Screenata

Platform / Autonomous operations

Compliance that runs
on a schedule, not a to-do list

Type II requires months of continuous evidence, and most startups let controls degrade after Type I. Screenata's agents operate on schedules: scanning, checking freshness, drafting remediations, and escalating what needs a human decision.

See pricing
Evidence freshness checks
Daily
Cloud & code scans
Weekly
Access reviews
Quarterly
Risk assessment refresh
Annual
Agent reports
LLM invoked only when there’s work
Access ReviewpinnedOkta + GitHub + AWS scanned · 2 removals drafted, awaiting your approvalNeeds approval
Evidence Agent500+ checks swept · 3 stale artifacts flagged, re-collection draftedWarn
Readiness Snapshot87% ready, +3 vs yesterday · 0 new blockersPass
Cloud Security Agent159 AWS checks · 2 warn: S3 encryption, stale CloudTrailWarn
Repository AgentBranch protection verified on 3 repos · secrets scan cleanPass

Unresolved issues pin to the top of the feed until resolved

Agents with jobs, not chat windows

Specialized agent personas

Cloud Security, Repository, Code Scanner, Evidence, and Controls agents each own a domain. Each posts structured reports with pass/fail/warn summaries, critical findings, and suggested actions.

  • Unresolved issues pin to the top of the feed until resolved
  • Reports arrive as structured messages, not dashboard-red-you-never-see
Agents on shift
  • Cloud Security AgentMon 09:002 warn
  • Repository AgentMon 09:04pass
  • Evidence Agentdaily 06:00pass

Each owns a domain, each reports pass / fail / warn

Executable runbooks

Compliance tests where the documentation IS the automation. Human-readable steps contain inline action pills, clickable references to real integration checks, so auditors read the same thing the system runs.

  • One source of truth: no drift between docs and automation
  • Vera generates runbooks; humans can edit them; both can execute them
  • Watch each step run sequentially with evidence collected automatically
Runbook · Quarterly access reviewexecutable
  • 1.Pull the user list from your identity providerokta.users.list
  • 2.Diff access against last quarter's approved setaccess.diff
  • 3.Draft removal tickets for 2 stale accountstickets.draft

The documentation IS the automation — auditors read what the system runs

Quarterly access reviews, actually run

The review scans your IdP, GitHub, and cloud accounts, drafts removal tickets, and queues them for your approval. Behavioral controls become agent-managed operations, not founder checklists.

  • Scan → draft → approve, on an automatic quarterly cadence
Quarterly access review
Scan IdP + cloud2 removals draftedYour approval

A behavioral control, run as an operation

Remediation orchestration

Agents don't just report gaps, they execute fixes with your approval: IAM policy updates, branch protection changes, encryption enablement, and ticket creation in Jira, Linear, or GitHub Issues.

  • 6-state lifecycle from detected to verified and closed
  • Deduplicated findings, one stable ticket per real issue
  • Platform-specific priority mapping for your ticketing system
Remediation lifecycle
DetectedFix draftedApprovedVerified · closed

Tickets land in Jira, Linear, or GitHub Issues

Autonomy with a paper trail

  1. 01

    Scoped

    Every agent action maps to a permission entry with a role requirement and risk tier.

  2. 02

    Gated

    High-risk actions render approval cards in chat. Legally binding actions always require a human.

  3. 03

    Logged

    Every tool invocation and permission decision is recorded, the audit trail is itself SOC 2 evidence.

Watch the agents work

See a weekly scan produce findings, draft remediations, and open tickets, with you approving, not executing.