Platform / Evidence
Evidence that collects itself,
and proves itself
Traditional platforms automate evidence monitoring but leave collection to you: screenshot the SSO config, export the log, upload the report. Screenata automates collection end to end, tracks freshness over time, and signs every artifact so auditors can verify it independently.
- Controls needing dashboard upload
- 0
- Evidence marked stale
- 90 days
- Evidence expired
- 120 days
- Independent timestamps
- RFC 3161
Fresh
412
Stale
9
Expired
2
Signed
100%
Every artifact: SHA-256 hash · RSA/ECDSA signature · RFC 3161 timestamp · verifiable without a Screenata account
Collection without the manual labor
Automated by default
Most evidence is collected fully automatically, native API scans, internal reports, and policy linking. Guided flows and automated screenshots cover what APIs can't reach.
- Native API checks against cloud providers with structured pass/fail results
- Raw API responses retained for forensics
- Guided step-by-step flows where the system records results
- AWS · 159 checkspassing
- Okta · MFA enforcementpassing
- GitHub · branch protectionpassing
Collected on schedule, with zero human touch
The last 5% comes to you
Pen test reports and insurance certificates don't require a dashboard either. Forward the email or drop the file in Slack, it's auto-classified, stored, and linked to the correct control.
- Email evidence to your org address with intent classification
- Slack file drops auto-classify and route to the right control
- Zero controls require visiting a dashboard to upload
- Fwd: pen-test-report-2026.pdfvia email→ CC4.1 · signed
- insurance-certificate.pdfvia Slack DM→ CC1.1 · signed
Auto-classified, stored, and linked to the right control
Freshness as a lifecycle, not a checkbox
Evidence decays. Screenata tracks fresh → stale (90 days) → expired (120 days), and the Evidence Agent checks daily, flags stale items, and triggers re-collection proactively.
- Daily 6:00 AM freshness sweeps
- Competitors show binary complete/incomplete; we track time-decay
Flagged and re-collected before it ever expires at 120d
Cryptographically signed packs
Evidence exports are tamper-evident ZIP bundles: SHA-256 per-file hashes, RSA or ECDSA signatures, RFC 3161 independent timestamps, and BYOK so enterprises sign with their own keys.
- Verify any pack without a Screenata account, free open-source CLI
- Published as an open specification (Open Attest)
- RFC 3161 timestamps are eIDAS-compatible, they hold up with Big 4 auditors
- manifest.jsonhashes + signature
- evidence/EV-1987-okta-mfa.jsonSHA-256 ✓
- evidence/EV-1523-2sv-capture.pngSHA-256 ✓
- policies/access-control-v3.pdfSHA-256 ✓
$ attest verify soc2-evidence-pack.zip✓ 4 files · signatures valid · RFC 3161 timestamp valid
From artifact to auditor
- 01
Collect
API scans, guided flows, email forwards, and Slack drops, every path lands in the vault.
- 02
Sign
Every artifact gets the same cryptographic treatment regardless of how it arrived.
- 03
Verify
Auditors trace any policy claim to its signed artifact and verify the manifest independently.
Tamper-evident by design
SHA-256 + digital signatures
Per-file hashes with RSA/ECDSA signatures on every evidence bundle.
BYOK signing
Platform key by default, or bring your own, including AWS KMS, GCP KMS, and Azure Key Vault.
Open specification
The pack format is published as an open spec with a free verify CLI, so anyone can check a Screenata pack.
Unbox an auditor-ready package
See a signed evidence pack, its manifest, and independent verification, end to end.