Screenata

Platform / Vera

An AI compliance officer,
not a chatbot in a sidebar

Competitors bolt AI assistants onto dashboards. Vera is the operational backbone: she scans your infrastructure, generates policies grounded in reality, collects evidence, escalates stale items, and executes remediation with your approval. She is the product.

See pricing
Daily Slack briefing
6:30 AM
Cloud & code scans
Weekly
Access reviews
Quarterly
On schedule, not on demand
24/7
Vera
26+ tools · permissioned

Are we ready for SOC 2 Type II?

readiness.checkevidence.query

87% ready, up 3 points this week. Two blockers before the observation window:

  • CloudTrail evidence stale (92 days) — I drafted a re-collection
  • Acceptable Use Policy awaiting @sam’s acknowledgment
Approve re-collectionNudge @sam

Every tool call is scoped by role and risk tier, logged, and audited

What Vera actually does

Ask Vanta or Drata to show you their AI doing something without a human clicking a button.

Context-aware on every page

Vera sees what you see. Open a failing control and she already knows which control, what evidence is missing, and what to do next, no copy-pasting IDs, no explaining your problem.

  • Page context flows to Vera automatically, control, test, policy, or risk
  • Status-aware suggestions: “This evidence is 92 days old, want me to re-collect?”
  • Scoped chat threads remember the conversation about CC6.1 from 20 minutes ago
Context: CC6.1 · Logical accessauto-loaded
  • Failing test in viewPR-15-T1seen
  • Missing: Q3 access reviewdetected
  • “Evidence is 92 days old — re-collect?”suggested

No IDs pasted, no re-explaining the problem

Autonomous scheduled operations

Daily evidence freshness checks at 6:00 AM, readiness snapshots at 6:15 AM, weekly Monday cloud and code scans, quarterly access reviews, annual risk refreshes, all running on scheduled jobs.

  • Agents invoke only when there's actual work, not token-burning heartbeats
  • Structured agent reports with pass/fail/warn summaries and action buttons
  • Unresolved issues pin to the top of the feed until resolved
On the schedule
  • Evidence freshness sweepdaily 06:00ran
  • Slack briefingdaily 06:30sent
  • Cloud + repo scanMon 09:00ran
  • Access reviewquarterlydue in 12d

Runs whether or not anyone logs in

Permissioned, auditable autonomy

Every tool Vera can use is scoped by user role and risk tier. Legally binding actions always require human approval. You control exactly what she can do, and every decision is logged.

  • Role-based access: admin, reviewer, viewer, tester, auditor, employee
  • Risk tiers from autonomous to approval-required, with in-chat approval cards
  • The audit trail of agent decisions is itself SOC 2 evidence
Approval requiredHigh risk

Enable S3 default encryption on 2 buckets

aws.s3.putEncryptionConfiguration · prod-uploads, prod-exports

ApproveDenyrequested by Cloud Security Agent

Legally binding actions always require a human

Delegation that follows up

Vera DMs teammates for evidence with step-by-step instructions and escalates on a ladder, 4 hours to DM, 24 hours to email, 48 hours to a dashboard banner, so nothing silently goes stale.

  • Evidence requests via Slack DM with guided instructions
  • File drops in Slack are auto-classified, signed, and routed to the right control
  • Email interface with sender-aware intent classification
Delegated requests
  • @priya · Q2 access reviewSlack DM · 2h agoreceived
  • @marcus · vendor SOC 2 reportemail · 22h agoescalates in 2h

Ladder: 4h → DM · 24h → email · 48h → dashboard banner

A day with Vera

  1. 01

    6:00 AM, freshness check

    The Evidence Agent sweeps every artifact for staleness and flags what needs re-collection.

  2. 02

    6:30 AM, Slack briefing

    Your #compliance channel gets a readiness briefing: what changed, what's stale, what needs a decision.

  3. 03

    During the day, approvals only

    Vera drafts, delegates, and scopes remediation. You approve actions; you don't run them.

Built to answer “what will your AI do to my systems?”

Declarative permission registry

Every agent action maps to a permission entry with role-based access and a risk tier, visible on your settings page.

Human approval for binding actions

Policy approvals and risk acceptance always require a human. Whitelist safe patterns to reduce friction over time.

Full audit trail

Every tool invocation is logged through audited wrappers. Every permission decision is recorded.

Meet your compliance officer

See Vera answer “What's our SOC 2 readiness?” with a specific answer and action items, live, on your stack.