Screenata

Pricing

Startup pricing is published. Complex programs are scoped.

The Startup program is $5,988/year per framework for a standard audit scope. Scale & Enterprise is custom-priced for complex environments, larger evidence populations, multiple entities, and tailored implementation requirements.

Startup is typically for teams up to 50 employees and one legal entity. Program complexity—not headcount alone—determines the right plan. Teams of five or fewer can contact us for micro-startup pricing.

Startup

$5,988/ year per framework

$499/mo · billed annually

For a standard startup audit scope—typically up to 50 employees, one legal entity, and one framework.

Five people or fewer? Micro-startup pricing

Included in Startup

  • All 16 modules, with no per-module or per-seat pricing
  • Infrastructure-grounded policies with overpromise detection
  • All 8 SOC 2 Type I deliverables
  • 60+ native integrations and 650+ automated evidence checks
  • Daily, weekly, quarterly, and annual agent operations
  • Slack, email, CLI, GitHub, and MCP surfaces
  • Cryptographically signed, exportable evidence packs
  • Works with any auditor, not a firm-specific workflow

What you get

16 modules. One price.

Every core module below is included in the Startup program for every seat on your team. Scale & Enterprise uses the same platform, with SAML SSO and pricing scoped to the complexity of your compliance program.
Module
What it covers
Key capabilities
Price

Compliance program

The audit-ready core: what you must prove, what you wrote down, and what proves it.

An auto-scoped control matrix, right-sized for your team, with tests as the unit of work.
  • Control matrix generated from your systems
  • N/A justifications recorded, not guessed
  • Cross-framework mapping through a canonical control catalog
  • Per-framework readiness scored daily
Included
Policies written from infrastructure scans instead of templates with blanks to fill.
  • Generated from real GitHub, cloud, and IdP configuration
  • Overpromise checker flags claims you can't prove
  • Every sentence traced: claim → test → evidence
  • Versioning, review, and approval workflow
Included
Collection, freshness tracking, and cryptographically signed evidence packs.
  • 70% of evidence collected fully automatically
  • Freshness lifecycle: fresh → stale at 90d → expired at 120d
  • SHA-256 hashes, RSA/ECDSA signatures, RFC 3161 timestamps
  • Bring-your-own-key signing, verifiable without a Screenata account
Included
Compliance procedures that are readable documentation and executable tests at once.
  • Inline action pills call live integration checks
  • Auditors read the same document the agent runs
  • No drift between what's documented and what executes
  • Every run captured as evidence
Included

Registers

The inventories every auditor asks for, built from your systems rather than a spreadsheet.

A risk register with scoring, treatment plans, and a scheduled annual refresh.
  • Risks linked to controls and policy claims
  • Treatment plans with owners and due dates
  • Risk acceptance always requires human approval
  • Annual risk assessment refresh runs on schedule
Included
Third-party risk built from your codebase, not from a form somebody forgot to fill in.
  • Vendors discovered from package.json, Terraform, and env vars
  • Auto-researched against a 500+ vendor catalog
  • Risk tiering with review cadences
  • HIPAA BAA tracking, separation of duties on assessments
Included
One asset register across clouds, SaaS, repos, and data stores.
  • Synced from GitHub, AWS, Azure, GCP, and Cloudflare
  • Discovered from infrastructure-as-code
  • Curated by you where discovery can't reach
  • Satisfies SOC 2, HIPAA, ISO 27001, PCI DSS, and NIST 800-53 at once
Included
Personnel compliance without chasing anyone in Slack for the fourth time.
  • Policy acknowledgments that track themselves
  • AI-generated security awareness training with quizzes
  • Device posture tracking
  • CSV onboarding auto-assigns required training
Included

Trust & audit

The buyer-facing and auditor-facing surfaces. Sold as paid add-ons elsewhere, included here.

A public, branded security page published straight from your compliance program.
  • Custom domain, so it lives on trust.yourcompany.com
  • Badges, control posture, subprocessors, and a changelog
  • Gated document downloads behind approval and email verification
  • Every download logged as an access record
  • Answers the security email before it's sent
Included
Buyer questionnaires answered from approved ground truth, with citations.
  • Excel upload: drop in the buyer's .xlsx workbook
  • Chrome extension answers web portals like OneTrust in place
  • Answer library grows from every answer you approve
  • Grounded only in approved policies and evidence, always cited
  • Fail-closed: leaves a question blank rather than guessing
  • Exports back into the buyer's original file
Included
A scoped workspace for your auditor instead of a ZIP file over email.
  • Live evidence review with comment threads on artifacts
  • Per-engagement access grants, fully logged
  • Readiness preflight gate before fieldwork starts
  • Signed audit package frozen at completion
Included

Automation & surfaces

The part that actually does the work, in the tools your team already has open.

An autonomous compliance officer, context-aware on every page, not a chatbot in a sidebar.
  • Knows what you're looking at, no pasting IDs
  • 27+ compliance tools across the whole program
  • Permission tiers: autonomous, notify, approval-required
  • Every tool call logged, which is itself AI governance evidence
Included
Scheduled agents that run the program on a cadence instead of a to-do list.
  • 06:00 evidence freshness, 06:15 readiness, 06:30 Slack briefing
  • Weekly cloud and repository scans
  • Quarterly access reviews, annual risk refresh
  • Remediation orchestration into Jira, Linear, and GitHub Issues
Included
Native provider checks that produce audit-grade evidence, not shallow connection points.
  • 60+ native integrations
  • 650+ automated evidence checks
  • AWS, Azure, Kubernetes, M365, GCP, GitHub, Okta, and more
  • Read-only by construction, credentials never touch our database
Included
Slack, email, CLI, GitHub, and MCP, all hitting one API with one context.
  • Slack briefings, DM evidence requests, file drops auto-classified
  • {org-slug}@screenata.com with sender-aware intent routing
  • screenata CLI with an audit preflight gate for CI
  • GitHub PR compliance review, MCP server for Claude Code and Cursor
Included
The long tail: consoles no API can reach, captured as audit-grade evidence.
  • Recorder extension captures workflows with DOM snapshots
  • AI coach guides collection in real time
  • Vision model scores quality across 4 dimensions before submission
  • Free desktop recorder for macOS and Windows
Included
All 16 modules
One compliance program, one evidence set.
No per-seat fee. Add a framework, keep the same modules.
Startup: $5,988/yr

