Screenata

Platform / Auditor portal

Give your auditor
a workspace, not a ZIP

The traditional audit is evidence lobbed over email and questions relayed through a shared spreadsheet. Screenata's auditor portal gives the audit firm scoped access to review evidence live, ask questions on the artifact itself, and receive a cryptographically signed package, with every access logged.

See pricing
Review tabs
5
Access grants
Per-cycle
Auditor access logged
100%
Audit packages
Signed
Auditor Center — SOC 2 Type II · FY2026
Access loggedGenerate Package

Controls

48/52

Open Requests

3

Policies

12

People

21/21

DashboardControlsEvidencePoliciesPeopleTimeline
CC6.1Logical access controlsSatisfactory
CC7.2System monitoringReviewed
CC8.1Change managementPending Review

Evidence request· Please provide the Q2 access-review export.

Uploaded — see EV-2041Resolved

CC9.2Vendor risk managementException Noted

Every view and download recorded — the access log is itself audit evidence

The audit, in one place

Live review across the whole program

Auditors work through controls, evidence, policies, people, and timeline in five tabs, setting a review status on each item as they go. No re-uploading, no 'can you resend that file', the current state is always in front of them.

  • Evidence reviewed where it lives, with its signatures intact
  • Review statuses show both sides exactly what's left
Review statuses48/52
  • CC6.1 · Logical accessSatisfactory
  • CC8.1 · Change managementPending Review
  • CC9.2 · Vendor riskException Noted

Both sides see exactly what's left, in real time

Threads on the artifact, not in your inbox

Evidence requests, clarifications, and exception discussions happen as comment threads attached to the item in question. Context never gets lost in an email chain three participants deep.

  • Request types for review notes, evidence asks, and exceptions
  • Every thread resolves against the artifact it's about
Threads on the artifact
  • Evidence request · CC8.1“Please provide the Q2 access-review export”open
  • Reply · EV-2041 uploadedresolved same dayResolved

No context lost three emails deep

Access that's scoped and logged

Auditors get a dedicated role plus per-engagement access grants, they see the audit cycle they're engaged on, nothing else. Every view and download is recorded, and the access log is itself audit evidence.

  • Per-cycle grants, revocable when the engagement ends
  • The log answers 'who saw what' with timestamps
Auditor access log
  • 09:02 · viewed EV-1987Meridian Assurancelogged
  • 09:05 · downloaded packageMeridian Assurancelogged
  • Access grant expiresend of engagementMar 31

The access log is itself audit evidence

Preflight-gated, signed, and frozen

A readiness gate checks the package before the auditor ever sees it: ready, needs review, or blocked. The final package ships as a signed ZIP, system description, control matrix, policies, evidence, exceptions, manifest, and completion pins exactly what the auditor saw.

  • No half-ready packages reaching the audit firm
  • Signed manifest makes the package independently verifiable
  • Completed engagements are frozen for the record
Audit package · preflightNeeds review
  • System description exists
  • Risk assessment complete
  • 2 evidence items stale
manifest.jsonSigned · SHA-256Timestamped · RFC 3161Pinned at completion

From engagement to sign-off

  1. 01

    Grant

    Set up the audit cycle, framework, type, and period, and grant the firm scoped access.

  2. 02

    Review

    Auditors review live, raise threads, and set statuses; you resolve gaps as they surface.

  3. 03

    Sign off

    The signed package goes out through the preflight gate and is pinned at completion.

Run the next audit in the open

See the auditor's view: live evidence, threaded questions, and a signed package at the end.