Screenata

Platform / Vendor management

Your vendor register,
discovered from your code

Most vendor inventories are a spreadsheet someone built the week before the audit. Screenata reads package.json, .env, Terraform, and Docker to find the vendors you actually depend on, researches their compliance posture, and runs a real assessment workflow that ends in signed audit evidence.

See pricing
Vendor enrichment catalog
500+
Risk tiers with cadences
4
SOC 2 control mapped
CC9.2
Critical-vendor reviews
180d
Vendor Inventory
ExportSeed from ContextAdd Vendor

Total Vendors

24

High Risk

3

Active

19

Needs Review

4

IDNameCategoryInherentResidualBAAStatusNext Review
VND-001AWSCloud InfraCriticalHighSignedActiveMar 14, 2027
VND-002OktaIdentityCriticalMediumSignedActiveJan 30, 2027
VND-003GitHubCI/CDHighMediumActiveJul 2, 2026
VND-004DatadogMonitoringHighLowActiveSep 22, 2027
VND-011StripeDiscovered · package.jsonOtherHighUnassessedUnder Review

11:42 · Stripe discovered in package.json — SOC 2 Type II researched, assessment drafted for review

Third-party risk without the spreadsheet

Discovery from real dependencies

Scans your repos and infrastructure config to surface the vendors in actual use, then auto-researches each one: SOC 2 and ISO status, BAA availability, breach history, drawing on an enrichment catalog of 500+ vendors.

  • Found in package.json, .env, Terraform, and Docker, not from memory
  • New dependencies surface as vendors automatically
  • Draft assessments arrive pre-researched for your review
Discovered from code
package.jsonStripe foundSOC 2 researchedAssessment drafted

Researched against a 500+ vendor catalog

Risk tiers that drive a schedule

Every vendor gets an inherent risk tier from its category and a residual tier once assessed. Tiers aren't labels, they set the review cadence: critical vendors every 180 days, high annually, medium every two years.

  • Inherent vs residual risk tracked separately
  • Review dates set automatically on approval
Review cadence by tier
  • Critical vendorsevery 180 days
  • Highannual
  • Mediumevery 2 years

Next-review dates set automatically on approval

Assessments with separation of duties

A versioned workflow, draft, submitted, approved, rejected, or needs revision, where the reviewer can never be the requester. On approval, the assessment mints a signed evidence pack mapped to SOC 2 CC9.2.

  • Reviewer ≠ requester, enforced by the system
  • Every approved assessment becomes signed audit evidence
  • Full version history for auditors to trace
VND-011 Stripe · Assessment v2Approved
DraftPendingApproved
Requested by @priya Reviewed by @marcus
reviewer ≠ requester · enforcedEvidencePack · CC9.2 · Signed

A BAA register for HIPAA

Business associate agreements tracked on the vendor itself: not required, required, signed, or expired. If you handle ePHI, the vendors that touch it can't quietly slip out of coverage.

  • BAA status visible right on the vendor row
  • Feeds your Trust Center subprocessor list
BAA registerHIPAA
  • AWShandles ePHISigned
  • Google Cloudhandles ePHISigned
  • Intercomhandles ePHINeeded

Coverage gaps can't hide in a filing cabinet

From dependency to signed evidence

  1. 01

    Discover

    Vendors surface from your codebase and infrastructure, enriched with researched compliance posture.

  2. 02

    Assess

    Risk-tiered assessments run through a reviewed, separation-of-duties workflow on a set cadence.

  3. 03

    Evidence

    Approvals mint signed evidence packs mapped to CC9.2, ready for the audit package.

See what your codebase depends on

Connect read-only and watch the vendor register build itself, researched, tiered, and ready to assess.