Platform / Policies
Policies written from
what’s real, not templates
Template-based policies are the #1 source of audit findings, founders approve “quarterly access reviews” they've never run. Screenata scans your GitHub, cloud, and identity provider first, then writes policies that match your actual setup.
3. Authentication
Access to production systems is granted on the principle of least privilege. Multi-factor authentication is enforced for all employees Verified · Okta scan via our identity provider. User access is reviewed quarterly by system owners Overpromise and revoked within 24 hours of termination.
Claim inspector
Every claim traces policy text → claim → test → signed evidence
Scan first. Then write.
Connect GitHub + AWS + your IdP, and policies generate from your real branch protection rules, IAM policies, and MFA enforcement.
Grounded in your infrastructure
Each policy is generated from structured context: company profile, IdP configuration, cloud posture, repo security settings, and the evidence you've already collected.
- MFA enforcement, user counts, and app assignments from your IdP
- IAM policies, encryption settings, and network ACLs from your cloud
- Branch protection, required reviews, and secrets scanning from your repos
- Okta · MFA enforced for 21 usersverified
- AWS · 2 buckets unencryptedflagged
- GitHub · branch protection on 3 reposverified
Policies are written from these results, not from templates
The overpromise checker
Hard commitments that your evidence can't support, like “quarterly access reviews” with no review on record, get flagged before you ever ship the policy to an auditor.
- Flags unsupported claims at generation time
- Auditors catch template overpromises; the checker catches them first
- “User access is reviewed quarterly”no review on recordOverpromise
- “MFA is enforced for all employees”Okta scan · 21/21Verified
- “Access revoked within 24 hours”IdP offboarding hookVerified
Caught at generation time, not in the auditor's findings
Claim-to-evidence traceability
Every policy generates claim records, testable assertions anchored to specific sentences. Each claim links to the control test that verifies it, and each test to its signed evidence artifacts.
- 4-layer chain: policy text → claim → test → submission → signed artifact
- Claims carry framework references (SOC 2 TSC, HIPAA §164, ISO 27001, CIS)
- Implementation status pills inline in the editor: implemented, partial, unimplemented
Policy text“MFA is enforced for all employees”
ClaimCLM-018 · SOC 2 CC6.1
TestPR-15-T1 · Okta MFA enforcement
EvidenceEV-1987 · signed, fresh
Auditors hover any claim and land on the signed artifact
Auditor-verifiable in one click
An auditor can hover any claim in a policy, see the test that proves it, and verify the evidence package independently with a signed manifest, no Screenata account required.
- Hover a claim → see the linked test status and evidence
- Citations map claims to specific framework controls
Verify the pack independently — no Screenata account required
From connection to approved policy
- 01
Connect your stack
GitHub, AWS or GCP, and your identity provider, read-only where possible.
- 02
Watch policies generate
Claims highlight as they're written, each traced to a real scan result.
- 03
Fix what's flagged
The overpromise checker lists claims you can't prove. Resolve or reword before approval.
See a policy generate from your real infrastructure
Connect GitHub and AWS, then watch the overpromise checker flag a claim you can't prove.