Platform / Vendor management
Your vendor register,
discovered from your code
Most vendor inventories are a spreadsheet someone built the week before the audit. Screenata reads package.json, .env, Terraform, and Docker to find the vendors you actually depend on, researches their compliance posture, and runs a real assessment workflow that ends in signed audit evidence.
- Vendor enrichment catalog
- 500+
- Risk tiers with cadences
- 4
- SOC 2 control mapped
- CC9.2
- Critical-vendor reviews
- 180d
Total Vendors
24
High Risk
3
Active
19
Needs Review
4
AWSCloud InfraCriticalHighSignedActiveMar 14, 202711:42 · Stripe discovered in package.json — SOC 2 Type II researched, assessment drafted for review
Third-party risk without the spreadsheet
Discovery from real dependencies
Scans your repos and infrastructure config to surface the vendors in actual use, then auto-researches each one: SOC 2 and ISO status, BAA availability, breach history, drawing on an enrichment catalog of 500+ vendors.
- Found in package.json, .env, Terraform, and Docker, not from memory
- New dependencies surface as vendors automatically
- Draft assessments arrive pre-researched for your review
Researched against a 500+ vendor catalog
Risk tiers that drive a schedule
Every vendor gets an inherent risk tier from its category and a residual tier once assessed. Tiers aren't labels, they set the review cadence: critical vendors every 180 days, high annually, medium every two years.
- Inherent vs residual risk tracked separately
- Review dates set automatically on approval
- Critical vendorsevery 180 days
- Highannual
- Mediumevery 2 years
Next-review dates set automatically on approval
Assessments with separation of duties
A versioned workflow, draft, submitted, approved, rejected, or needs revision, where the reviewer can never be the requester. On approval, the assessment mints a signed evidence pack mapped to SOC 2 CC9.2.
- Reviewer ≠ requester, enforced by the system
- Every approved assessment becomes signed audit evidence
- Full version history for auditors to trace
Requested by @priya
Reviewed by @marcusA BAA register for HIPAA
Business associate agreements tracked on the vendor itself: not required, required, signed, or expired. If you handle ePHI, the vendors that touch it can't quietly slip out of coverage.
- BAA status visible right on the vendor row
- Feeds your Trust Center subprocessor list
- AWShandles ePHISigned
- Google Cloudhandles ePHISigned
- Intercomhandles ePHINeeded
Coverage gaps can't hide in a filing cabinet
From dependency to signed evidence
- 01
Discover
Vendors surface from your codebase and infrastructure, enriched with researched compliance posture.
- 02
Assess
Risk-tiered assessments run through a reviewed, separation-of-duties workflow on a set cadence.
- 03
Evidence
Approvals mint signed evidence packs mapped to CC9.2, ready for the audit package.
See what your codebase depends on
Connect read-only and watch the vendor register build itself, researched, tiered, and ready to assess.