## Why It Matters

Vanta tracks security-awareness training as a personnel task and reopens it every year. Kit does not push completions into Vanta, so Vanta treats Kit as a **Custom** training source. Vanta links each person to the training, then asks them to upload proof of completion. The Kit completion certificate is that proof.

| Step | Where | Who |
|---|---|---|
| Publish the program, invite the roster | Kit | Training admin |
| Set Kit as the Custom training | Vanta | Vanta admin |
| Complete the training, download the certificate | Kit portal | Employee |
| Upload the certificate, click **Submit** | Vanta | Employee, or an admin on their behalf |
| Export the completion register | Kit | Training admin |

## 1. Prepare the Program in Kit

1. **Publish the program.** Invitations only work for a published program.
2. **Invite with Vanta's email addresses.** Only invited addresses can sign in to the portal, so use the same email each person has in Vanta. Someone who follows the Vanta link with an uninvited address is told a link was sent, but none arrives. Add the employee ID too; it lands in the register export. See [Participants, Completion & Recertification](/docs/training-participants-completion-and-recertification).
3. **Write the next step into the portal.** On the program page, open **Portal content** and fill in **Completion message**. Participants see it right above the **Download certificate** button:

   > Download your certificate below, then upload it to your Vanta training task at app.vanta.com/onboarding and click **Submit**.

   EU and Australian Vanta accounts use `app.eu.vanta.com` and `app.aus.vanta.com`.

## 2. Point Vanta at Kit

In Vanta, as an admin:

1. Go to **Personnel** → **People** → **Groups** and open the group. Everyone belongs to the default group.
2. In the **Tasks** tab, click **Trainings**.
3. In **Manage trainings**, enable the training category.
4. Choose **Custom** (**Custom training** in newer accounts), click **Add training**, and select **Custom training**.
5. Enter the URL `https://startupkit.app/training/portal/login` and instructions such as: *"Complete the training in Kit, download your certificate from the completion page, upload the PDF here and click Submit."*
6. Save. Newer accounts ask twice: **Save** in the modal, then **Save** on the group page and confirm the review.

| Kit template | Vanta training category |
|---|---|
| SOC 2, ISO 27001 | General security awareness |
| HIPAA | HIPAA |
| GDPR | GDPR |

> [!NOTE]
> Vanta allows one training source per category. Switching a category to Custom replaces Vanta's own videos for that group. Categories other than General security awareness appear only if your Vanta plan includes the matching framework.

## 3. What Each Person Does

1. Opens the training task in Vanta under **My security tasks** and follows the link to Kit.
2. Signs in with a magic link or Google, finishes the training, and signs the attestation.
3. Clicks **Download certificate** on the completion page.
4. Uploads the PDF to the Vanta task and clicks **Submit**.

The certificate shows the person's name, the program and version, the completion date, the quiz score, how their identity was verified, the signed attestation, and a `tcr_…` evidence record ID an auditor can trace back to Kit.

**People without a Vanta login.** Uploading requires an Employee role in Vanta. For anyone without one, download their certificate from the **Certificate** action on their **Completion register** row, then upload it from their profile on Vanta's **People** page.

> [!WARNING]
> Vanta cannot uncheck a completed task. Check that the certificate belongs to the right person before you submit it on their behalf.

## 4. Keep the Register for the Audit

Certificates close individual tasks. The register proves the whole cohort. From the program's **Completion register**, click **Export CSV** for Vanta's seven training columns or **Export PDF** for a branded register. Attach it to your security-awareness training evidence in Vanta, or hand it straight to the auditor.

After an annual cycle, a person appears twice in the export: last year's completed row and this year's open one. That is the history, not a duplicate.

## Recertification and Reminders

Both tools reopen training one year after the last completion. Kit invites the person to a new cycle; Vanta reopens their task. The new certificate carries the new date, so the flow repeats as-is.

Each tool sends its own reminders. Kit's stop when the person finishes in Kit; Vanta's stop when they upload. A completion message that asks for the upload in the same breath keeps the two from drifting apart.

## Quick Checklist

- [ ] Program published; roster invited with the email addresses used in Vanta
- [ ] **Completion message** tells people to upload the certificate to Vanta
- [ ] Vanta group has the category set to **Custom** with the Kit portal URL
- [ ] One person tested end to end: Vanta task → Kit training → certificate → **Submit**
- [ ] Register exported before the audit window closes