Startup pricing is $5,988/year ($499/mo) per framework, not per module or per seat. It is designed for a standard audit scope, typically for teams up to 50 employees and one legal entity. Each additional framework is priced lower than the first, because it shares the same modules and the same evidence set through a canonical control catalog, so one MFA scan satisfies SOC 2 CC6.1 and HIPAA §164.312(d) at once. Machine-readable version: pricing.md.

The math

Year one of SOC 2, priced honestly.

A first Type II means an auditor, a year of platform licence, someone to operate it, and your own hours through the observation window. Three ways to buy the same year, with own time priced at $150/hr so it counts.
Line item
Platform + vCISO
Platform + DIY
Screenata
Why
Auditor (Type II)
$7–15K
$7–15K
$7–15K
Startup-focused CPA firm. Identical in every column; the auditor stays independent.
Platform (1 yr)
$12–25K
$12–25K
$6K
Vanta or Drata: Vendr transaction data, under 50 employees, one framework. Screenata: $5,988/yr, every module.
Consultant / vCISO (12 mo)
$5–120K
$0
$0
From a $5K readiness project (Workstreet's published floor) to a $10K/mo retainer for the year. DIY and Screenata: nobody on payroll.
Own time (12 mo × $150/hr)
$18K
~120 hrs
$30K
~200 hrs
$9–12K
60–80 hrs
Readiness concentrates in one or two months, then a few hours a month through the observation window. Conservative: Vanta's own survey of teams running its platform reports about 10 hours a week. With Screenata your part is attestations and approvals, then the same upkeep.
Total
$42–178K
$49–70K
$22–33K
Auditor identical in every column

Multi-framework note: SOC 2 + HIPAA share one evidence set via a canonical control catalog. Competitors charge $3–10K per additional framework with separate evidence sets.

Pricing FAQ

What founders ask before buying.

More questions? Browse the resources or book a walkthrough.
What does $5,988/year include?

The Startup program includes one framework, all 16 core modules, all integrations, all agent operations, and policy generation through the auditor-ready evidence package. That's $499/month, billed annually. It is designed for a standard startup audit scope, typically up to 50 employees and one legal entity. Eligibility also reflects environment complexity, evidence populations, and implementation requirements—not headcount alone.

Are any modules sold separately as add-ons?

No. All 16 core modules are in the Startup program, including the three that competitors most often charge extra for: Trust Center, vendor management (third-party risk), and the AI security questionnaire assistant. There are no per-module or per-seat fees. Scale & Enterprise adds organization capabilities such as SAML SSO and a tailored implementation, rather than withholding core compliance modules.

When do we need Scale & Enterprise?

Scale & Enterprise is for programs with complex environments, larger evidence populations, multiple entities or business units, custom integration or control requirements, or dedicated implementation needs. It includes SAML SSO. Pricing is scoped to the program, not determined by employee count alone.

Is there pricing for teams of five or fewer?

Yes. Teams of five or fewer can contact us for micro-startup pricing. It is the same product with every module included and your own independent auditor, priced for a smaller scope and quoted by email rather than published. See the micro-startup page for eligibility and how to ask.

What happens to the modules when we add a second framework?

You keep all of them, and they share one evidence set. Frameworks are mapped through a canonical control catalog, so a single MFA scan satisfies SOC 2 CC6.1 and HIPAA §164.312(d) at the same time. You are not rebuilding a second control matrix, a second vendor register, or a second policy set. Competitors typically charge $3–10K per additional framework and maintain separate evidence.

Does the price include the audit itself?

No, and that's deliberate. AICPA independence rules prevent the firm that prepares your compliance program from also auditing it. You pick the auditor (we work with any), typically $5–15K for a SOC 2 Type I from an independent boutique firm — peer-reviewed firms quoted us as low as $3K in September 2026. Do the all-in math: $5,988 for the platform plus your auditor is roughly $11–21K, a fraction of the $60–180K traditional stack, and the report comes from an auditor with no stake in the platform that prepared you. Bundles that fold the audit into the platform price can't say that.

How does this compare to Vanta or Drata?

Vanta and Drata are quote-based; Vendr's transaction data puts companies under 50 employees at $12–25K/year for one framework, before modules and headcount, before the person-hours it takes to actually operate them ($8–15K/month if you outsource that work). Screenata is $5,988/year per framework ($499/mo) and operates itself: scheduled scans, evidence collection, Slack briefings, and policy generation run as agent operations, not checklists waiting for a human.

How long until we're audit-ready?

4–6 weeks from connecting your systems to a complete Type I package, policies, risk assessment, system description, network diagram, org chart, control matrix, vulnerability review, and oversight minutes. Founder effort is measured in hours, not weeks.

What happens to our evidence if we leave?

It leaves with you. Your evidence packs are signed and exportable, verifiable outside Screenata with the free verify CLI, so your compliance program is portable by design rather than locked to our platform.

Deal waiting on SOC 2?

Your next enterprise deal is waiting on SOC 2.

Get audit-ready in 4–6 weeks. Hours of your time, not months.