Screenata

Changelog

What we ship, every week.

Screenata moves fast. Here's a running log of the new features, integrations, and improvements we release across SOC 2, HIPAA, and ISO 27001, updated weekly.

Latest · 18 updates

New

  • Screenata now works out which cloud services you actually run — across AWS, Azure, Google Cloud, and Cloudflare — and asks you to confirm the list during setup, so checks are scoped to the services in use rather than every service the provider sells
  • Wider native coverage inside each cloud: more AWS services, deeper Azure service discovery, and Cloudflare account, DNS, and TLS checks
  • Every step in the Setup guide can be skipped, not just the ones marked optional, so a step that does not apply to you stops holding up the chapter it sits in
  • Bulk actions on test lists
  • Linked risks show their risk code, so a risk referenced from a control is identifiable without opening it
  • Search-or-create boxes create what you typed when you press Enter, with a hint showing that they will

Improved

  • Native checks are more accurate across several providers — Azure management MFA coverage is scoped correctly, security contact checks match the current provider API, owner notification roles are validated, and the security and monitoring checks are hardened
  • The AI review is told what Screenata already holds, so it stops asking for evidence that is already in the vault
  • Procedure evidence rolls up by period
  • Scope proposals read as defer or activate, rather than presenting themselves as a new test

Fixed

  • Eight elective controls were marked required and no longer are
  • The Audit chapter of the Setup guide is reachable, and specific to the cycle you are in
  • Cloud service selections are preserved and restored instead of resetting between visits
  • Sessions stay in step between the web app and the browser extension when you sign in or out
  • Evidence lifecycle state agrees between generated evidence and what the interface shows
  • Daily briefing details render in the inbox
  • Recording no longer captures navigation that happened while it was paused
  • Grouped unread counts stay consistent

Week of · 30 updates

New

  • Single sign-on for your organization — SAML and OIDC, with guided setup for your identity provider, while password and social sign-in stay available alongside it
  • A Setup guide that owns the whole audit process, not just onboarding — eleven chapters from connecting systems through the audit, each saying what the auditor is looking for, with skipped steps struck through and restorable, and a link to exactly where each step happens
  • A machine-readable Trust Center API — every Trust Center is also a versioned JSON API, so a customer’s vendor management can pull your documents, controls, subprocessors, and a signed attestation straight into their intake instead of asking over email
  • Revoke a Trust Center access grant at any time, and the access link is shown on approval with a copy button, so it never depends on an email arriving
  • Vendor risk scored from impact and likelihood, with an assessment workbench that shows where every fact came from — a document, a trust page, or a person — and lets you edit it
  • A relational people graph for assets — who holds which device, a custody history when it changes hands, and a default accountable owner for every asset, with licenses folded into the People tab
  • Comments and full editor toolbars on policy documents and recordings, plus review notes you can reply to, resolve, and export, in read mode too
  • Start an empty policy by uploading yours or generating it with Vera, and generation waits until the questionnaire it depends on is answered
  • Bulk actions on resources, including marking them out of scope — scoped-out resources are skipped at collection time and their findings dispositioned, so they stop generating noise
  • Key documents on the auditor dashboard, resolved to the tests behind them with each one’s review status
  • Recording submissions attach to the test they evidence

Improved

  • Test lists show automated rollup progress, and rollups include a representative check’s evidence so you can see what passed, not just that it did
  • Requirement rollups are labelled apart from automated checks, and a linked test’s status is clearer
  • A test’s verdict respects the exceptions on it, reminders go out before an exception expires, and SLAs are no longer raised for tests marked not applicable
  • Audit readiness covers more of the program, and new native checks landed across integrations
  • Questionnaire answers are verified against live scans rather than a stored snapshot
  • Policy acknowledgment reports use one canonical format
  • Compliance roles can be held by more than one person
  • Chat accepts attachment-only messages

