Screenata SOC 2 compliance software
Screenata is SOC 2 compliance software for small engineering teams, priced at $5,988 per year for companies under 50 people. Connect GitHub and your cloud stack, and it collects audit evidence, drafts policies, and hands work to your CPA through an auditor portal.
By Peter Korpak, Lead Editor Β· independently researched Β· Methodology
- Pricing
- Published, from $6.0K/yr
- Source-checked frameworks
- 3
- Integrations
- 60+
Screenata is run by WOX LLC, a small private company (about 2-10 people on LinkedIn as of September 2026). G2 and Capterra list the product but had no usable review counts when we checked. Data stays in the US. The audit itself is separate: you pick the CPA firm and pay them directly. Adding ISO 27001 is marketed on a product page while the homepage FAQ still says SOC 2 and HIPAA only; extra-framework pricing differs between the pricing page and the SOC 2 page. We did not verify Screenata's own SOC 2 report (offered under NDA). GDPR is not listed because the solutions page returned 404.
Screenata publishes a price.
You can read the numbers without a sales call, which is uncommon in this category and worth weighing on its own.
- Disclosure model
- Published, from $6.0K/yr
- Sourced annual price
- USD 5,988 / year
- Basis
- Confirmed, 2026-09-02
Published catalog evidence
These prices are tied to the named channel and scope. A missing direct price remains unknown; it is not inferred from the marketplace listing.
| Plan or add-on | Published price | Channel and scope |
|---|---|---|
| AI compliance officer Plan | USD 5,988 / year | Under 50 employees, one framework; billed annually at $499/month equivalent Β· Published catalog |
Software pricing alone does not establish the audit fee. A licensed CPA firm issues the SOC 2 report. A commercial offer may package coordination or the fee, so get the legal provider, deliverable, and amount in writing. See the SOC 2 audit cost guide for scope and budget context.
What Screenata does.
Seven capabilities, graded the same way for every platform in the directory. "Not established" means we looked and could not confirm it, not that the feature is missing.
| Capability | Status | Evidence |
|---|---|---|
| Automated evidence collection | Yes | Scheduled checks pull evidence from connected cloud, identity, and code tools. Screenata says each artifact is signed and time-stamped. We did not run the connectors ourselves. Source |
| Auditor workspace | Yes | Pricing page lists an auditor portal: your CPA can review live evidence, leave comments, and download a locked audit package when you are done. We have not used the portal. Source |
| Trust center | Partial | Trust center module is included (custom domain, badges, subprocessors, gated downloads). Screenata's own public trust-center URL returned 404; we found no live customer example. Source |
| Security questionnaire answering | Yes | Upload Excel questionnaires, use a Chrome extension on web portals, or pull answers from a library tied to your policies and evidence. Extension listed July 2026. Source |
| Enterprise admin (SSO, SCIM, RBAC) | Partial | Role-based permissions (admin through employee) and two-factor login. SSO and SCIM for logging into Screenata were not on public pages we checked. Source |
| SCIM 2.0 provisioning | Not established | No public Screenata page we reviewed documents automatic user provisioning (SCIM). Missing from their site is not proof they lack it. |
| Continuous control testing | Yes | Published schedule: daily evidence refresh, weekly cloud and code scans, quarterly access reviews, annual risk refresh. Source |
| Native multi-framework support | Partial | Adding HIPAA or ISO 27001 reuses evidence from your SOC 2 program by mapping controls across frameworks, rather than building each from scratch. Screenata cites a shared control catalog. Source |
3 frameworks checked individually, and how well each is established.
A framework on a marketing page is a vendor claim, not a confirmed capability. We grade the difference rather than repeating the list.
| Framework | Evidence | Note |
|---|---|---|
| SOC 2 | Vendor-claimed | Product page covers Type I and Type II prep, maps evidence to SOC 2 criteria, and includes an auditor-ready package. Screenata sells software, not a signed report. Source |
| HIPAA | Vendor-claimed | HIPAA page covers policies tied to HIPAA security rule requirements, scoping for covered entities and business associates, and tracking vendor BAAs. Evidence can be shared with your SOC 2 program. Source |
| ISO 27001 | Vendor-claimed | ISO 27001 page adds Annex A controls on top of SOC 2 by mapping shared checks across frameworks. Homepage FAQ still says SOC 2 and HIPAA today, with more frameworks coming. Source |
Who actually issues the report.
Screenata does not perform SOC 2 audits and says it takes no referral fees from auditors. You choose an independent CPA firm. The product is built to work with any auditor, not one specific firm. Screenata offers to share its own SOC 2 report under NDA; we have not reviewed it.
