# Screenata Pricing

> $5,988/year per framework ($499/mo). All 16 modules included. No per-module pricing, no per-seat pricing. Under 50 employees, one framework.

Canonical page: https://screenata.com/pricing
Last generated from: app/(marketing)/pricing/modules.ts (single source of truth shared with the rendered page)

## The plan

| Item | Value |
| --- | --- |
| Price | $5,988 per year, per framework ($499/mo) |
| Billing | Annual, $5,988/year per framework, all modules included |
| Eligibility | Under 50 employees, one framework |
| Seats | Unlimited, no per-seat fee |
| Modules | All 16, no add-ons and no module tiers |
| Frameworks | Start with SOC 2. HIPAA, ISO 27001 and others priced per framework |
| Time to audit-ready | 4 to 6 weeks from connecting systems |
| Audit fee | Not included, and deliberately so, see "What is not included" below |

## What "per framework" means

The $5,988/year is charged per compliance framework, not per module and not per
seat. Every module listed below is included for every framework you run.

Adding a second framework does not duplicate your work. Frameworks are mapped
through a canonical control catalog, so one MFA scan satisfies SOC 2 CC6.1 and
HIPAA §164.312(d) simultaneously, and you keep one control matrix, one vendor
register, one asset register, and one policy set. Competitors typically charge
$3,000 to $10,000 per additional framework and maintain separate evidence sets.

## Modules included

All 16 modules are included at no additional cost. Notably, Trust Center,
vendor management (third-party risk), and the AI security questionnaire assistant
are included here; Vanta, Drata, and OpenLane commonly sell those as paid add-ons.

### Compliance program

The audit-ready core: what you must prove, what you wrote down, and what proves it.

| Module | What it covers | Key capabilities | Price |
| --- | --- | --- | --- |
| [Controls & tests](https://screenata.com/product) | An auto-scoped control matrix, right-sized for your team, with tests as the unit of work. | Control matrix generated from your systems<br>N/A justifications recorded, not guessed<br>Cross-framework mapping through a canonical control catalog<br>Per-framework readiness scored daily | Included |
| [Policies & documents](https://screenata.com/product/policies) | Policies written from infrastructure scans instead of templates with blanks to fill. | Generated from real GitHub, cloud, and IdP configuration<br>Overpromise checker flags claims you can't prove<br>Every sentence traced: claim → test → evidence<br>Versioning, review, and approval workflow | Included |
| [Evidence vault](https://screenata.com/product/evidence) | Collection, freshness tracking, and cryptographically signed evidence packs. | 70% of evidence collected fully automatically<br>Freshness lifecycle: fresh → stale at 90d → expired at 120d<br>SHA-256 hashes, RSA/ECDSA signatures, RFC 3161 timestamps<br>Bring-your-own-key signing, [verifiable without a Screenata account](https://screenata.com/open-attest) | Included |
| [Procedures & runbooks](https://screenata.com/product/agents) | Compliance procedures that are readable documentation and executable tests at once. | Inline action pills call live integration checks<br>Auditors read the same document the agent runs<br>No drift between what's documented and what executes<br>Every run captured as evidence | Included |

### Registers

The inventories every auditor asks for, built from your systems rather than a spreadsheet.

| Module | What it covers | Key capabilities | Price |
| --- | --- | --- | --- |
| [Risk management](https://screenata.com/product) | A risk register with scoring, treatment plans, and a scheduled annual refresh. | Risks linked to controls and policy claims<br>Treatment plans with owners and due dates<br>Risk acceptance always requires human approval<br>Annual risk assessment refresh runs on schedule | Included |
| [Vendor management](https://screenata.com/product/vendors) | Third-party risk built from your codebase, not from a form somebody forgot to fill in. | Vendors discovered from package.json, Terraform, and env vars<br>Auto-researched against a 500+ vendor catalog<br>Risk tiering with review cadences<br>HIPAA BAA tracking, separation of duties on assessments | Included |
| [Asset management](https://screenata.com/product/assets) | One asset register across clouds, SaaS, repos, and data stores. | Synced from GitHub, AWS, Azure, GCP, and Cloudflare<br>Discovered from infrastructure-as-code<br>Curated by you where discovery can't reach<br>Satisfies SOC 2, HIPAA, ISO 27001, PCI DSS, and NIST 800-53 at once | Included |
| [Personnel & employee portal](https://screenata.com/product/employee-portal) | Personnel compliance without chasing anyone in Slack for the fourth time. | Policy acknowledgments that track themselves<br>AI-generated security awareness training with quizzes<br>Device posture tracking<br>CSV onboarding auto-assigns required training | Included |

### Trust & audit

The buyer-facing and auditor-facing surfaces. Sold as paid add-ons elsewhere, included here.