Fixed

  • Audit package downloads survive navigating away mid-generation
  • Policy editor autosave no longer loses work, and Edit and Request Approval are hidden while a policy is still generating
  • A policy whose generation job was lost can be recovered, and questionnaire answers are committed before regenerating or closing
  • The scoped policy upload dialog binds the file you chose and drops the redundant slot list
  • Review note actions and policy comment interactions no longer misfire
  • GitHub branch protection remediation is hardened against partial configurations
  • Dashboard and inbox indicators show the right counts
  • Long finding titles stay contained in the dismiss dialog, and formatting is preserved in color popovers
  • The Setup guide no longer offers Start setup on workspaces that already have tests
  • New workspaces reach the onboarding questions exactly once, and those answers scope the test plan, so a SOC 2 program no longer starts with every non-Security control out of scope
  • The Inbox stat card is gone from the auditor cycle dashboard

Week of · 34 updates

New

  • Vera reviews rollup evidence for sufficiency on its own, so a period that falls short is flagged before an auditor sees it
  • The activity log shows the reasoning behind a verdict, not just the verdict itself
  • Tests say whether their evidence is a policy, an automated check, or something a person has to capture, so it is clear what each one needs from you
  • An MDM enrollment report showing which devices are enrolled and which are not
  • Open Attest device rosters sync nightly and carry a freshness deadline, so stale device data is flagged rather than assumed current
  • Open Attest now counts as anti-malware evidence, and the different Defender products are told apart properly
  • Not-applicable tests are hidden by default, with one checkbox to bring them back and lighter badges on every row

Improved

  • Failed evidence reviews keep their five-axis score and are marked advisory, so you can see exactly where the evidence fell short
  • Annual training tests use the training records already in Screenata instead of asking you to upload them again
  • The training program schedule can be edited after it is set
  • Comment and mention emails link straight back to the test they came from
  • SLA warnings arrive batched instead of one message per item
  • Azure onboarding scans are scoped by subscription, so a multi-subscription tenant is covered properly
  • Every evidence route is a link from the empty state, so it is obvious how to supply what is missing
  • Scan coverage is reported as its own finding, so a gap in what was scanned shows up instead of passing quietly

Fixed

  • Rollup periods no longer park waiting on approval — evidence is scored and the period moves on
  • Partial review scores are kept instead of being lost on the next pass
  • A failing rollup shows the window it actually examined instead of a dash
  • Passed rollups still require approval before they count
  • Submitting evidence clears the escalation attached to it
  • Recording actions stay reachable, hidden steps no longer drift, and progress is restored for guidance-only tests
  • Edited recording screenshots submit as evidence, and hidden video is left out of what gets submitted
  • Confirmed fields stay editable during onboarding, and discovered company logos are checked before they are shown
  • GitHub repository security verdicts resolve instead of hanging unresolved
  • Framework cards count tests the same way the framework page does
  • Requirement citations are scoped to the framework you are looking at
  • Setup progress counts framework requirements rather than the controls underneath them
  • Baseline program depth covers the first engagement for every framework
  • Chat send and loading no longer jump around, and forms wait for the whole input before submitting
  • Leaving a test view shows one consistent loading state
  • Bulk edit on people resets properly between uses
  • Risk exports from Vera use the standard CSV format
  • Slack no longer runs admin checks its API does not support, so those stop showing as failures
  • Compliance counts on Open Attest reconcile with the rest of the program

Week of · 27 updates

New

  • Auditor portal request queue — auditors raise information requests, you answer them, and the whole exchange stays in one place instead of an email thread
  • Decide an auditor's proposed change straight from your inbox, without opening the request
  • Auditors can see the run history behind an automated check: when it last ran and what it returned
  • Per-engagement scope review — the auditor confirms what's in scope inside their own workflow, and the decision is recorded
  • Choose Baseline or Enterprise-ready program depth during onboarding, with the recommended option and the reason for it shown before setup runs
  • Filter your tests by program depth, and see the depth badge on any test, so it's clear why a test is or isn't in your program
  • Agent-first onboarding — hand setup to Claude Code or Codex from the first screen, with a manual path if you'd rather do it yourself
  • Search the vendor catalog while extending coverage during onboarding
  • Optional Slack step in onboarding, with a preview of the channel Vera will post to
  • Assign policies and training to groups of people instead of one person at a time
  • Import your vendor list from a CSV or Excel file
  • Axiom compliance checks
  • Okta access evidence lands in canonical types, with new coverage checks behind it

