 10-person company really has an IT person. No. Because the hardware is super reliable. You just buy a new version every now and then. Everything's in the cloud, so there's no porting data over. They just use Google Workspace for everything.

35:58It works really nicely. And so IT still exists as a profession. There's lots of interesting things. But, you know, Stripe has a bunch of IT people. You don't need a bunch of IT people.

36:06Christina Cacioppo:You've got, like, mail laptops to, like, how many countries in the world, which is, like, actually kind of hard. Yeah, we have some IT challenges. But, again, we're 10 ,000 people. And, again, it naively feels like you will have a similar effect with compliance as we had with IT, where the profession very much stays around. It actually gets more skilled rather than like, I think the stuff we do in IT is harder than kind of the basic IT that a 10 person company would have done. Is that basically where compliance is going? I think that's basically true, yes. So one model we've thought about with Banta, even like pre-AI, is we will delay the point at which you have to bring on a full-time security compliance person or like a kind of consultant who's spending meaningful time.

36:46Christina Cacioppo:But, you know, in the past, if you were an enterprise company, maybe you did that at 50, 100. And it's like, can we actually push that further out? Yes, yes. Because what we see is that an engineering leader or someone in the engineering org can manage more of this. Because they kind of have the mental models and they're usually system thinkers and they can, you know. And they're responsible for it so they can kind of change the stuff. Exactly. Yeah, yeah, yeah. And so you're like, have this, what personas do you call them Amelia engineers? But like, you have the Amelia engineers just like going further here.

37:13Christina Cacioppo:And then you bring on, and then you can bring on a like unified security and compliance person versus like, oh, you have your security person. your IT person, your compliance person. But it's a little bit of like the, kind of what we're seeing in the like engineer PM designer collapse. So you have the like security compliance, IT collapse into one role. So you can keep them unified for longer. Exactly. If you can give them good tools, right? They can do that. Okay, fine. And then again, pre-AI, but then over time that team starts to grow and then you have a GRC team and CISO and all this. What we're talking about now and we haven't seen yet, but if I like had the future cast and guess, is we're going to see actually those GRC teams collapse a bit more into these single threaded owners.

37:56Christina Cacioppo:Taking a GRC team today, there's maybe one person answering questionnaires, one person just reviewing new software vendors, right? And you look at those and you're like, okay, I think you can mostly agent the work and then have someone oversee it with 20 % of your time. But like, okay, great. It's collapsed two into 40%, right? And you're like, okay, you have some person who's like the, who is responsible for bothering the engineers to get evidence for them, you know, when they, for the audit or like to get the control in place because they don't own the control, but they own the program. So they have to go to the engineer and be like, hello, I noticed you have a new database that is not encrypted.

38:35Christina Cacioppo:And like, will you please encrypt it? Right. And you're like, you can just have software go nag that person. Anyway, it collapses. And so I do think we will seek smaller GRC teams, managing agents, But actually in the future. Yeah. And then they are doing more. I'm not doing the security reviews. I'm like thinking about the findings and overall managing this like risk portfolio, this like vendor risk portfolio versus being like, oh, this vendor doesn't have this thing and I need to go get it from. Yeah. I think what you're saying is there's a strategy component to how should we be doing things.

39:08Yes. And then there's an hourly labor component to compliance, which is like, oh, we did 10 times as many sales. we need like 10 times as many bodies on the security reviews. And you're saying that AI will eat up a lot of the hourly labor part of compliance and leave people doing the strategy work.

39:24Christina Cacioppo:Yes. Yeah. Yeah, I do. I do think that. What changes are coming down the pike in the world of compliance? I think there's, to the XKCD, there's lots of folks both trying to make new compliance standards, but it's a little bit of like, what's the difference with the 22nd one? From a Vantip perspective, we've sort of taken a like, we will support them all because we have built a machine. where it is easy to add a new one in. Yeah. But obviously you only want to support ones that customers actually want to comply with. So you're not sure. Well, yeah. But like kind of what we do, actually, we used to spend a bunch of time debating which ones those would be.

