v1

latestOpenAPI 3.0.1Vanta Terms of Service2026-07-26327517821.8 KB
Vendors

Update vendor by ID

Update vendor.

patch/vendors/{vendorId}

Path parameters

vendorIdstring required

Request body

namestring

Display name of the vendor.

websiteUrlstring nullable

The url of the vendor's website.

accountManagerNamestring nullable

Name of the external account manager for this vendor.

accountManagerEmailstring

Email of the external account manager for this vendor.

securityOwnerUserIdstring nullable

The Vanta user ID of the security owner of this vendor.

servicesProvidedstring nullable

Services provided by the vendor.

additionalNotesstring nullable

Miscellaneous notes about the vendor

businessOwnerUserIdstring nullable

The Vanta user ID of the business owner of this vendor.

contractStartDatestring date-time nullable

When the contract with the vendor is up for renewal.

contractRenewalDatestring date-time nullable

When the contract with the vendor is up for renewal.

contractTerminationDatestring date-time nullable

When the contract with the vendor was terminated.

isVisibleToAuditorsboolean

Whether or not auditors can view this vendor.

status'MANAGED' | 'ARCHIVED' | 'IN_PROCUREMENT'

The current state of a vendor:

  • MANAGED: The vendor is actively managed.
  • ARCHIVED: The vendor has been archived
  • IN_PROCUREMENT: The vendor is in the procurement process
categorystring

The vendor's category.

inherentRiskLevel'CRITICAL' | 'HIGH' | 'LOW' | 'MEDIUM' | 'UNSCORED'

The risk level of a vendor:

  • CRITICAL: The vendor has a critical security risk
  • HIGH: The vendor has a high security risk
  • MEDIUM: The vendor has a medium security risk
  • LOW: The vendor has a low security risk
  • UNSCORED: The vendor has not been given a risk level
residualRiskLevel'CRITICAL' | 'HIGH' | 'LOW' | 'MEDIUM' | 'UNSCORED'

The risk level of a vendor:

  • CRITICAL: The vendor has a critical security risk
  • HIGH: The vendor has a high security risk
  • MEDIUM: The vendor has a medium security risk
  • LOW: The vendor has a low security risk
  • UNSCORED: The vendor has not been given a risk level
riskAttributeIdsstring[]

A list of risk attribute ids the vendor has been assigned.

vendorHeadquarters'EUE' | 'AND' | 'ARE' | 'AFG' | 'ATG' | 'AIA' | 'ALB' | 'ARM' | 'AGO' | 'ATA' | 'ARG' | 'ASM' | 'AUT' | 'AUS' | 'ABW' | 'ALA' | 'AZE' | 'BIH' | 'BRB' | 'BGD' | 'BEL' | 'BFA' | 'BGR' | 'BHR' | 'BDI' | 'BEN' | 'BLM' | 'BMU' | 'BRN' | 'BOL' | 'BES' | 'BRA' | 'BHS' | 'BTN' | 'BVT' | 'BWA' | 'BLR' | 'BLZ' | 'CAN' | 'CCK' | 'COD' | 'CAF' | 'COG' | 'CHE' | 'CIV' | 'COK' | 'CHL' | 'CMR' | 'CHN' | 'COL' | 'CRI' | 'CUB' | 'CPV' | 'CUW' | 'CXR' | 'CYP' | 'CZE' | 'DEU' | 'DJI' | 'DNK' | 'DMA' | 'DOM' | 'DZA' | 'ECU' | 'EST' | 'EGY' | 'ESH' | 'ERI' | 'ESP' | 'ETH' | 'FIN' | 'FJI' | 'FLK' | 'FSM' | 'FRO' | 'FRA' | 'GAB' | 'ENG' | 'SCT' | 'GBR' | 'WAL' | 'NIR' | 'GRD' | 'GEO' | 'GUF' | 'GGY' | 'GHA' | 'GIB' | 'GRL' | 'GMB' | 'GIN' | 'GLP' | 'GNQ' | 'GRC' | 'SGS' | 'GTM' | 'GUM' | 'GNB' | 'GUY' | 'HKG' | 'HMD' | 'HND' | 'HRV' | 'HTI' | 'HUN' | 'IDN' | 'IRL' | 'ISR' | 'IMN' | 'IND' | 'IOT' | 'IRQ' | 'IRN' | 'ISL' | 'ITA' | 'JEY' | 'JAM' | 'JOR' | 'JPN' | 'KEN' | 'KGZ' | 'KHM' | 'KIR' | 'COM' | 'KNA' | 'PRK' | 'KOR' | 'KWT' | 'CYM' | 'KAZ' | 'LAO' | 'LBN' | 'LCA' | 'LIE' | 'LKA' | 'LBR' | 'LSO' | 'LTU' | 'LUX' | 'LVA' | 'LBY' | 'MAR' | 'MCO' | 'MDA' | 'MNE' | 'MAF' | 'MDG' | 'MHL' | 'MKD' | 'MLI' | 'MMR' | 'MNG' | 'MAC' | 'MNP' | 'MTQ' | 'MRT' | 'MSR' | 'MLT' | 'MUS' | 'MDV' | 'MWI' | 'MEX' | 'MYS' | 'MOZ' | 'NAM' | 'NCL' | 'NER' | 'NFK' | 'NGA' | 'NIC' | 'NLD' | 'NOR' | 'NPL' | 'NRU' | 'NIU' | 'NZL' | 'OMN' | 'PAN' | 'PER' | 'PYF' | 'PNG' | 'PHL' | 'PAK' | 'POL' | 'SPM' | 'PCN' | 'PRI' | 'PSE' | 'PRT' | 'PLW' | 'PRY' | 'QAT' | 'REU' | 'ROU' | 'SRB' | 'RUS' | 'RWA' | 'SAU' | 'SLB' | 'SYC' | 'SDN' | 'SWE' | 'SGP' | 'SHN' | 'SVN' | 'SJM' | 'SVK' | 'SLE' | 'SMR' | 'SEN' | 'SOM' | 'SUR' | 'SSD' | 'STP' | 'SLV' | 'SXM' | 'SYR' | 'SWZ' | 'TCA' | 'TCD' | 'ATF' | 'TGO' | 'THA' | 'TJK' | 'TKL' | 'TLS' | 'TKM' | 'TUN' | 'TON' | 'TUR' | 'TTO' | 'TUV' | 'TWN' | 'TZA' | 'UKR' | 'UGA' | 'UMI' | 'USA' | 'URY' | 'UZB' | 'VAT' | 'VCT' | 'VEN' | 'VGB' | 'VIR' | 'VNM' | 'VUT' | 'WLF' | 'WSM' | 'YEM' | 'MYT' | 'ZAF' | 'ZMB' | 'ZWE'