Improved

  • AI evidence review now scores the five dimensions an auditor actually weighs instead of four that all moved together
  • Curated auditor guidance appears in the test, in its scoring, and in what Vera tells you
  • Inbox digest emails are scannable and labeled by organization, with a preview of each item and a count of the rest
  • Approval notifications link straight to the thing waiting on you
  • SOC 2 Type II is the recommended audit type, and the onboarding wizard resumes where you left off
  • A period rollup result now shows on every check that covers it
  • Clearer evidence panel on a test for automated and approved results, and an easier risk assessment to read and edit

Fixed

  • Approved policy claims now show on the tests that prove them
  • Filtering by framework returns the right tests instead of quietly matching the wrong ones
  • Microsoft 365 sign-in for delegated permissions no longer fails partway through connecting
  • Okta coverage now includes MFA enforcement and the complete user roster
  • The CLI installs cleanly again, and screenata upgrade updates it in place
  • Imported records keep their ownership and their rounding instead of being overwritten by setup
  • Restored native evidence checks that had gone missing

Week of · 16 updates

New

  • ISO 42001 readiness — get audit-ready for the AI management standard alongside SOC 2, HIPAA, and ISO 27001, with its own artifacts and AI governance questionnaire
  • AI system inventory — register the AI systems you run, break them into components, and see the tests covering each
  • EU AI Act Article 50 transparency evidence, offered only on the AI systems it actually applies to
  • Supabase connector — connect over OAuth and scope scans to the projects you choose
  • Policy commitments become tracked claims — every hard commitment in your policy prose links to the test that proves it
  • Tiered policy approval — Vera blocks a statement that isn't true of your company and offers the rest as suggestions
  • Audit package readiness — see what an auditor would find missing before you submit

Improved

  • Recommended evidence is consolidated per test, including documents Screenata generates for you, with the automated check or person behind each result
  • Reminders and escalations arrive as one batched digest instead of a message per item
  • Test list filters stay in the URL and carry through to the tests you open, and long dropdowns are searchable
  • A failing test or period rollup hands off to a person instead of stalling

Fixed

  • HIPAA Business Associate programs no longer inherit requirements that only apply to Covered Entities
  • Audit cycles edit the framework you actually selected instead of defaulting to SOC 2
  • Editing a policy awaiting review now opens for editing and withdraws the stale approval request
  • Controls are titled by the requirement they satisfy, and retired tests stay out of your test list
  • A check covering several connected accounts runs once and records its result on every test it proves

Week of · 16 updates

New

  • ISO 27001 readiness tracking — cover the ISMS clauses and the Annex A themes a certification body samples
  • Requirement-level control mapping — every control is labeled by the framework requirement it satisfies, with coverage gaps shown per period
  • Custom evidence requirements — define the exact evidence a control needs, and tests scope themselves to what you asked for
  • Sentence-level policy comments — highlight a single sentence and comment on it instead of the whole section
  • Reusable questionnaire answers — saved answers carry forward as durable commitments, written as prose instead of stitched-together claims
  • Control status in plain words — read each control's state from the row itself instead of decoding a colored dot
  • Employee account linking — connect the accounts Screenata finds in your integrations to the right employee profile

Improved

  • Review notifications open inline in your inbox, with a direct link to the test in question
  • Guided setup tracks Slack and Trust Center as their own steps, and no longer opens on sample data
  • Test and task counts now agree across the dashboard, the board, and the test list
  • Vendor discovery pulls candidates from every connected integration, not just a handful

