Screenata

Platform / Evidence

Evidence that collects itself,
and proves itself

Traditional platforms automate evidence monitoring but leave collection to you: screenshot the SSO config, export the log, upload the report. Screenata automates collection end to end, tracks freshness over time, and signs every artifact so auditors can verify it independently.

See pricing
Controls needing dashboard upload
0
Evidence marked stale
90 days
Evidence expired
120 days
Independent timestamps
RFC 3161
Evidence Vault
Export packSign & timestamp

Fresh

412

Stale

9

Expired

2

Signed

100%

IDEvidenceControlSourceFreshnessSignature
EV-2041Q2 access-review exportCC6.3Slack DMFreshSigned
EV-1987Okta MFA enforcement checkCC6.1API scanFreshSigned
EV-1875S3 default-encryption reportCC6.6AWSFreshSigned
EV-15232-Step Verification captureRe-collection drafted by the Evidence AgentCC6.6ScreenshotStale · 92dSigned
EV-1102Pen test report 2025CC4.1EmailExpiredSigned

Every artifact: SHA-256 hash · RSA/ECDSA signature · RFC 3161 timestamp · verifiable without a Screenata account

Collection without the manual labor

Automated by default

Most evidence is collected fully automatically, native API scans, internal reports, and policy linking. Guided flows and automated screenshots cover what APIs can't reach.

  • Native API checks against cloud providers with structured pass/fail results
  • Raw API responses retained for forensics
  • Guided step-by-step flows where the system records results
Native checks70% of evidence
  • AWS · 159 checkspassing
  • Okta · MFA enforcementpassing
  • GitHub · branch protectionpassing

Collected on schedule, with zero human touch

The last 5% comes to you

Pen test reports and insurance certificates don't require a dashboard either. Forward the email or drop the file in Slack, it's auto-classified, stored, and linked to the correct control.

  • Email evidence to your org address with intent classification
  • Slack file drops auto-classify and route to the right control
  • Zero controls require visiting a dashboard to upload
Inbox-ingested
  • Fwd: pen-test-report-2026.pdfvia email→ CC4.1 · signed
  • insurance-certificate.pdfvia Slack DM→ CC1.1 · signed

Auto-classified, stored, and linked to the right control

Freshness as a lifecycle, not a checkbox

Evidence decays. Screenata tracks fresh → stale (90 days) → expired (120 days), and the Evidence Agent checks daily, flags stale items, and triggers re-collection proactively.

  • Daily 6:00 AM freshness sweeps
  • Competitors show binary complete/incomplete; we track time-decay
Freshness lifecycledaily 06:00 sweep
FreshStale · 90dRe-collected

Flagged and re-collected before it ever expires at 120d

Cryptographically signed packs

Evidence exports are tamper-evident ZIP bundles: SHA-256 per-file hashes, RSA or ECDSA signatures, RFC 3161 independent timestamps, and BYOK so enterprises sign with their own keys.

  • Verify any pack without a Screenata account, free open-source CLI
  • Published as an open specification (Open Attest)
  • RFC 3161 timestamps are eIDAS-compatible, they hold up with Big 4 auditors
soc2-evidence-pack.zipVerified
  • manifest.jsonhashes + signature
  • evidence/EV-1987-okta-mfa.jsonSHA-256 ✓
  • evidence/EV-1523-2sv-capture.pngSHA-256 ✓
  • policies/access-control-v3.pdfSHA-256 ✓

$ attest verify soc2-evidence-pack.zip✓ 4 files · signatures valid · RFC 3161 timestamp valid

From artifact to auditor

  1. 01

    Collect

    API scans, guided flows, email forwards, and Slack drops, every path lands in the vault.

  2. 02

    Sign

    Every artifact gets the same cryptographic treatment regardless of how it arrived.

  3. 03

    Verify

    Auditors trace any policy claim to its signed artifact and verify the manifest independently.

Tamper-evident by design

SHA-256 + digital signatures

Per-file hashes with RSA/ECDSA signatures on every evidence bundle.

BYOK signing

Platform key by default, or bring your own, including AWS KMS, GCP KMS, and Azure Key Vault.

Open specification

The pack format is published as an open spec with a free verify CLI, so anyone can check a Screenata pack.

Unbox an auditor-ready package

See a signed evidence pack, its manifest, and independent verification, end to end.