| Module | What it covers | Key capabilities | Price |
| --- | --- | --- | --- |
| [Trust Center](https://screenata.com/product/trust-center) | A public, branded security page published straight from your compliance program. | Custom domain, so it lives on trust.yourcompany.com<br>Badges, control posture, subprocessors, and a changelog<br>Gated document downloads behind approval and email verification<br>Every download logged as an access record<br>Answers the security email before it's sent | Included |
| [Security questionnaires](https://screenata.com/product/questionnaires) | Buyer questionnaires answered from approved ground truth, with citations. | Excel upload: drop in the buyer's .xlsx workbook<br>[Chrome extension](https://screenata.com/extensions/security-questionnaire-assistant) answers web portals like OneTrust in place<br>Answer library grows from every answer you approve<br>Grounded only in approved policies and evidence, always cited<br>Fail-closed: leaves a question blank rather than guessing<br>Exports back into the buyer's original file | Included |
| [Auditor portal](https://screenata.com/product/auditor-portal) | A scoped workspace for your auditor instead of a ZIP file over email. | Live evidence review with comment threads on artifacts<br>Per-engagement access grants, fully logged<br>Readiness preflight gate before fieldwork starts<br>Signed audit package frozen at completion | Included |

### Automation & surfaces

The part that actually does the work, in the tools your team already has open.

| Module | What it covers | Key capabilities | Price |
| --- | --- | --- | --- |
| [Vera, AI compliance officer](https://screenata.com/product/vera) | An autonomous compliance officer, context-aware on every page, not a chatbot in a sidebar. | Knows what you're looking at, no pasting IDs<br>27+ compliance tools across the whole program<br>Permission tiers: autonomous, notify, approval-required<br>Every tool call logged, which is itself AI governance evidence | Included |
| [Agent operations](https://screenata.com/product/agents) | Scheduled agents that run the program on a cadence instead of a to-do list. | 06:00 evidence freshness, 06:15 readiness, 06:30 Slack briefing<br>Weekly cloud and repository scans<br>Quarterly access reviews, annual risk refresh<br>Remediation orchestration into Jira, Linear, and GitHub Issues | Included |
| [Integrations & checks](https://screenata.com/integrations) | Native provider checks that produce audit-grade evidence, not shallow connection points. | 60+ native integrations<br>650+ automated evidence checks<br>AWS, Azure, Kubernetes, M365, GCP, GitHub, Okta, and more<br>Read-only by construction, credentials never touch our database | Included |
| [Workflow surfaces](https://screenata.com/product/workflows) | Slack, email, CLI, GitHub, and MCP, all hitting one API with one context. | Slack briefings, DM evidence requests, file drops auto-classified<br>{org-slug}@screenata.com with sender-aware intent routing<br>screenata CLI with an audit preflight gate for CI<br>GitHub PR compliance review, MCP server for Claude Code and Cursor | Included |
| [Screenshot automation](https://screenata.com/product/screenshots) | The long tail: consoles no API can reach, captured as audit-grade evidence. | [Recorder extension](https://screenata.com/extensions/evidence-collector) captures workflows with DOM snapshots<br>AI coach guides collection in real time<br>Vision model scores quality across 4 dimensions before submission<br>[Free desktop recorder](https://screenata.com/desktop) for macOS and Windows | Included |

**Total: all 16 modules for $5,988/year per framework ($499/mo), unlimited seats.**

Module index (flat list): Controls & tests, Policies & documents, Evidence vault, Procedures & runbooks, Risk management, Vendor management, Asset management, Personnel & employee portal, Trust Center, Security questionnaires, Auditor portal, Vera, AI compliance officer, Agent operations, Integrations & checks, Workflow surfaces, Screenshot automation.

## What is not included

| Item | Typical cost | Why |
| --- | --- | --- |
| The audit itself | $4,000 to $8,000 for a SOC 2 Type I | AICPA independence rules prevent the firm that prepares your compliance program from also auditing it. You pick the auditor; Screenata works with any of them and is TSC-mapped, not firm-specific. All-in: platform $5,988 + your auditor is roughly $10K to $14K, versus the $60K to $180K traditional stack, and the report comes from an auditor with no stake in the platform that prepared you. |
| Additional frameworks | Priced per framework | Same modules, same evidence set, separate framework fee. Get in touch to scope it. |

## Cost comparison, first six months to SOC 2 Type I

| Line item | Traditional | Screenata | Note |
| --- | --- | --- | --- |
| Auditor | $15K | $15K | Stays independent either way |
| Policy + evidence operations (6 mo) | $60K | $0 | Vera runs the repeatable operational work |
| GRC platform | $10K | $3K | Six months of Screenata at $499/mo |
| Founder hours | 80+ | <10 | Hours, not weeks |
| **Total** | **$85K+** | **$18K** | ~95% less orchestration cost |

For reference, Vanta runs $10,000 to $80,000 per year and Drata $7,000 to $50,000
per year, before the person-hours it takes to operate them ($8,000 to $15,000 per
month if you outsource that work).

## Frequently asked pricing questions

### Are any modules sold separately as add-ons?

No. All 16 modules are in the $5,988/year per-framework price, including
Trust Center, vendor management, and the AI security questionnaire assistant.
There are no module tiers and no per-seat pricing.

### What happens to our evidence if we leave?

Evidence packs are cryptographically signed and exportable, and verifiable
outside Screenata with a free verify CLI, so the compliance program is
portable by design. Talk to us about terms.

### How long until we are audit-ready?

4 to 6 weeks from connecting your systems to a complete Type I package: policies,
risk assessment, system description, network diagram, org chart, control matrix,
vulnerability review, and oversight minutes.

## Related

- Pricing page: https://screenata.com/pricing
- Product overview: https://screenata.com/product
- Integrations: https://screenata.com/integrations
- Site index for AI agents: https://screenata.com/llms.txt
- Full content for AI agents: https://screenata.com/llms-full.txt
