Hi All,
We are working with a vendor on a compliance project. One of their tools integrates with Bitbucket and checks for misconfigured settings/etc. I was wondering if anyone has come across this and could offer some advice as far as security risks regarding the integration? We obviously don't want to make something more secure by opening up another hole 
From their website:
Overview
Automates the collection of evidence for your code repository configurations, pull request workflows, and security issue tracking.
Automation
Automates 11 tests and 7 controls
Permissions
Vanta requires read-only access to your account information, team membership, repositories, issues, pull requests.
We also request permission to administer your repositories to check branch protection. There is currently no read-only access for this.
Any insights are helpful. Thank you!