39:55Christina Cacioppo:And it was honestly so frustrating. Exactly. Now you're just like build the machine that just logs them in. And so the debate and the document you would write. Do you want to support this payment method? Sure. Sure. Whatever. Yeah, exactly. We did that with compliance standards and integrations because it was just like the prioritization debates were just too intense. Yes, yes. We can take all of that debate time. Anyway, so anyway, there's a bunch of those. Would I bet on any of them? If you really pressed me, I would say ISO 42001, just because it's the European one. I don't know that ISO. 42001?

40:27Christina Cacioppo:You've got to catch me up on this new ISO. It's a good one. My recommendation is bedtime reading. So ISO, you know this, but like European standards body, and it is their version of what one should care about with AI. It ends up being pretty data privacy focused and pretty high level. But those are the counters. The pros are that European enterprises are the ones that care the most about AI, and this is where they would turn. And so it's the thing that has the most market traction so far. But again, none of these are— But none of these are, like, breakout. None of them have product-market fit.

40:58And none of them are regulatory. Like, they're all—

41:00Christina Cacioppo:Correct. You opt into— Exactly. It is like this market has, like, roughly agreed you might need this thing. So there's that. I think the—ah, okay. I'm kind of proud of this. they're like trust if you remember the trust centers they're the security status pages oh sure like trust.blahblahblah trust.vanta.com trust. I didn't know they're called trust centers it's just like a status page yeah but like for your security posture so you get the like you know green bars sort of or green traffic lights or yellow traffic lights but it's for your controls I see and but they always say the same thing like a status page is like red amber green whereas hopefully the trust center always says we're a real compliant boss Yeah, yeah, exactly.

41:44Christina Cacioppo:So there's like a version of that. And so if nothing else, what they actually are, they're ticket deflection for the GRC team. I see. Because when your sales team sends them out and you're like, doesn't it look good? And then if you have any questions, you know, here you go. Yeah, yeah, yeah. It's the pre-filled questionnaire. Yes, exactly. It's like, here's the binder of information. Please read it. And if you have questions for me thereafter, I am here. Does that work? It does, actually. And I think part of it is the just show of strength. Yeah, yeah, yeah. And the show of like, I'm on top of it.

42:11Yep, yep.

42:11Christina Cacioppo:And then there's like, yeah, yeah, read things first. And then if you want to ask me, go for it. Has outbound selling gotten harder now that everyone has a million AI bots spamming everyone? I think what I have heard is phone calls work in a way that I kind of wouldn't expect. For now, right? Until a year from now. But now with emails, like, yeah, yeah, a million AI bots. And I mean, like, how many chat GPT-written emails do you get, you know, in your inbox a day? But outbound phone calls are currently working. Got it. Yes. But again, it's only a matter of time. It's only a matter of time. And I think, you know, then we're just back to like, oh, events, right?

42:47Christina Cacioppo:And especially like small curated events. And yeah. Yes. A topic we talk about sometimes here is on-demand software. Patrick's taken to saying that software should be like pizza, you know, delivered fresh, piping hot. But why are you using software that someone coded five years ago rather than just the computer deciding what to render to you at that moment? Yes. Is that coming to Vanta? It is. It's something we're playing with internally, but like really excited about is having an agent that maybe is guiding you through the process or doing something and then, you know, needs the user to render an opinion or make a connection or, you know, do something.

43:27Christina Cacioppo:And can the agent just generate UI specific for that task so the user completes it and then move on? Yes. And you get this like bespoke agent-generated, hand-generated UI just for that. that does not exist. But are you talking about, because like maybe people have a little bit of a experience with agentic UI where, you know, an AI chat interface is like people's first experience. Has some stuff in it, yeah. And you know, maybe there's like three options you can choose, example. That's like kind of an agentic UI, but you're talking about a full UI. Or like maybe you have that agentic chat bar on, you know, half of the page or a third of the page and then the other two thirds would be a SaaS app, you can imagine, a data table with a view and columns and, you know, rather than just like customizing it.

44:06Christina Cacioppo:You're like, no, no, no, I just want you to do this thing and I will take over that right side canvas of the page, generate the UI for the thing or generate the report. I think reporting is another great use here. And what step of the process would this be? And would this be like you have 14 things you need to fix to get to? So we've thought about it in two ways. So kind of in the like you're setting it up and you're going through. And actually reporting is another, I think, great case. It's like no one wants more, you know, knobs and whistles on their reporting tool. Yes, yes. And also no one really wants to learn SQL.