Fixed

  • HIPAA tests are no longer judged against SOC 2 criteria you never selected
  • ISO 27001 audit cycles load and stay editable instead of failing on an unrecognized audit type
  • Re-scoping or unlinking a control now reaches its tests and stays that way
  • Every test gets its own code and title instead of repeating the first one
  • Google Workspace and GitHub checks verify against live APIs, and skipped scans no longer read as failures

Week of · 12 updates

New

  • Global search — find any test, task, or work item by name or code from a new sidebar search box and a ⌘K command palette
  • Grouped list view — organize tasks and registers into collapsible groups you can scan at a glance
  • "Provides evidence for" links on tasks — jump straight from a task to the test it satisfies
  • Quieter compliance board — auto-generated scanner findings stay off the board until you choose to triage them

Improved

  • Vera's escalation emails now deep-link to the exact test or task that needs your attention
  • Stale "Vera needs your help" prompts auto-dismiss once the underlying work is resolved
  • Task descriptions expand to fit their full content instead of clipping

Fixed

  • Signature attestations now persist reliably
  • Activity logs show assignee and role changes accurately and no longer merge distinct events
  • One person now shows a single consistent avatar across every name-format variant
  • Uploaded intake attachments keep their original source and provenance
  • Group inventory registration now completes without stalling

Week of · 16 updates

New

  • Self-service compliance requests — a unified intake for compliance work, with in-app and email requests that Vera routes to the right procedure automatically
  • Live request activity feed — follow any request in real time with a causally-ordered timeline of steps, evidence, decisions, and comments
  • Agentic compliance operations — Vera triages incoming work, auto-executes high-confidence steps, posts her outcome report to the test thread, and hands anything uncertain to a human for approval
  • Asset and device register — track device lifecycle, warranty, and MDM sync in one place, with employee software licenses and per-device history unified into the asset timeline
  • Custom form fields — add Choice (dropdown) and Signature field types to your procedures and human steps
  • Auditor Center rollups — period-of-time evidence coverage, sampled-run details, live check-health badges on test cards, and searchable run history for audit sampling

Improved

  • Reorganized Screenata sidebar — grouped into Program, Vault, Registers, Trust, and Configure
  • Instant procedure start — begin a procedure immediately while policy grounding finishes in the background
  • Broader contributor access — contributors can now act on questionnaires, assets, offboarding, and risk seeding without hitting permission walls
  • Workspace-scoped GitHub — connect and disconnect GitHub per workspace, with multi-account support
  • Bulk evidence export — download any selection of documents as a single zip

Fixed

  • Cancelled procedure runs no longer leave phantom tasks in your inbox or My Tasks
  • Board columns now render cards correctly after a previously-empty column re-populates
  • The public Trust Center now loads on your custom-domain root without an auth prompt
  • Vera chat handles empty replies gracefully instead of stalling
  • Vera's comments no longer show double-escaped whitespace

Week of · 10 updates

New

  • Trust center on your own domain, host your public trust page on a custom domain with guided DNS verification
  • Redesigned public trust page, dark and light themes, brand-color theming, and configurable hero backgrounds
  • NDA-gated document access, require a signed NDA with an expiry date before sharing trust-center documents
  • 90+ new automated checks across AWS, GCP, Azure, and SaaS identity providers

Improved

  • Review panel, a cleaner layout with intent-clear actions to mark not applicable, remove, assign an owner, or route for approval
  • Trust-center admin, frameworks visibility controls, request filters, and a live public-URL preview
  • Vera grounds drafted answers in your approved policy passages only

Fixed

  • Approval cards now name the specific check or action you're approving
  • Viewer role, read-only access is enforced consistently across every surface
  • Setup guide hides itself once onboarding is complete

