Pricing
Startup pricing is published. Complex programs are scoped.
The Startup program is $5,988/year per framework for a standard audit scope. Scale & Enterprise is custom-priced for complex environments, larger evidence populations, multiple entities, and tailored implementation requirements.
Startup is typically for teams up to 50 employees and one legal entity. Program complexity—not headcount alone—determines the right plan. Teams of five or fewer can contact us for micro-startup pricing.
Startup
$499/mo · billed annually
For a standard startup audit scope—typically up to 50 employees, one legal entity, and one framework.
Included in Startup
- All 16 modules, with no per-module or per-seat pricing
- Infrastructure-grounded policies with overpromise detection
- All 8 SOC 2 Type I deliverables
- 60+ native integrations and 650+ automated evidence checks
- Daily, weekly, quarterly, and annual agent operations
- Slack, email, CLI, GitHub, and MCP surfaces
- Cryptographically signed, exportable evidence packs
- Works with any auditor, not a firm-specific workflow
What you get
16 modules. One price.
Compliance program
The audit-ready core: what you must prove, what you wrote down, and what proves it.
- Control matrix generated from your systems
- N/A justifications recorded, not guessed
- Cross-framework mapping through a canonical control catalog
- Per-framework readiness scored daily
- Generated from real GitHub, cloud, and IdP configuration
- Overpromise checker flags claims you can't prove
- Every sentence traced: claim → test → evidence
- Versioning, review, and approval workflow
- 70% of evidence collected fully automatically
- Freshness lifecycle: fresh → stale at 90d → expired at 120d
- SHA-256 hashes, RSA/ECDSA signatures, RFC 3161 timestamps
- Bring-your-own-key signing, verifiable without a Screenata account
- Inline action pills call live integration checks
- Auditors read the same document the agent runs
- No drift between what's documented and what executes
- Every run captured as evidence
Registers
The inventories every auditor asks for, built from your systems rather than a spreadsheet.
- Risks linked to controls and policy claims
- Treatment plans with owners and due dates
- Risk acceptance always requires human approval
- Annual risk assessment refresh runs on schedule
- Vendors discovered from package.json, Terraform, and env vars
- Auto-researched against a 500+ vendor catalog
- Risk tiering with review cadences
- HIPAA BAA tracking, separation of duties on assessments
- Synced from GitHub, AWS, Azure, GCP, and Cloudflare
- Discovered from infrastructure-as-code
- Curated by you where discovery can't reach
- Satisfies SOC 2, HIPAA, ISO 27001, PCI DSS, and NIST 800-53 at once
- Policy acknowledgments that track themselves
- AI-generated security awareness training with quizzes
- Device posture tracking
- CSV onboarding auto-assigns required training
Trust & audit
The buyer-facing and auditor-facing surfaces. Sold as paid add-ons elsewhere, included here.
- Custom domain, so it lives on trust.yourcompany.com
- Badges, control posture, subprocessors, and a changelog
- Gated document downloads behind approval and email verification
- Every download logged as an access record
- Answers the security email before it's sent
- Excel upload: drop in the buyer's .xlsx workbook
- Chrome extension answers web portals like OneTrust in place
- Answer library grows from every answer you approve
- Grounded only in approved policies and evidence, always cited
- Fail-closed: leaves a question blank rather than guessing
- Exports back into the buyer's original file
- Live evidence review with comment threads on artifacts
- Per-engagement access grants, fully logged
- Readiness preflight gate before fieldwork starts
- Signed audit package frozen at completion
Automation & surfaces
The part that actually does the work, in the tools your team already has open.