Example request

{
  "frameworkScope": {
    "frameworkIds": [
      "soc2",
      "hipaa"
    ]
  }
}

Response

Ok

idstring required

The vendor's unique ID.

namestring required

The vendor's display name.

websiteUrlstring nullable required

The vendor's website URL.

accountManagerNamestring nullable required

The vendor's external account manager name.

accountManagerEmailstring nullable required

The vendor's external account manager email.

servicesProvidedstring nullable required

Services provided by the vendor.

additionalNotesstring nullable required

Any additional notes about the vendor

securityOwnerUserIdstring nullable required

The vendor's security owner's Vanta user ID.

businessOwnerUserIdstring nullable required

The vendor's business owner's Vanta user ID.

contractStartDatestring date-time nullable required

The date the contract with the vendor began.

contractRenewalDatestring date-time nullable required

The date the contract with the vendor is up for renewal.

contractTerminationDatestring date-time nullable required

The date the contract with the vendor was terminated.

nextSecurityReviewDueDatestring date-time nullable required

The next due date for a security review.

lastSecurityReviewCompletionDatestring date-time nullable required

The most recent date a security review was completed.

isVisibleToAuditorsboolean nullable required

Whether or not auditors can view this vendor.

isRiskAutoScoredboolean nullable required

Whether or not the vendor's risk is automatically scored.

riskAttributeIdsstring[] required

The list of risk attribute IDs the vendor has been assigned to.

status'MANAGED' | 'ARCHIVED' | 'IN_PROCUREMENT' required

The current state of a vendor:

  • MANAGED: The vendor is actively managed.
  • ARCHIVED: The vendor has been archived
  • IN_PROCUREMENT: The vendor is in the procurement process
inherentRiskLevel'CRITICAL' | 'HIGH' | 'LOW' | 'MEDIUM' | 'UNSCORED' required

The risk level of a vendor:

  • CRITICAL: The vendor has a critical security risk
  • HIGH: The vendor has a high security risk
  • MEDIUM: The vendor has a medium security risk
  • LOW: The vendor has a low security risk
  • UNSCORED: The vendor has not been given a risk level
residualRiskLevel'CRITICAL' | 'HIGH' | 'LOW' | 'MEDIUM' | 'UNSCORED' required

The risk level of a vendor:

