Skip to content

Compliance

Vanta MCP connector

Connecting Vanta to Elaichi lets Claude, ChatGPT, Cursor, and any other MCP client read and update your controls, documents, tests, and frameworks, with each person signed in as themselves and every action recorded in an audit log.

  • How it connects. App credentials. The credential goes into a vault nobody reads back.

  • One address. https://api.elaichi.ai/mcp, the same for every user.

  • Their own access. An agent never gets more than the person it acts for.

How to connect

How to connect Vanta to Claude, ChatGPT or Cursor

Two steps, about a minute.

1

In Elaichi

Connect Vanta once

  1. Open Connections, choose Add connection, and pick Vanta.

  2. Optionally set Share with to give a team access, then press Connect.

  3. Paste your Vanta app credentials. Vanta authenticates the app rather than a person. One person supplies the credentials once, and everyone else works through Share with.

The credential is vaulted. Nobody reads it back, not even the AI.

Add connection

Choose a connector.

vanta
Vanta
Alloy
Cakewalk
Comp AI
ComplyCube
Drata
2

In your AI client

Point it at one endpoint

Everyone in the organization uses the same address, and each person only ever reaches what their own account allows.

Connect Vanta to Claude

  1. 1

    Open Customize, then Connectors.

  2. 2

    Press Add.

  3. 3

    Name it, paste the MCP server URL, then Continue.

    https://api.elaichi.ai/mcp
  4. 4

    Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

Connect Vanta to ChatGPT

  1. 1

    Open Plugins, then press the + button.

  2. 2

    Name it and paste the endpoint into Server URL.

    https://api.elaichi.ai/mcp
  3. 3

    Leave Authentication on OAuth, then tick the risk acknowledgement.

  4. 4

    Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

Connect Vanta to Cursor

  1. 1

    Open ~/.cursor/mcp.json.

  2. 2

    Add the endpoint under mcpServers.

    https://api.elaichi.ai/mcp
  3. 3

    Reload Cursor, then sign in and approve.

~/.cursor/mcp.json

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

Set up per machine, so repeat it on each computer you work from.

Connect Vanta to any MCP client

  1. 1

    Add the endpoint as a remote MCP server.

    https://api.elaichi.ai/mcp
  2. 2

    Sign in and approve.

{
  "mcpServers": {
    "elaichi": {
      "url": "https://api.elaichi.ai/mcp"
    }
  }
}

The Elaichi Agent already has these tools, with nothing to set up.

Use cases

What teams do with Vanta through Elaichi

Every one of these runs inside the access the person already has, and lands in the same audit log.

  • Compliance

    Find every control still missing an owner

    Ask which Vanta controls have no owner assigned, then set the right person on each one without opening every record by hand.

  • Security

    Attach evidence after a fix ships

    Once a gap is closed, add the screenshot or export as a control document in Vanta so the control shows evidence before the auditor asks.

  • IT

    Upload a policy and submit it

    Create the document in Vanta, attach the signed policy file, and submit it for review in one conversation instead of three clicks and an email.

  • Compliance

    See what a new framework will require

    List the frameworks in your Vanta account, pull one up in detail, and add the controls you still need from the library.

  • Engineering

    Add a test to a control

    When a control is verified by a check your team already runs, record that test against the Vanta control so it stays visible to the compliance team.

  • Legal

    Pull the file an auditor asked for

    Ask for the current version of a Vanta document by name, download the attached file, and hand it over without searching folders.

Try asking

  • “Which Vanta controls have failing control tests this week?”
  • “List Vanta controls with no owner set.”
  • “Show control documents uploaded in Vanta this month.”

See all 182 Vanta tools below

AI tools

Vanta tools for your AI agents

182 tools are ready to call through Elaichi's MCP endpoint the moment you connect Vanta, governed by the same roles, restrictions, and audit log as everything else in Elaichi.

See it in Elaichi

What connecting Vanta gets you

6 screens from the product, each doing one job for your Vanta account.

The agent

Ask about controls, get answers from Vanta.

Plain language questions return live Vanta controls, tests and documents.

  • controls
  • control tests
  • control documents
  • documents

Ask Elaichi to work across your apps.

