Skip to content

Vanta CEO Christina Cacioppo on France's Engineer-Forward Buyers, Slow Procurement, and 'Free as a Puppy' Software

Christina Cacioppo, co-founder and CEO of the compliance and security automation company Vanta, spoke with The French Tech Journal about why the company resonates in Europe, what makes French customers different, and how AI is reshaping demand for security and compliance.

Vanta CEO and Co-Founder Christina Cacioppo. Courtesy of Vanta
Vanta CEO and Co-Founder Christina Cacioppo. Courtesy of Vanta

Vanta sells a promise that has become much harder to keep in the age of AI: that a company can prove, at any given moment, that its systems and data are secure.

The San Francisco-based company automates security and compliance work by pulling in data from across a customer's systems, testing it against the company's controls, and monitoring it continuously. Christina Cacioppo, who taught herself to code before writing Vanta's first prototype, founded the company with engineer Erik Goldman out of Y Combinator in 2018. It has since raised more than $500 million, including a $150 million Series D led by Wellington Management in July 2025 that valued the company at $4.15 billion. Vanta now has roughly 1,000 employees and more than 16,000 customers, among them Snowflake, Atlassian, Duolingo, Ramp, Cursor, and Harvey.

AI has turned out to be a major tailwind. In April, Fortune reported that Vanta had passed $300 million in annual recurring revenue, triple its level of two years earlier, and that customer growth had accelerated to about 60% a year. Much of that demand comes from what the industry calls "shadow AI." Vanta's own data shows that 70% of companies have AI tools that employees adopted without any security review, and that security teams are struggling to keep track of what is already running on their networks.

Europe has been a notable growth driver. Cacioppo says the continent's more regulatory culture makes Vanta an easier sell there than one might expect for an American company, and that its share of revenue from Europe is roughly in line with that of a mature enterprise software company.

The company's European hubs are in London and Dublin, and French AI companies such as Mistral and Dust fit the profile of what she calls its core customers.

During a recent visit to Paris for a Vanta event, Cacioppo spoke with The French Tech Journal about French buyers, procurement cycles, vibe-coded software, and why the debate over open-weight AI models is making data privacy a much more practical concern.

The interview has been edited for length and clarity.

Q: Europe is famous, for better or worse, for its regulatory approach. Is there something about Europe, or France specifically, that makes it an interesting market for Vanta?

CC: I'll give you the Europe side and the French side. On Europe, your observation is true, and we find there's more cultural resonance to what Vanta does here than in the United States. To speak very broadly and in black and white, with all the caveats, I do think regulation and compliance are perceived here as more of something one does, and one does well, and that is just what you do. In the U.S., it can be more like, "Ah, that's a hurdle, and I will jump the hurdle, but I'm carrying on with my race here." And so we just find more resonance here, more than one would expect for an American company.

With France in particular, it is one of my favorite markets actually, because we find our users here tend to be more technical and closer to engineering than any other market. Again, broad brush, broad generalization, but it's much more engineer-forward here versus other markets that might be a generalist or a legal persona or a compliance audit background. You certainly have all of those folks here, but you have relatively more engineers.

Q: A common complaint among French founders is how hard it is to sell to large French enterprises, with proof-of-concept phases that can drag on for 18 months. What has your experience been?

CC: In comparison to the U.S., across Europe, France included, we find procurement cycles are longer across the board, for all company sizes. Again, broad generalization, but we find a French company or a German company of 50, 100, 400 people will act like an American company of 100, 400, 1,000 people. The American company at the same size will often have less mature processes, honestly. So it cuts both ways.

From first meeting to "Oh yes, we'd like to procure Vanta," it's longer here, but not enormously so. But then from "we'd like to procure" to "sign the contract," that period is much longer.

Q: AI has sharply raised concerns about security and safety. Has that always been part of the Vanta playbook, or has it expanded because of how people are using AI?

CC: A little bit of both. I do find one set of tailwinds for Vanta are just things that make people more nervous about the software they're using in general, and AI is right in that bullseye.

What we find practically is companies that deploy AI in their organization right now are trying to figure out what's going on: who's built what, what agents are doing what, with what data. That initial visibility piece is lacking, and therefore concerning. And then companies that are building AI products are getting put through the wringer of security reviews and more vetting and longer procurement, and that's global, so it's not just France or Europe.

Both of those are tailwinds for Vanta, because whenever someone wants to do more vetting of the software they're using, that ends up looking like requests for information, for documents, for certifications, for real-time monitoring, the set of things we offer. So we have seen it be a rather large tailwind.

Q: In Europe, sovereignty and openness are a big part of the conversation, and Chinese open-weight model makers are pitching on-premise deployment and transparency to European buyers. Does that make compliance more complicated for you, or create more opportunity?

