# Vanta: 11 point Door Gap
- Site: vanta.com
- Scanned: 2026-09-08
- Scan type: Basic scan
- Business type: b2b_saas
- Report: https://www.seconddoor.io/r/vanta-z9acct
- Scanner version: 12
Vanta publishes no pricing and routes all buyers to a sales demo, blocking agents from computing cost before signup.
## Scores
| Measure | Score |
| --- | --- |
| Humans | 57/100 |
| Agents | 46/100 |
| Composite | 52/100 |
| Door Gap | 11 points |
| Percentile | 16th |
The human score is the mean of the four human dimensions, the agent score the mean of the six agent dimensions, and the Door Gap the difference between them.
## What the machine actually did
The agent got through 7 of 15 requests, but could not read the site's own guide for language models. It came up empty on 7 other checks too. That is enough missing for a machine to give up before it reaches a purchase.
- ok      reach the site at all
- ok      find out whether machines are welcome
- ok      ask whether the door opens for requests carrying the AI crawlers' names
- missing read the site's own guide for language models
- ok      find out what pages exist
- ok      find a contact route for machines
- ok      find a published agent interface
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- missing read the homepage as data rather than as a page
- missing find a machine readable API spec
- missing read the developer documentation
- missing read the prices without running JavaScript
- missing find a comparison page worth citing
- ok      walk the way a visitor would, to a signup form or a product
## Top issues
1. **Vanta publishes no prices on its pricing page, forcing all buyers to request a demo before learning cost.** (pricing_legibility)
2. **The signup form requires 7 of 14 fields, including company headcount and HQ country, which an agent cannot reliably infer.** (required_fields)
3. **The developer documentation contains no API endpoints, authentication details, code samples or self-serve key issuance.** (programmatic_onboarding)
The evidence and the recommended fix for each are on the report page: https://www.seconddoor.io/r/vanta-z9acct
## Files generated from this scan
- **A pricing page that states a price** at `/pricing.md`, 1 hour, no developer needed. Verify: The next scan reads at least one price in the raw HTML of the pricing page.
- **A comparison page brief** at `/compare/vanta-vs-competitor`, 3 hours, no developer needed. Verify: The next scan finds a comparison page listed in the sitemap or linked from the homepage, and reads its text without JavaScript.
- **robots.txt rules for AI crawlers** at `/robots.txt`, 10 minutes, no developer needed. Verify: The next scan reads robots.txt and finds every search and agent crawler allowed, none of them kept off product or pricing paths.
- **Machine interfaces: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds the interface you published answering at its well-known path, and that check passes.
- **Organization structured data** at `homepage`, 15 minutes, developer. Verify: The next scan reads Organization and WebSite nodes in the homepage JSON-LD and the structured data check passes.
- **llms.txt** at `/llms.txt`, 15 minutes, no developer needed. Verify: The next scan fetches /llms.txt as text and the llms.txt check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/vanta-z9acct
## The agent door
- **machine_discoverability** 68/100. No AI crawler is blocked by robots.txt, a real browser is served the page normally, and the sitemap lists 1286 URLs. However, the homepage carries no JSON-LD or microdata markup, so machines cannot extract product details, pricing tiers or.
- **programmatic_onboarding** 10/100. The developer documentation at developer.vanta.com contains 1513 characters of text but shows no API credentials, endpoints, code samples, authentication documentation or self-serve key issuance.
- **pricing_legibility** 12/100. The pricing page at vanta.com/pricing publishes zero prices in raw HTML or rendered output. The page routes visitors to a demo request form instead, making it impossible for an agent to compute total cost of ownership before signup.
- **agent_aware_instrumentation** 58/100. An MCP manifest is published.
- **machine_fetchable_trust** 85/100. security.txt is published at /.well-known/security.txt with a contact route for machines. The homepage responds to automated requests with HTTP 200 and renders normally in a browser, establishing basic trust signals.
- **commercial_rails** 40/100. A self-serve signup form is reachable 2 steps from the homepage and asks for 14 fields with 7 required. The form does not ask for payment, and the primary call to action routes to a demo request, not a trial or purchase flow.
## The human door
- **steps_to_first_value** 80/100. The signup form is 2 steps from the homepage. However, the form itself is a demo request, not a trial activation, so the path to working access requires a sales conversation after submission.
- **required_fields** 25/100. The signup form contains 14 fields total, of which 7 are required: work email, first name, last name, company name, job title, company headcount and company HQ country. This is a high barrier for an agent to clear without human context.
- **verification_walls** 65/100. No verification requirement appears on the signup page itself. The form does not ask for email confirmation, phone verification or identity proof before submission. What happens after submission could not be observed in this scan.
- **error_recovery** 58/100. 7 of 14 form inputs carry validation rules, providing inline feedback for malformed entries. No live regions or inline error containers were detected, so error messages may not be announced to assistants.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