Which Vanta controls have failing control tests this week?

List Vanta controls with no owner set.

Show control documents uploaded in Vanta this month.

Also runs in Claude, ChatGPT or Cursor

MCP clients

One Vanta endpoint for every MCP client.

Claude, ChatGPT and Cursor connect over OAuth, no SDK, no shared key.

ElaichiMCP clients
Claude ChatGPT Cursor

Copy the endpoint

https://api.elaichi.ai/mcp
Client Connected by Status Last used
Claude
E

Emma Laurent

• Connected 4 minutes ago
Cursor
S

Sofia Ricci

• Connected 2 hours ago
ChatGPT
C

Clara Nowak

• Connected Yesterday

Tool catalog

182 Vanta tools ready without custom code.

Controls, control tests, control documents and documents, each with full methods.

  • List all Vanta controls
  • Get single Vanta control by ID
  • Create a Vanta control
  • Update a Vanta control by ID
ElaichiTools
Tool Action Description
List all Vanta controls List List controls in Vanta. Returns id, externalId, name, description, source, domains, owner, role, and customFields for each control.
Get single Vanta control by ID Get Get a control in Vanta by id. Returns fields such as id, externalId, name, description, source, domains, owner, customFields, numDocumentsPassing, numDocumentsTotal, numTestsPassing, numTestsTotal, status, role, and note.
Create a Vanta control Create Create a custom control in Vanta. Requires externalId, name, description, effectiveDate, and domain as parameters. Returns id, externalId, name, description, source, domains, owner, role, and customFields, which include information about the newly created control.
Update a Vanta control by ID Update Update a control's metadata in Vanta using id. Returns id (control's unique ID), externalId (external control ID), name, description, source, domains, owner, role, and customFields in the response.
Delete a Vanta control by ID Delete Delete a specific control in Vanta using id. No content is returned in the response when the control is successfully removed.

Toolboxes

Every team gets its own Vanta toolbox.

Curate one toolbox per team and scope it to the Vanta work they own.

  • Security
  • Compliance
  • Engineering
  • IT Operations
ElaichiToolboxes
Name Source template Tools Created

Security toolbox

Vanta · controls and control tests

Vanta starter 18 Mar 4, 2026

Compliance toolbox

Vanta · frameworks and evidence documents

9 Mar 2, 2026

Engineering toolbox

Vanta · failing tests and remediation

24 Feb 27, 2026

IT Operations toolbox

Vanta · control owners and policies

Vanta starter 6 Feb 19, 2026

Legal toolbox

Vanta · documents and attestations

31 Jan 30, 2026

Audit toolbox

Vanta · read only control history

12 Jan 22, 2026

Shared connections

Teammates use Vanta without seeing a credential.

See who connected each Vanta account and which teams and members it reaches.

  • Security
  • Compliance
  • Engineering
  • IT Operations
ElaichiConnections
Connection Scope Status Access
VA

Vanta (Security)

Connected by Emma Laurent

Personal • Active 1 team · 6 members
VA

Vanta (Compliance)

Connected by James Whitfield

Organization • Active 3 teams · 24 members
VA

Vanta (Engineering)

Connected by Sofia Ricci

Organization • Active 2 teams · 11 members
VA

Vanta (IT Operations)

Connected by Daniel Ortega

Personal • Needs re-auth 1 team · 3 members
VA

Vanta (Legal)

Connected by Clara Nowak

Personal • Active Not shared
VA

Vanta (Audit)

Connected by Michael Brennan

Personal • Active 2 teams · 9 members

Audit log

Every Vanta call is on the record.

When, who, what happened, type and resource for each control and document change.

