Where the GRC community shapes what’s next
Registration is open for in-person and virtual tickets. In-person tickets start at $200, attend virtually for free.
Joined by speakers from
Featured Speakers





AI is fast transforming every aspect of security and compliance—and no aspect of GRC will be left unchanged.
This year at VantaCon, join us for a full-day GRC community event! Be the first to hear exciting product announcements, discover how industry peers and leaders are preparing for big changes while uncovering unique opportunities for growth, and take part in new breakout sessions designed for collaboration—not just on what’s next for GRC, but how we’ll write its future together.

Hear from the GRC and security leaders shaping the industry
Meet top security and compliance minds from across the GRC community and hear how they’re building their GRC programs in the new age of AI.

Network with the best
Connect with peers from across the GRC community to swap stories, share ideas, and build lasting relationships.

Help us write the future of GRC
Be part of the community reimagining what trust looks like next.
Speakers

















Agenda










Questionnaires are the backbone of TPRM. But for organizations with thousands of vendors, they lead to inefficiencies and busy work. It’s time to rethink third-party risk from a customer and vendor perspective. Enter AI, tiered risk scoring, and more proactive ways to demonstrate security maturity.

How do you calculate ROI of things that never happened? The key is aligning how you communicate value to business risk. Having developed and now leading the GRC at Duolingo, Mandy has built a framework for doing just that in a way that impacts teams, boards, and executives.

Modern GRC teams must cover more frameworks, manage more risks, and implement controls in more atomised environments. GRC Engineering can help manage the complexity. Learn how to use engineering problem-solving techniques to solve common challenges and build stronger connections across your teams.

AI agents are moving fast from theory to practice, transforming how GRC gets done. In this session, we’ll cover the risks, rewards, and responsibilities of deploying them—plus practical strategies, frameworks, and standards to help you innovate securely while staying compliant.





GRC is often seen as a box-checking exercise. But a strong program goes beyond audits—it accelerates sales cycles, builds customer trust, and frees engineering teams to focus on innovation. Learn how to position GRC as a business enabler, with controls and treatment plans that address what matters.



“Move fast and break things” doesn’t cut it anymore. Winning startups pair rapid innovation with strong security from day one—turning trust into a growth accelerator and a lasting competitive edge. Join this session for a series of stories from the startup trenches.


Compliance teams face pressure to develop AI governance strategies that mitigate risk and protect information. But many don’t know where to start. Learn practical strategies to understand risk, generate buy-in from stakeholders, and build a team of partners to stay ahead of evolving threats.

Teams want faster access to new tools, executives expect deeper supply chain assurance, and customers demand more visibility. Yet building a Risk Management program that monitors all facets of risk is challenging. Learn how Ironclad’s own Fish Fisher has scaled risk management into business impact.

AI brings new security and privacy threats to the table, but no GRC specialist can afford to fear or ignore it. Learn how to stay ahead of the evolving AI landscape, while also unlocking opportunities to provide secure AI to your organization and create a competitive advantage.


Breakout session themes
AI beyond the hype
Navigating the impact of AI on risk, security, and GRC
Prove program impact
Proving program value: influence, impact, and buy-in.
Scale your career
Analyst to exec: evolving your GRC career.
FAQs
November 19, 2025 at Convene 100 Stockton in San Francisco.
Two ticket types are available:
1. In-person event: attend the in-person event in San Francisco to get the full VantaCon experience, tickets start at $200 for early bird pricing, once early bird tickets are sold out ticket price will increase to $300.
2. Virtual event: Join VantaCon virtually for Free! This will be a livestream experience of the keynotes and a limited number of breakouts. Virtual attendees will have access to real-time Q&A.
To register, simply click the "register" button above.
Yes, please reach out to coryn.mulrey@vanta.com
We’ve got you! Download this letter to help show your manager all the benefits of joining VantaCon this year.
Yes, we've reserved a limited number of rooms with a group rate at the Clift Royal Sonesta San Francisco. Book here.
Yes, we’re offering a buy-2-get-1 free promotion for groups of attendees. You’ll be able to select this option during the registration process.
Yes! A portion of the event will be made available to view and participate in virtually. You can register for the virtual event via the “register now” button and selecting the virtual option. To attend virtually is free.
Tickets are nonrefundable per registration terms & conditions. In most cases we can transfer your ticket to another guest if you are no long able to make it. Please reach out vantaconsupport@vanta.com.