CC: More interesting. Yeah, more opportunity. I think it takes data privacy, from an American lens, from a perfunctory topic to an actually very important one. Is the data being used for training, or where is it sent? What is the subprocessor, and whoever you send it to, the LLM, what are they going to do with it? And what are your commitments to your customers? All of that is more practical now than it has been historically, especially for Americans. And so again, I think there's a bunch of anxiety in that, and ergo opportunity for Vanta.

You talk to people in San Francisco about that milieu, and the inference providers like the Basetens and the Fireworks are very involved with open-weight models. One new line of business for them is helping a company post-train a model for a very specific use case. Right now it's very cost-based: you can basically get relatively similar accuracy results for a narrow use case at lower cost. The cost is more internally driven. But I think increasingly you'll see providers doing that for customer demand as well, "We don't want our data sent to insert-large-LLM-here," same way you see some of that here with cloud providers.

Q: Then there's the "SaaS apocalypse" argument: that companies can now vibe-code their own tools and won't need a Vanta. How do you see that?

CC: I have heard and read the "I coded Vanta in a weekend" LinkedIn posts. They're actually kind of great now, because mostly the comment threads are full of people who don't work at Vanta being like, "Why would you do that?"

One of our customers on our advisory board talked about all these vibe-coded apps internally, and we made some of these at Vanta too, for sure. They're all free as in a puppy. As in, you can get a free puppy, and then you have years and years of feeding and grooming and caring and veterinary bills. The software that we can make so quickly with an LLM is free as a puppy. So if you want a free puppy, it is excellent.

Some people want puppies, and some people take care of puppies. It's not like no one will vibe-code things. People definitely vibe-code things. But it gets back to the Jeff Bezos truism of, does this make your beer taste better? Often we find compliance is necessary and important, but not something that perhaps makes the product better beyond its existence, or its existence done well.

Q: Sentiment more recently has swung from "SaaS is dead" to something close to the opposite. Do you find yourself constantly readjusting strategy?

CC: I think the more one reads Twitter or X, the more one thinks one needs to throw everything out immediately and start over. Gotta moderate that one.

I think the high-level principles are clear. This is a new technology wave. It's very important. You need to adopt it. If you don't, you will not have a business in a couple of years. But I think being close to that frontier and just experimenting and understanding the model capabilities and what this new technology is, is really important, because it does change so quickly.

A year ago, we were all about, "Prompt engineering is the new role, and that's what our kids should be learning." Right now the meme is, "Prompts don't matter; it's just model quality." And I'm sure the meme will be something different in six months. You want to be using this stuff so you understand when the conventional wisdom from three months ago is now stale.

Q: How are you using AI in your own products?

CC: We've been building a lot with AI. "Build on Vanta" is our catchphrase for opening up MCP and API and command-line access to a bunch of our data. For the customers that are advanced and do want to build some of their own workflows, where we don't support them to the degree they want yet, that means letting them build around Vanta but still use the core of the automation platform, which pulls in data and correlates it and tests it across a company's controls.

Q: Companies are now moving from experimentation to more practical agentic deployments. Is that changing the equation around compliance and risk?

CC: I do see a little bit of scrutiny there, and I think we'll see more in the future. I think we're at the middle to end of the era of "just go try all the things, just do them." Token max. Don't token max, but use tokens. Go experiment.

In that, there was some amount of kerfuffling about Anthropic data protection policies under some of its plans, and whether or not it would use data to train on. But they were in a position where they wouldn't negotiate it, and they were able to do that. And then you have OpenAI. Broadly generalizing, when I talk to European customers, they have been more skeptical of OpenAI than they have been of an Anthropic or a Gemini or a Copilot.

I think we're gonna firmly leave the token-maxing era and see the model providers have slightly less leverage. Now, they still might have a lot of leverage. But historically, they've just had 100% of it. I start to see the pendulum switch back a little bit.

Q: What are you seeing among French founders? Are there trends in how they build compared with other places?

CC: A couple of things. One, I do think founders everywhere tend to be pretty similar. They might live in Paris, but really they live in the digital cloud, alongside the founders in New York and London and Berlin and San Francisco to some extent. So I think there's actually much more commonality on the small companies side of the market globally than certainly any other segment. And then as the companies grow, they take on more of the qualities of their region or their country, their milieu.

I do think, and I think Dust has done this very well, there's a set of companies that are very consciously hiring engineers and technical talent here, where they are less likely to get poached or go through the Silicon Valley, San Francisco talent wars, which are very real. And so I think there's a real competitive advantage here for French founders that build in that way, from team continuity, from team quality, all of that.

Comments

Latest