  • CRITICAL: The vendor has a critical security risk
  • HIGH: The vendor has a high security risk
  • MEDIUM: The vendor has a medium security risk
  • LOW: The vendor has a low security risk
  • UNSCORED: The vendor has not been given a risk level
vendorHeadquarters'EUE' | 'AND' | 'ARE' | 'AFG' | 'ATG' | 'AIA' | 'ALB' | 'ARM' | 'AGO' | 'ATA' | 'ARG' | 'ASM' | 'AUT' | 'AUS' | 'ABW' | 'ALA' | 'AZE' | 'BIH' | 'BRB' | 'BGD' | 'BEL' | 'BFA' | 'BGR' | 'BHR' | 'BDI' | 'BEN' | 'BLM' | 'BMU' | 'BRN' | 'BOL' | 'BES' | 'BRA' | 'BHS' | 'BTN' | 'BVT' | 'BWA' | 'BLR' | 'BLZ' | 'CAN' | 'CCK' | 'COD' | 'CAF' | 'COG' | 'CHE' | 'CIV' | 'COK' | 'CHL' | 'CMR' | 'CHN' | 'COL' | 'CRI' | 'CUB' | 'CPV' | 'CUW' | 'CXR' | 'CYP' | 'CZE' | 'DEU' | 'DJI' | 'DNK' | 'DMA' | 'DOM' | 'DZA' | 'ECU' | 'EST' | 'EGY' | 'ESH' | 'ERI' | 'ESP' | 'ETH' | 'FIN' | 'FJI' | 'FLK' | 'FSM' | 'FRO' | 'FRA' | 'GAB' | 'ENG' | 'SCT' | 'GBR' | 'WAL' | 'NIR' | 'GRD' | 'GEO' | 'GUF' | 'GGY' | 'GHA' | 'GIB' | 'GRL' | 'GMB' | 'GIN' | 'GLP' | 'GNQ' | 'GRC' | 'SGS' | 'GTM' | 'GUM' | 'GNB' | 'GUY' | 'HKG' | 'HMD' | 'HND' | 'HRV' | 'HTI' | 'HUN' | 'IDN' | 'IRL' | 'ISR' | 'IMN' | 'IND' | 'IOT' | 'IRQ' | 'IRN' | 'ISL' | 'ITA' | 'JEY' | 'JAM' | 'JOR' | 'JPN' | 'KEN' | 'KGZ' | 'KHM' | 'KIR' | 'COM' | 'KNA' | 'PRK' | 'KOR' | 'KWT' | 'CYM' | 'KAZ' | 'LAO' | 'LBN' | 'LCA' | 'LIE' | 'LKA' | 'LBR' | 'LSO' | 'LTU' | 'LUX' | 'LVA' | 'LBY' | 'MAR' | 'MCO' | 'MDA' | 'MNE' | 'MAF' | 'MDG' | 'MHL' | 'MKD' | 'MLI' | 'MMR' | 'MNG' | 'MAC' | 'MNP' | 'MTQ' | 'MRT' | 'MSR' | 'MLT' | 'MUS' | 'MDV' | 'MWI' | 'MEX' | 'MYS' | 'MOZ' | 'NAM' | 'NCL' | 'NER' | 'NFK' | 'NGA' | 'NIC' | 'NLD' | 'NOR' | 'NPL' | 'NRU' | 'NIU' | 'NZL' | 'OMN' | 'PAN' | 'PER' | 'PYF' | 'PNG' | 'PHL' | 'PAK' | 'POL' | 'SPM' | 'PCN' | 'PRI' | 'PSE' | 'PRT' | 'PLW' | 'PRY' | 'QAT' | 'REU' | 'ROU' | 'SRB' | 'RUS' | 'RWA' | 'SAU' | 'SLB' | 'SYC' | 'SDN' | 'SWE' | 'SGP' | 'SHN' | 'SVN' | 'SJM' | 'SVK' | 'SLE' | 'SMR' | 'SEN' | 'SOM' | 'SUR' | 'SSD' | 'STP' | 'SLV' | 'SXM' | 'SYR' | 'SWZ' | 'TCA' | 'TCD' | 'ATF' | 'TGO' | 'THA' | 'TJK' | 'TKL' | 'TLS' | 'TKM' | 'TUN' | 'TON' | 'TUR' | 'TTO' | 'TUV' | 'TWN' | 'TZA' | 'UKR' | 'UGA' | 'UMI' | 'USA' | 'URY' | 'UZB' | 'VAT' | 'VCT' | 'VEN' | 'VGB' | 'VIR' | 'VNM' | 'VUT' | 'WLF' | 'WSM' | 'YEM' | 'MYT' | 'ZAF' | 'ZMB' | 'ZWE' required