Platform / Asset management
One asset register,
every framework
SOC 2 CC3.2, HIPAA, ISO 27001 8.1, PCI DSS, and NIST 800-53 CM-8 all ask the same question: what's in scope, who owns it, and what data does it touch? Screenata answers once, with a register that syncs from your providers but never overwrites your judgment.
- Asset types
- 13
- Provider syncs
- 5
- Ingestion paths
- 3
- Frameworks satisfied
- 5
Total Assets
87
Critical
9
Unclassified
4
In Scope
61
prod-postgres-primaryDatabaseRestrictedCriticalProductionIn scope
legacy-redis-cacheorphanedDatabaseInternalLowProductionIn scope
api-gatewayComputeConfidentialHighProductionIn scope
staging-clusterContainerInternalLowStagingOut of scopeLast synced 6 minutes ago · GitHub, AWS, GCP, Cloudflare · sticky fields preserved
An inventory that stays honest
Three ways in, one register
Assets arrive by provider sync (GitHub, AWS, Azure, GCP, Cloudflare), by IaC discovery during source scans, or by manual and AI-assisted entry. Compute, storage, databases, SaaS, repos, devices, facilities, datasets, thirteen types in one place.
- Cloud resources sync directly from provider APIs
- Terraform-declared infrastructure discovered during repo scans
- Every asset records where it came from
- Provider syncGitHub · AWS · Azure · GCP · Cloudflarelive
- IaC discoveryTerraform, during source scanslive
- Manual + AI createanytime
One register, whatever the source
Sticky fields protect your curation
Re-syncs refresh provider-owned attributes but never overwrite what you've set: classification, criticality, owner. Resources that disappear from a provider are marked orphaned, never silently deleted, so the audit trail survives.
- Your classifications survive every sync
- Orphaned assets keep their history for auditors
Provider-owned · refreshed
- ProviderAWS · us-east-1
- Provider IDarn:aws:rds:…:prod-postgres
- Last Synced6 minutes ago
User-curated · never overwritten
- ClassificationRestricted
- CriticalityCritical
- Owner@priya
legacy-redis-cache removed at provider → marked Orphaned, history kept for audit
Data scope where auditors look first
Each asset carries explicit data-scope flags, ePHI, PII, PCI, and a criticality rating. When an auditor asks which systems touch regulated data, the answer is a filter, not an archaeology project.
- ePHI tracking activates with HIPAA in scope
- Owner and criticality on every row
- Contains ePHIyes
- Contains PIIyes
- CriticalityCritical
“Which systems touch regulated data?” is a filter, not a project
No test explosion on connect
Connecting a cloud account deliberately does not spawn 150 tests you'll spend a week dismissing. The register stays an inventory; risk links are made explicitly, from the risk side, where they mean something.
- Inventory and monitoring are separate, on purpose
- Risk linkage is deliberate, not auto-generated noise
- Elsewhere: 150 tests spawneda week of dismissing alertsnoise
- Screenata: 41 assets inventoriedmonitoring stays separatesignal
Risk links are made deliberately, from the risk side
From sprawl to scoped
- 01
Sync
Providers and IaC populate the register automatically, with provenance on every asset.
- 02
Curate
Set classification, criticality, and ownership once, syncs never overwrite them.
- 03
Prove
One register satisfies the inventory requirements of five frameworks simultaneously.
See your real inventory
Connect read-only and watch the register assemble itself from your providers and your Terraform.