Platform / Workflows
Compliance comes to you,
not the other way around
Founders log into GRC dashboards, feel overwhelmed, close the tab, and go back to shipping. That's why audits fail. Screenata does the daily work where you already are, Slack, email, GitHub, and your terminal. The dashboard exists for auditors and deep dives.
Veraapp6:30 AM
Morning. Readiness 87% (+3).
- S3 default encryption fixed on 2 buckets
- CloudTrail evidence stale (92d) — re-collection drafted
- Acceptable Use Policy awaiting @sam

Marcus9:14 AM · DM
pentest-report-2026.pdf
Vera: Classified as pen test reportCC4.1Signed · vaulted
File drops in DM are auto-classified, signed, and routed to the right control
Four surfaces, one program
Slack, as a first-class surface
Daily readiness briefings in your #compliance channel at 6:30 AM. Evidence requests as DMs with step-by-step instructions. File drops auto-classified, signed, and routed to the right control.
- Slash commands and approval blocks built in
- Escalation ladder: 4h → DM, 24h → email, 48h → dashboard banner
Nothing silently goes stale
Email, understood
Every org gets a universal address. Forward a pen test report or an insurance certificate and it's classified by intent, stored, and linked to the correct control, auditor questions get routed too.
- Sender-aware intent classification
- Attachments auto-route to the evidence vault
- Fwd: auditor questionssender: audit firmrouted → audit thread
- pen-test-2026.pdfsender: security vendorevidence → CC4.1
Sender-aware intent classification, no inbox triage
CLI + coding agents
A real terminal interface for engineers, and a surface your coding agents can drive. Run vendor discovery from your codebase: package.json, Terraform providers, and env vars become an audit-ready vendor inventory.
- Vendor risk discovery from code, not from a form you fill out
- Structured assessments submitted through the API
$ screenata status
SOC 2 Type II · readiness 87% · 2 blockers · 9 stale artifacts
$ screenata audit check
✓ pass · exit 0 — safe to release
GitHub, read-only by design
PR compliance reviews and repo security checks, without write access. When Vera detects a config issue, she provides guidance and a direct link. We never modify your repos.
- Explicit architectural decision: no administration:write, ever
- Branch protection and secrets scanning feed policy generation
- Linked to CC6.1 · policy claim surfacedcomment
- Verification suggestion posteddone
- Compliance status checkpassing
Read-only by design — we never write to your repos
What a week looks like
- 01
Morning briefings
6:30 AM Slack summary: readiness, stale evidence, decisions needed. Read it with your coffee.
- 02
Evidence in passing
A teammate gets a DM, drops a file, done. No login, no upload form, no nagging spreadsheet.
- 03
Approvals, not admin
You approve remediations and policies from chat. The dashboard is for auditors and deep dives.
See the 6:30 AM briefing
One demo: Slack briefing, evidence delegation by DM, and a PR compliance review.