- Knows what you're looking at, no pasting IDs
- 27+ compliance tools across the whole program
- Permission tiers: autonomous, notify, approval-required
- Every tool call logged, which is itself AI governance evidence
- 06:00 evidence freshness, 06:15 readiness, 06:30 Slack briefing
- Weekly cloud and repository scans
- Quarterly access reviews, annual risk refresh
- Remediation orchestration into Jira, Linear, and GitHub Issues
- 60+ native integrations
- 650+ automated evidence checks
- AWS, Azure, Kubernetes, M365, GCP, GitHub, Okta, and more
- Read-only by construction, credentials never touch our database
- Slack briefings, DM evidence requests, file drops auto-classified
- {org-slug}@screenata.com with sender-aware intent routing
- screenata CLI with an audit preflight gate for CI
- GitHub PR compliance review, MCP server for Claude Code and Cursor
- Recorder extension captures workflows with DOM snapshots
- AI coach guides collection in real time
- Vision model scores quality across 4 dimensions before submission
- Free desktop recorder for macOS and Windows
Startup pricing is $5,988/year ($499/mo) per framework, not per module or per seat. It is designed for a standard audit scope, typically for teams up to 50 employees and one legal entity. Each additional framework is priced lower than the first, because it shares the same modules and the same evidence set through a canonical control catalog, so one MFA scan satisfies SOC 2 CC6.1 and HIPAA §164.312(d) at once. Machine-readable version: pricing.md.
The math
Year one of SOC 2, priced honestly.
Multi-framework note: SOC 2 + HIPAA share one evidence set via a canonical control catalog. Competitors charge $3–10K per additional framework with separate evidence sets.
Pricing FAQ
What founders ask before buying.
What does $5,988/year include?
The Startup program includes one framework, all 16 core modules, all integrations, all agent operations, and policy generation through the auditor-ready evidence package. That's $499/month, billed annually. It is designed for a standard startup audit scope, typically up to 50 employees and one legal entity. Eligibility also reflects environment complexity, evidence populations, and implementation requirements—not headcount alone.
Are any modules sold separately as add-ons?
No. All 16 core modules are in the Startup program, including the three that competitors most often charge extra for: Trust Center, vendor management (third-party risk), and the AI security questionnaire assistant. There are no per-module or per-seat fees. Scale & Enterprise adds organization capabilities such as SAML SSO and a tailored implementation, rather than withholding core compliance modules.
When do we need Scale & Enterprise?
Scale & Enterprise is for programs with complex environments, larger evidence populations, multiple entities or business units, custom integration or control requirements, or dedicated implementation needs. It includes SAML SSO. Pricing is scoped to the program, not determined by employee count alone.
Is there pricing for teams of five or fewer?
Yes. Teams of five or fewer can contact us for micro-startup pricing. It is the same product with every module included and your own independent auditor, priced for a smaller scope and quoted by email rather than published. See the micro-startup page for eligibility and how to ask.
What happens to the modules when we add a second framework?
You keep all of them, and they share one evidence set. Frameworks are mapped through a canonical control catalog, so a single MFA scan satisfies SOC 2 CC6.1 and HIPAA §164.312(d) at the same time. You are not rebuilding a second control matrix, a second vendor register, or a second policy set. Competitors typically charge $3–10K per additional framework and maintain separate evidence.
Does the price include the audit itself?
No, and that's deliberate. AICPA independence rules prevent the firm that prepares your compliance program from also auditing it. You pick the auditor (we work with any), typically $5–15K for a SOC 2 Type I from an independent boutique firm — peer-reviewed firms quoted us as low as $3K in September 2026. Do the all-in math: $5,988 for the platform plus your auditor is roughly $11–21K, a fraction of the $60–180K traditional stack, and the report comes from an auditor with no stake in the platform that prepared you. Bundles that fold the audit into the platform price can't say that.
How does this compare to Vanta or Drata?
Vanta and Drata are quote-based; Vendr's transaction data puts companies under 50 employees at $12–25K/year for one framework, before modules and headcount, before the person-hours it takes to actually operate them ($8–15K/month if you outsource that work). Screenata is $5,988/year per framework ($499/mo) and operates itself: scheduled scans, evidence collection, Slack briefings, and policy generation run as agent operations, not checklists waiting for a human.
How long until we're audit-ready?
4–6 weeks from connecting your systems to a complete Type I package, policies, risk assessment, system description, network diagram, org chart, control matrix, vulnerability review, and oversight minutes. Founder effort is measured in hours, not weeks.
What happens to our evidence if we leave?
It leaves with you. Your evidence packs are signed and exportable, verifiable outside Screenata with the free verify CLI, so your compliance program is portable by design rather than locked to our platform.
Deal waiting on SOC 2?
Your next enterprise deal is waiting on SOC 2.
Get audit-ready in 4–6 weeks. Hours of your time, not months.