44:38Christina Cacioppo:Yeah, yeah. You just want, like, I want to report for this. Go. Yes. Generate it. Yeah, yeah, yeah. Like, not quite right. Take this out. That's cool. So when will we be seeing generated UI in Vanta? This summer. Wow. Okay. What has worked well from a go-to-market perspective for you guys? In a way that we don't, we have tried to, but brand spend, honestly. The billboards. We do all the stuff people do of, like, you know, zip code tracking and all of that. Gone call mentions. so recorded sale like mentions of the word billboard on recorded sales calls and then you can track the billboard. Exactly.

45:12Christina Cacioppo:Then you track those deals through to closed one and like that. And you're ultimately doing a geo splish. You're looking at like the locations where you had a billboard versus not. Exactly. And then just like does the prospect say the word billboard in a call at some point. So some of that podcast advertising has been exceedingly effective for us. It's funny because we started doing it in late 2020 and our first salesperson, Eric, who's still at the company, really wanted to advertise, I think, on this week in startups. And I thought it was silly because my model is like the only, you know, companies that advertise on podcasts are like founders who want to hear about themselves.

45:52Christina Cacioppo:Like this is just nonsense. Or mattress companies. Exactly. Or mattress companies. But like, exactly. But like we are neither, right? Like, doesn't everybody really need to talk to you? Anyway. And so that Paulie came to me and was like, I want to spend$60 ,000 on this ad. And my deal with him was like, fine, but you got to sell four more Vantas because the Vanta basically costs$15 ,000. And the next month he sold like 34 more Vantas because of the podcast ads. And that was one where you're like, well, I know nothing. You should keep going. I call this, by the way, I think there's a real, there's the founder negative value out at times for founders have these like incredibly strong views that are wrong, but it's like really hard to remember.

46:27It's good that you let them go and do it. Because sometimes, you know, I think some people would have said, no, we're not doing that. It's silly. and it would have taken many more years to earn the last.

46:34Christina Cacioppo:Yeah, no, the deal is you have to sell four extras. Yeah, yeah, yeah. I feel like I've heard you on the Acquired podcast. We do, yeah. We do, yeah. We do, yeah. We're going to Acquired. Yeah. We do invest, like, the best. Yeah. Yeah. I like those. And I think in the early days, so this was helpful and then deeply unhelpful, but in the early days, before we had competitors, we tried to basically make this call response of, like, someone says SOC 2, someone says Vanta. And this really close association, which in the early, again, when we were just competing against consultants. We wanted to, like, own the term SOC 2, basically.

47:03Christina Cacioppo:Which worked really well until we had competitors who were like, well, we do a sock too, but we're, you know, Vanta but cheaper, but worse but better. And then you're like, oh, that got, you know, like now we're all pointing at a thing we don't own. Yep. And like, that's bad. Yeah. And so there was a, yeah, that's like kind of a, then there was a great reframe on that one. Yeah. What did you learn working with Fred Wilson? USV is a very special place in lots of ways. And I think USV is fundamentally about ideas. More so than other venture firms. Yes. I think most venture firms are sort of great man, great person firms.

47:36Yeah.

47:37Christina Cacioppo:They're about the person and this person will like do the thing. I have no idea what this is, but I like the cut of his jib. Exactly. Yes. And I think USV is, you know, it's just too black and white, but it's like basically the opposite. Whatever person can walk in, but like if it is an idea that is interesting and compelling and intellectually engaging and networked, that is like classic USV. And they've matched back some great people. I don't mean that, but it's just first thing. First, second, and third thing is the idea. And so, like, really pressing on that. It was that piece that I think is, like, very important.

48:14Christina Cacioppo:I think the second part is market sizing is bullshit. You know, you can, like, be as academic or whatever, strategery-ish as you want about it. and like the market size today is only a predictor of the market size today. And I think I like deeply learned that because if you like you just, if you looked at the SOC 2 market in 2018, my best estimate was there was$10 million spent globally and you would never start a startup on that. But the theory of Vanta was like, well, if we can make this thing easier to get and like take down the cost dollars, but really time, more people will get them. And you're like, that ended up being deeply true.