  • When
  • Who
  • What happened
  • Type
ElaichiAudit log
When Who What happened Type

2 minutes ago

Mar 6, 2026, 3:10 PM

E

Emma Laurent

[email protected]

Restriction Created Access

8 minutes ago

Mar 6, 2026, 3:04 PM

J

James Whitfield

[email protected]

Restriction Updated Access

14 minutes ago

Mar 6, 2026, 2:58 PM

S

Sofia Ricci

[email protected]

Role Assigned Access

20 minutes ago

Mar 6, 2026, 2:52 PM

D

Daniel Ortega

[email protected]

Vanta Users Updated MCP

26 minutes ago

Mar 6, 2026, 2:46 PM

C

Clara Nowak

[email protected]

Vanta Controls Created MCP

32 minutes ago

Mar 6, 2026, 2:40 PM

M

Michael Brennan

[email protected]

Vanta Controls List Toolbox

Launching soon

From answering questions to doing the work

A person no longer has to ask. A trigger starts the work, inside the same permissions and the same audit log as everything else. Automations and live dashboards are launching soon, on the Black plan.

Automations

A schedule fires and Vanta work finishes.

Fetch controls, group them, draft a digest, get approval, post back to Vanta.

Vanta digest

Run 418 · started 2 minutes ago · on behalf of Emma Laurent

  1. Schedule

    Every weekday at 08:00

    0.2s
  2. Fetch controls

    Vanta

    1.4s
  3. Group by owner

    Transform

    0.1s
  4. Draft the digest

    Agent step

    Ran with 4 tools, returned a structured summary

    6.2s
  5. Approve the digest

    Needs approval

    Assigned to Michael Brennan

    Approve
  6. Post the digest

    Vanta

    Queued

Collections and dashboards

Vanta compliance numbers, counted not generated.

Four metrics, 14 days of controls created, split by team, refreshed on schedule.

Vanta health

Refreshed 4 minutes ago · every 15 minutes · from the controls collection

Live

Controls

1,284 ↓ 12%

Control tests

96 ↓ 8%

Needs attention

3 ↑ 2

Updated this week

412 ↑ 9%

Controls created

Last 14 days

By team

Share of activity

Security 34%

Compliance 27%

Engineering 21%

IT Operations 18%

FAQ

Frequently asked questions

How do I connect Vanta to Claude?

Two steps. In Elaichi, add the Vanta connector and enter your Vanta app credentials, then paste https://api.elaichi.ai/mcp into Claude under Customize, then Connectors, then Add. There is no OAuth application to register in Vanta and no client ID or secret to generate. It takes a few minutes.

Does Vanta work with ChatGPT and Cursor as well as Claude?

Yes. Once Vanta is connected in Elaichi, the same https://api.elaichi.ai/mcp endpoint works in Claude, ChatGPT, Cursor, any other MCP client, and the Elaichi Agent. You connect Vanta once and every client uses that one connection.

What can an AI agent actually do with my Vanta data?

It can list your Vanta controls, find the ones with no owner and assign one, add controls from the library, and create or remove controls and their tests. It can also create and submit documents, attach or download the files behind them, and look up the frameworks your Vanta account tracks. Because Vanta exposes a lot of actions, short concrete asks like "show controls without an owner" work better than long paragraphs.

Does connecting Vanta give the AI access to everything in my Vanta account?

No. Every call to Vanta runs inside the access of the person who signed in, so the agent sees only the controls, documents, and frameworks that person could already see in Vanta. Elaichi can narrow that access further with restrictions, and it can never widen it beyond what Vanta itself allows.

Can my team share one Vanta connection?

Yes. One person connects Vanta in Elaichi and shares the connection with a team, and nobody else ever handles the Vanta credentials. Each teammate still signs in to Elaichi as themselves, so the audit log records who assigned an owner or submitted a document, not just that the shared connection did.

Can I stop an agent from deleting or changing things in Vanta?

Yes. Restrictions in Elaichi apply per action, so you can allow reading Vanta controls and documents while blocking deletes, updates, or submissions. A blocked action is never advertised to Claude, ChatGPT, Cursor, or any other client, so no prompt can reach it.

What happens to a Vanta connection when someone leaves?

Offboarding that person in Elaichi ends their access to Vanta through every client at once. If they connected Vanta and shared it, the connection keeps working for everyone else on the team. If you ever want Vanta gone entirely, disconnecting it once in Elaichi removes it from Claude, ChatGPT, Cursor, and every other client together.

Put Vanta in front of your team

Fourteen days on Gold, no credit card. Connect it once and pick what each team can call.