Week of · 14 updates

New

  • Guided "Get audit-ready" setup, a floating setup guide, coach-marks across compliance surfaces, and Vera starter suggestions on every onboarding step
  • Ask Vera everywhere, starter prompt pills under the composer and a chat rail you can open from any compliance surface
  • Audit command center, a dedicated audit page with SOC 2 Type II period-coverage tracking, plus auditor first and last names captured at invite time
  • Vera-generated SOC 2 bridge letter, draft a bridge letter for your SOC 2 audit without leaving the platform
  • Personnel and manager management, a structured manager picker that auto-links on sync and import, a background-check column, and personnel sync across your identity providers
  • Continuous-monitoring lens, surface the latest automated check verdict directly on each control test

Improved

  • Simplified cloud setup, a cleaner wizard for connecting your cloud providers
  • Design system refresh, softer squircle corners, refined focus rings, and clearer elevation across the app
  • Policy-set approvals, approvals are now coverage-aware, so you only sign off on what actually needs it
  • Evidence guidance, recommendations no longer hinge on test type and evidence-slot instructions are consolidated in one place

Fixed

  • Browser capture, grab evidence by screenshotting any web-app URL
  • Document evidence, no longer fails on tests that don't have a template
  • Risk register layout, widened the ID column so warning icons no longer overlap the rating badge
  • Navigation, the Controls sidebar item now stays active while you're viewing tests

Week of · 14 updates

New

  • Employee onboarding and offboarding, automate joiner and leaver workflows with manager approvals and access tracking
  • Human steps in Slack and email, approve, complete, or upload evidence for Vera's workflow steps without leaving your inbox
  • Ask Vera in the portal, grounded answers about your compliance posture, drawn from your own policies and evidence
  • Slack agent escalations, act on Vera's compliance alerts with one click, right in Slack
  • Email Vera and browser-capture settings, manage how you reach Vera by email and capture evidence from any web app

Improved

  • Policy governance, override approvals and import your entire policy library from a single page
  • Tasks, a unified board and list view for everything assigned to you, now defaulting to a board
  • Document management, upload, stash, and batch-assess evidence documents in one workflow
  • Faster program setup with parallelized test compilation

Fixed

  • MFA enrollment, now shows a clear error message instead of a generic network failure
  • Policy coverage counts, now reflect shared and master policies accurately
  • Completion ratios, no longer capped by covered policies or not-applicable controls
  • Control lists, de-duplicated across overlapping frameworks
  • Test editing, the Edit Test dialog now updates the evidence instructions directly

Week of · 15 updates

New

  • Vendor risk management, discover vendors from integrations, tier them, and let Vera draft assessments
  • Continuous evidence enforcement, track freshness with renewal filters and automated integration-to-evidence lifecycles
  • Compliance posture dashboard, monitor workspace-wide readiness with actionable cards and Vera-generated risk registers
  • Policy governance, set per-policy review cadences and manage bulk approval requests in a unified inventory
  • HRIS and IdP sync, automate personnel directory management and provider-agnostic background checks
  • Microsoft Teams and M365 compliance, dedicated provider support for Teams, SharePoint, and Entra ID

Improved

  • Optimized cloud connection, improved background processing speeds when connecting or disconnecting cloud providers
  • Framework mapping, unified HIPAA controls for streamlined cross-framework evidence collection
  • Policy management UI, split policy imports into tabs with smarter classification and richer review dialogs
  • Role-based access control, restricted policy edits and vendor assessment writes to authorized manager roles

Fixed

  • N/A test accuracy, corrected display logic and applicability reasons for non-applicable control tests
  • Identity resolution, resolved duplicate user account creation during OAuth login and browser extension authentication
  • Role stability, fixed role assignment persistence by syncing on stable identifiers rather than editable names
  • Questionnaire parsing, improved support for multi-sheet workbook uploads and draft auto-population
  • Audit cycle management, fixed date-shift logic and handled null periods in auditor invitation emails

Week of · 16 updates

New

  • Test-first onboarding, replace questionnaires with action-oriented steps to accelerate audit readiness
  • Evidence classification, Vera suggests tests for uploaded documents and saves them as classified evidence
  • Two-stage request lifecycle, manage evidence requests through distinct respond and resolve stages
  • Audit-cycle management, track frameworks, vault uploads, and readiness analytics in a unified view
  • Organization-wide MFA enforcement, manage and enforce two-factor authentication across all user accounts
  • Policy checklist, upload and track required policies with support for bulk imports and drag-and-drop
  • Open Requests dashboard, view all pending requests and linked-document evidence in a dedicated view