48:58Christina Cacioppo:But that was not a market, especially for startups. The market for startups getting SOC 2 in 2018 was zero dollars. Yes, yes. Truly zero. Yes. Okay, so Vanta is an example of the kind of company that being too tan-grained. Yeah, he would not come up with it. And now it's like, oh, but of course everyone gets it. And you're like, right. But like 2017. Yes. Again, when did Stripe get a SOC 2?

49:25Probably reasonably early on because it's so core. Like it's not a small part of your stack, but definitely before 2017. It's very interesting framing on USV where I feel like you can see this a little bit in Fred's blog and stuff. To ideas. It's clear. Yeah, exactly. Attraction to ideas and a prepared mind for, you know, something like crypto comes along. Exactly, comes along. You're like that thing. You're ready to strike. Yes. And is that across the firm or is that Fred in particular?

49:52Christina Cacioppo:It's Fred and Brad for sure. Brad is the undersung Fred partner. I mean, they started the firm together. Tell me about the Fred and Brad relationship. Yeah, yeah. Brad Burnham is a venture capitalist, mostly retired now, but like X also excellent, incredible track record. He and Fred started Union Square Ventures in, I think, 2002. First fund was 04. Took him two years to raise that fund. If you go look up USV 04 Vintage, like, God, we all should have invested in that, you know. But it was the two of them. And then Albert came on at the venture partner, I think in like 06. And he was on the front of the partner.

50:27Going real deep here, sorry.

50:30Christina Cacioppo:But it was like the two of them. And there is just, it's not yin-yang, it's not the right frame. Complementarity. Yeah. And so many of the ideas of the firm were back and forth by them. And then Fred was excellent at articulating those ideas in a way the rest of the world could understand. which you did on avc yes uh but i think one of the underappreciated things is like how much back and forth there there kind of was there in the creation there yes like that that pairing is i think probably should be in the annals of like you know the coastal door pairing yeah maybe like leone maritz like these venture pairings where you had two people who could play off one of another and they were just like that like i think brad and fred had that for like a decade and a What's the difference in person?

51:21Because like, as I say, Doug and Mike Moritz at Sequoia are very different people. And again, I think that's part of how it works. Yeah.

51:27Christina Cacioppo:I don't think Fred and Brad are as different as those two are. But like, yeah, Brad is cerebral, philosophical, academic, like so interesting to talk to. And you have this wonderful conversation and you'll be like, are there any ties to the business world? You know, but like, but like truly these like, and then like one thing Fred could do was like go back and forth and be like, oh, freemium. and then run with freemium. But it wasn't just, I'm going to market this term. It was a back and forth and the communication out. Wait, did Fred coin the term freemium? He did. Yeah, in a blog post in 2009, I don't know, eight, nine, something like that.

52:02Christina Cacioppo:Yeah, yeah. Right, doesn't that feel like it was just always a term? Yeah, exactly. That's what it's called. In 1952, didn't they talk about freemium? Yeah, it's like when you learn those things like, did you know, seeing the quiet part out loud, that term comes from The Simpsons. In what ways are you a different CEO coming from your experience as an investor? I mean, I wouldn't have done it. It's a real answer. That's a good start. I mean, I was really lucky in approximately 9 million ways with them. One of the ways was for two years, I just like met 15 founders a week for two years straight.

52:34Christina Cacioppo:And I think whatever model I had of like what a founder is or does, was like, yeah, that exists. But like, look at all the ways one can do it. And there's like some coming out, some more successful ones. But just like there's a lot of ways to do this thing. And I think that exposure was super helpful for me because you got to see people who I felt more affinity or similarity to in whatever dimension, like also do it. And it was just like it was kind of the role model thing, but not like one person. Just, you know, you meet a thousand of them. Yes. And you can pick out the pieces. Having all that training data.

53:12What passions do you think you see in people who went on to be successful? or maybe conversely what anti-patterns do you see in the people who

53:18Christina Cacioppo:oh I think there is a like someone said this better than me but like there is a totally a truth seeking piece of it or just sometimes you can bend reality to your will but often like reality is reality and you gotta like embrace it and figure out how to work around it like reality sometimes it's an immovable object and I think there was a there's a delusion to the unsuccessful founders exactly I'm gonna say yeah yeah the like oh no but I can change this and you're like yeah that one I don't Yeah, gravity's gravity, kind of. Yes, yes. Yeah, the version of this I talked about with Des Traynor is I feel like investor updates with a lot of words and no metrics.

