For micro-startups · 1–5 people
There’s nobody else to do the work. That’s the job Vera does.
A customer’s security review asked for SOC 2, and at your size the person who has to produce it is you. Screenata is the same product larger teams run, every module included and your own independent auditor, on a micro-startup rung of the same pricing ladder. We quote it by email.
Reply within one business day · same number for every team at this size
What is the same
Not a lite tier. The same program, one rung down.
Same product, every module
Policies composed from your attestations, risk and vendor registers, trust center, the questionnaire assistant, procedures, the evidence vault. Nothing is withheld at this size, and there is no per-seat or per-module fee.
Same auditor independence
You pick the CPA firm. We do not sell audits or take referral fees from auditors, so the firm you choose is your decision, and the evidence pack you hand them is signed and verifiable outside Screenata.
Same ladder, one rung down
Startup pricing is $5,988/year per framework ($499/mo) for a standard scope, typically up to 50 employees. Scope scales with headcount in both directions: teams of five or fewer are priced on the same ladder, and we quote that rung by email.
Who it's for
Five people or fewer, counted the same way your auditor counts.
- Five people or fewer, counted as logins in your identity provider (Google Workspace, Microsoft 365, Okta). Contractors with a login count.
- One framework to start, usually SOC 2. A second framework reuses the first one's evidence and is priced lower.
- Billed annually. Micro-startup pricing is a yearly program, not a monthly plan.
- Grow past five and you move to Startup pricing at your next renewal. Nothing about the program changes.
What a first SOC 2 costs at this size
Three lines. The auditor is usually the largest.
For the full breakdown of what an audit costs and where the money goes, see what a SOC 2 audit actually costs.
What you actually do
Approve, answer, and hand over. Vera does the rest.
Answer the readiness questionnaire once
Vera scans GitHub, your cloud, and your identity provider first, then asks only what the scan can't see. Your answers become the policies, sentence by sentence, and every sentence is traceable back to the answer that produced it.
Approve, don't assemble
Automated checks run against the same sources a dashboard reads. What they can't reach, Vera walks you through capturing in your own browser or desktop and files it against the control. You review; you don't hunt.
Hand the auditor a signed pack
One evidence pack, a SHA-256 manifest per file, a signature and a timestamp. Your auditor can verify it from a terminal. No shared drive of screenshots named IMG_4392.png.
Micro-startup FAQ
The questions every small team asks.
Can a three-person company actually get SOC 2?
Yes. The report attests to your controls, not your headcount. A three-person company we spoke with did its entire SOC 2 with one person and twenty to forty hand-taken screenshots; the audit was real, the work was the problem. Screenata exists to take that work off the one person who has it.
Is micro-startup pricing a stripped-down version of Screenata?
No. It is the same product with every module included, the same integrations and automated checks, the same signed evidence packs, and the same choice of auditor. The only difference is the rung of the headcount ladder you sit on.
Why isn't the number on this page?
Below five people we quote the rung rather than publish it. It is a fixed price, the same for every team at this size, and you will have it within one business day of emailing us. Startup pricing for teams up to 50 is published on the pricing page.
Is this a discount?
No. Screenata prices by scope, and scope scales with headcount: devices, access reviews, training records, evidence volume. A five-person company has less of all of it than a fifty-person company, so it sits one rung lower on the same ladder. Nothing is being knocked off a higher number.
What happens when we hire our sixth person?
You move to Startup pricing at your next renewal. Your policies, evidence, controls, and auditor relationship carry over unchanged; the program does not restart.
Do we need a penetration test?
SOC 2 does not require one. Some enterprise contracts and security questionnaires do, and some specify a manual test rather than an automated scan. Check the contract that is asking for SOC 2 before buying one.
Which auditor should we use?
Your choice, and we mean that literally: we do not sell audits or take referral fees from auditors. Look for a CPA firm with a published peer review that works with startups on a compliance platform; several quote a Type I at $5,000 to $10,000.
Micro-startup pricing
Three lines in an email. One number back.
Your company URL, your headcount, and the deal that is asking for SOC 2. We reply within one business day with the micro-startup rung, and it is the same number for every team at this size.