Improved

  • Automated test status, Vera automatically marks tests as N/A when no in-scope resources are found
  • Enhanced Microsoft 365 monitoring, replaced manual attestation stubs with automated Graph API checks
  • Bulk actions, manage controls and policies efficiently with multiselect and bulk approval workflows
  • Responsive interface, properties panel now collapses into a floating tab for better use on narrow screens

Fixed

  • Test regression handling, tests now revert to a failed state if a re-run confirms a new failure
  • Evidence integrity, Vera now invalidates and re-grades reviews when the underlying evidence files change
  • Notification cleanup, stopped duplicate Open Requests from appearing as auditor notifications
  • Upload reliability, blocked evidence submissions when files are unreachable to prevent data gaps
  • Login security, hardened workspace-scoped routes and validated redirect URIs to prevent cross-org requests

Week of · 16 updates

New

  • Frameworks dashboard, navigate controls and tests grouped by specific regulatory criteria
  • Automated test skipping, Vera identifies and skips non-applicable tests to reduce manual escalations
  • HIPAA Security Rule expansion, six additional implementation specifications added to the compliance catalog
  • Readiness questionnaire overhaul, inline integration setup and direct access to Vera for guidance
  • Evidence management, attach evidence to any category and find tests by description
  • Audit Cycles, track historical and active audits grouped by year with dedicated cycle views
  • Discrete evidence tracking, specific slots for network diagrams and performance evaluations

Improved

  • Vera reasoning transparency, new visual indicators show Vera's thinking process and skill usage
  • Slack and email agent reliability, improved skill reachability and cross-turn memory for remote interactions
  • Test activity feed, paginated results with noise reduction for automated check logs
  • Progress tracking, section counts now reflect sub-questions for more accurate readiness reporting

Fixed

  • Evidence-driven test status, test results now trigger from evidence submission for higher accuracy
  • Chat evidence attachment, resolved issues with test ID memory and link sanitization in Vera
  • Integration stability, fixed OAuth connection lifecycles and API key credential modal triggers
  • Control tree reliability, eliminated duplicate controls and flickering when switching between frameworks
  • Document search, improved relevance ranking to match any token within policy searches

Week of · 15 updates

New

  • Vera claim verification, Vera verifies compliance claims and recommends supporting evidence from your integrations
  • Continuous monitoring, daily API-driven checks detect configuration drift across your security stack
  • Audit cycle management, track progress and evidence submissions across multiple frameworks in one view
  • On-demand evidence review, Vera performs instant quality reviews on uploaded evidence artifacts
  • SOC 2 readiness expansion, 14 new auditor-requested tests for SOC 2 Type I readiness
  • Policy-to-message attachments, attach existing vault documents and policies directly to chat threads with Vera
  • Deep-linked onboarding, resume setup at any stage with persistent wizard state and direct URLs

Improved

  • Performance virtualization, faster loading for large task boards, test lists, and control trees
  • Composer responsiveness, reduced input lag by deferring non-critical card rendering in the chat interface
  • Snapshot coalescing, cleaner readiness history by grouping gap-detection updates into single snapshots

Fixed

  • Evidence locking, vault documents linked to submitted evidence are now correctly locked from modification
  • M365 provider resolution, corrected display titles for Microsoft 365 integration checks
  • Inbox layout, fixed property panel overflow issues within the inbox view
  • Evidence submission flow, resolved errors blocking the end-to-end evidence approval and submission process
  • Duplicate tool calls, prevented duplicate assistant messages to ensure stable AI agent responses

Keep up

Want these features working in your stack?

Vera, your AI compliance agent, puts every one of these to work, scanning your infrastructure, drafting policies, and collecting evidence continuously.