53:54Oh, yeah, those are bad. Those are bad. And actually, like, no investor updates is fine. Like, you didn't have to send me a... No is either way. Yeah, yeah, exactly.

54:01Christina Cacioppo:No is either very good or very bad. Yeah, metrics is fine, but, like, a lot of words and no metrics is almost a sure sign of failure. Bad, yes. Yep. Because, again, I think it gets at that delusion. Right. failure to truth seek yes tendency um what else everything famous Etsy and Kickstarter with a bunch of these companies of this era stories where I think I developed yeah this is true this huge appreciation for product market fit that sounds so dumb but kind of now it's still like if you think you have it you don't framing or if you're asking whether you have it you don't yes and so Etsy great example you're like co-founder CEO spent 80 % of his time for kind of years like making people desks because they had this lovely cultural thing that when you joined you were getting like homemade bespoke desks because they sold homemade bespoke things.

54:53Christina Cacioppo:So there's a thing Yancey would make people a desk? Rob, Rob Galen at Etsy would make people a desk. Sorry, I'm getting confused between Kickstarter and Etsy. This is the Etsy version. Yeah, yeah. And you're just like, now you're like 80 % of a CEO's time is making desks and the business is on fire. Amazon had it figured out where you had to make your own desk. Exactly. It's a much more scalable way. Rob made the desks. Yeah. But, you know, you're just like, I mean, it's kind of a funny story, but you're like, the business was fine. Yeah, yeah, yeah. Exactly. You know, and so there are just these things that have, like, their own physical, their own immovable objects.

55:26Yeah, yeah.

55:26Christina Cacioppo:And you can be making desks for people all the time. Doing a podcast. Yeah, yeah, yeah. It doesn't matter. Yeah, yeah. And, like, if you don't have that, you know, it's not that we should all, I mean, maybe we should all go make desks. I don't know. How did, would you make, would you spend time making desks at this stage? I think woodworking is very, I. I don't do it, but I did it as a kid. It was satisfying. Yeah. Last question. Does Vanta expand from here beyond security? Do you start helping people apply with everything else? Just do you continue taking over the world until all the world runs on Vanta?

55:57Christina Cacioppo:Yeah. That's fun. Definitely taking over the world, making desks along the way. No. I think right now we do think about, especially in this world where, in theory, code has become much cheaper, which was two things. So one, it's like, can we add different pillars or verticals? And so there's a whole lot in security, especially for a small business or a mid-market business. I think enterprise, it's a different ballgame there, but there's things there. And then when we think about it, we really think about parts of the CISO organization versus, for the most part, other parts of an organization. But we would think about enterprise risk or internal audit.

56:35Christina Cacioppo:Financial audit is adjacent and interesting. What can you do in internal audit or financial audit? So internal audit is sort of easier for us, given what we've built in a way. It's like we have all of this and, you know, currently we're packaging material and sending it to the auditor. But you can imagine packaging it and sending it to an internal audit. And it's the same thing. It's a controls platform, right? It's like decide what it is that you should do and then validate that you're doing it. Prove that you're doing it. Exactly. Financial audit is the system is similar. It's a different set of integrations on data.

57:07Christina Cacioppo:And so it's thinking through, okay, what is the right point to start building out those ERP integrations, appointments integrations, all of that to get that sort of data to parcel this in. Exciting. Yeah. I'm Christina. Thank you. Thank you.

From the publisher

Christina Cacioppo, founder and CEO of Vanta, joins the pub to discuss building the future of agentic trust. She explains why compliance has a “vitamin vs painkiller” dynamic, the drama behind their famous 101-billboard campaign, and why she believes "market sizing is bullshit." They cover the tension between vibe coding and rigorous security, how Vanta is using agents to generate UI, and why the best founders are relentless truth-seekers.


Timestamps

(00:00:17) Vanta

(00:12:30) How compliance works

(00:15:06) Breaches

(00:23:52) Stripe Tax

(00:24:43) AI and compliance

(00:44:50) Go-to-market

(00:47:22) Lessons from USV

More from Cheeky Pint

All 35 episodes
Compliance at scale and why TAM is a distraction with Christina Cacioppo of VantaCheeky Pint · 57 min
Listen in VO