Screenata

Manifesto

Why we’re building a new compliance platform.

Evidence should be a byproduct of the work, not a project after it.

Tao Huang · Founder, Screenata ·

Somewhere right now a founder is losing an enterprise deal because a security questionnaire arrived and nobody on the team has ever read a SOC 2 report. The product is fine. The security is probably fine. What’s missing is proof, in the specific shape an auditor accepts, and producing that proof has become an industry that charges $60,000 to $180,000 a year and still leaves the founder doing most of the work at midnight.

We think that industry is built on a mistake, and we’re building Screenata to correct it.

The mistake: tracking the work instead of doing it

Compliance software has gone through generations, and the honest way to tell them apart is to ask one question. Who does the work?

The first generation was a spreadsheet. You did the work, and you remembered where the evidence went.

The second generation was the dashboard. You still did the work, but now the software told you what was missing. This was genuine progress, and it’s also where the industry stopped. The dashboard business model is a checklist with 200 empty boxes, sold as automation, renewed annually. If you have a compliance team, a dashboard is a reasonable buy. If you are a 30-person company where “the compliance team” is the CTO, a list of what’s missing is not help. It’s homework.

The third generation added AI. A model drafts your policy, suggests your risk register, answers your questions. You still do the work, and now you also check the AI. Bolting a chat window onto a dashboard changes who types, not who does the work.

We’re building the fourth generation: an agent that owns the work item, does it, and can prove it did it right.

AI made compliance’s trust problem worse before it made anything better

We should say the uncomfortable part out loud. “AI compliance” has already burned people. Earlier this year one AI compliance startup was found to have produced 493 of its 494 SOC 2 reports from identical boilerplate, conclusions written before evidence existed. The market’s takeaway was correct: when generating text becomes free, text stops being proof.

Most of the industry responded by adding more AI-generated text.

Our response is the opposite. If an agent is going to do compliance work, every action it takes has to be more inspectable than a human’s, not less. Not “trust our AI.” Trace our AI.

What we believe

The work should get done, not tracked. Vera, our agent, runs the tests in your control matrix, DMs the person who holds the evidence, reminds them, escalates when they go quiet, ingests the file they finally send, and files it against the right control. A dashboard would have shown you a red row. That difference is the entire company.

Policies should describe what you actually do. The number one reason small companies fail audits is the gap between what the policy claims and what the company does. So we don’t start from templates and we don’t let a model freestyle your control language. Vera scans your real infrastructure, GitHub, AWS, Okta, and pre-fills a questionnaire. You attest: confirm what she found or correct it. The policy is then composed deterministically from your attestations. Same attestation, same sentence, every time. Your auditor can re-derive the policy from the questionnaire. There is no creative writing in your control language.

Every claim should trace to proof. In Screenata, every paragraph in a policy links to a claim, every claim links to a test, every test produces an evidence artifact, and every artifact is signed and timestamped. Ask us to show one action the agent took and trace it end to end. That demo is our standard, and we think it should be the standard you hold every vendor to, including us.

We sell the platform, never the audit. Some vendors bundle the software, the advisor, and the auditor into one purchase. Convenient, and also the vendor grading its own homework. We do not sell audits or take referral fees from auditors, so the firm you choose is your decision. You pick your auditor; we build the portal they work in.

An agent that admits what it can’t do is worth more than one that pretends. Vera escalates. When a test needs human judgment, she says so and waits. We think honest escalation is the feature that separates an agent you can put in front of an auditor from a chatbot you have to apologize for. Every action Vera takes runs under her own named account, badged “Vera (AI)” in the audit trail too, and lands in an event log your auditor can read. The auditor accepts the output, not your AI.

Compliance should live where your work lives. Slack and Teams briefings, a CLI, evidence forwarded by email, review comments on your PRs. The dashboard exists, but if you’re visiting it daily, we’ve failed.

Where this goes: the work should produce the evidence

Everything above still treats evidence as something to fetch. Faster, by an agent who owns the job, but fetched after the fact. We think the endpoint is different. Run the work itself, the access request, the offboarding, the vendor review, as a governed procedure, wherever your team already works, and the record is produced at the moment of the act. Nothing to go find, because nothing was ever lost.

Collecting evidence is archaeology. Recording it isn’t. The procedure engine that runs work this way ships today; the layer that lets an auditor sample those runs directly is still being built, and we’ll keep saying so until it isn’t.

Why now

Three things converged. The incumbents priced themselves into the mid-market and can’t come back down without breaking their own business. Auditor independence rules mean the firms that audit you are permanently barred from doing your prep, so the gap is structural. And agents crossed the line from drafting text to owning work, right as the boilerplate scandal made unverifiable AI claims worthless. The opening is exactly the shape of what we’ve built: an agent that does the work, priced for the company that has no compliance team, with proof a skeptic can check.

Where we are

Screenata runs 650+ automated compliance checks across your stack, covers SOC 2, HIPAA, and ISO 27001 through a shared NIST 800-53 backbone so your second framework reuses the first one’s evidence, and collects about 70% of evidence with no human in the loop. It costs $499 a month for a company of up to 50 people; additional frameworks cost less, because the evidence carries over. We ran our own SOC 2 Type I through it and passed with an unqualified opinion, zero exceptions.

We are early, and plenty is still human-gated on purpose. But the direction is not in doubt. Compliance was never supposed to be a profession of screenshot-taking. It was supposed to be proof that you run your company the way you say you do. Software can finally carry that, do the work, and show its receipts.

That’s what we’re building. Come inspect it.

Tao Huang, Founder, Screenata

Come inspect it

Pick one action. Trace it end to end.

Connect GitHub and cloud read-only. Vera runs against your real systems, and every action she takes traces to a claim, a test, and a signed artifact you can verify without an account.

Read the security architecture