Software prepares you for the audit; a licensed CPA firm performs it and issues the report. If you have not picked a firm yet, we list independent SOC 2 auditors separately, and we are not one of them.
Who Screenata is for, and who it is not.
Good fit
A SaaS team under 50 people that wants a published yearly price, will connect GitHub and cloud accounts (read-only), and will bring its own CPA firm.
Poor fit
Teams that need lots of public reviews, named implementation help, confirmed SSO or automatic user provisioning, or data residency outside the US (Screenata is US-only). Also a weak fit if you need PCI DSS, HITRUST, CMMC, NIS2, or DORA; those are not on Screenata's public product pages.
Typical buyer: An engineering-led B2B SaaS team under 50 people pursuing a first SOC 2, or SOC 2 plus HIPAA, who want a listed price and plan to hire their own auditor..
Compare Screenata with three alternatives.
- Comp AI Sponsored
An engineering-led company that values an inspectable, self-hostable compliance platform and wants one vendor scope that can include guided implementation, a trust center, penetration testing, and audit coordination when quoted.
-
A company that wants to see real dollar figures before a sales call: Strike Graph is one of the few vendors in this set that puts specific starting prices ($10,000 / $21,500 / $35,000 per year) and most framework add-on costs directly on its public pricing page.
-
A company fielding a high volume of inbound security questionnaires and enterprise trust reviews, where TrustShare's AI pre-fill and live trust portal reduce sales-cycle friction as much as the SOC 2 compliance work itself.
Sources
If a claim on this page is out of date, this is the list to re-check.
| Establishes | Source | Retrieved |
|---|---|---|
| Screenata Security Questionnaire Assistant extension v0.2.0, updated 2026-07-11, no ratings. Developer email support@deepguide.ai. Establishes a public marketplace listing independent of screenata.com. | Chrome Web Store Marketplace | |
| G2 hosts a Screenata product page in Security Compliance Software. A usable rating and review count could not be read from the public page on 2026-09-02. | G2 Review platform | |
| Capterra lists Screenata as an AI-powered compliance platform for startups needing SOC 2, HIPAA, and security-review readiness. No review corpus was independently counted. | Capterra Review platform | |
| GitHub organization created 2026-01-24. Public repos include open-chronicle (28 stars), open-attest, and open-evidence-signing. | GitHub Vendor docs | |
| Company page: Technology, Information and Internet; privately held; company size 2-10 employees. About copy markets SOC 2, HIPAA, and ISO 27001. The same retrieval showed 8 followers and one associated member, founder Tao Huang in Redmond, WA. | LinkedIn Editorial | |
| Canonical pricing page: $5,988/year per framework ($499/mo), under 50 employees, unlimited seats, all modules included, audit not included, 4-6 weeks to Type I package, 60+ integrations, 650+ checks. Additional frameworks priced separately. | Screenata (vendor) Vendor docs | |
| Rendered pricing page matches the spec: published $5,988/year per framework, no demo gate, trust center, questionnaires, and auditor portal included. | Screenata (vendor) Vendor docs | |
| SOC 2 product page: Type I and Type II preparation, signed evidence mapped to SOC 2 criteria, self-serve connect-and-scan onboarding. Also prints $349/mo per additional framework, which the canonical pricing page does not. | Screenata (vendor) Vendor docs | |
| HIPAA product page: policies mapped to HIPAA security rule requirements, covered-entity vs business-associate scoping, shared evidence with SOC 2 and ISO 27001. | Screenata (vendor) Vendor docs | |
| ISO 27001 product page: Annex A added onto SOC 2 through a shared control catalog; one MFA check mapped across SOC 2, HIPAA, and ISO 27001. | Screenata (vendor) Vendor docs | |
| Integrations catalog: 60+ integrations, 650+ automated checks across 30+ providers, named cloud, identity, code, and HR connectors, scheduled signed evidence. | Screenata (vendor) Vendor docs | |
| Security page: Azure Key Vault for customer credentials, read-only GitHub App, signed evidence, role-based permissions, offer to share a SOC 2 report under NDA. | Screenata (vendor) Vendor docs | |
| Privacy policy effective 2026-08-20: WOX LLC operates Screenata; US headquarters; subprocessors named; Dallas mailing address 539 W. Commerce St #8166. | Screenata (vendor) Vendor docs |
1 fact on this page we could not establish.
Everything above renders with its evidence state, so a gap is visible rather than quietly filled in. If you work at Screenata, send us the sources and we will fill them.
Verification is free and always will be. It does not change where Screenata appears in any list on this site, what our reviews conclude, or which platform we recommend to a buyer. We only accept a correction that comes with a source we can check ourselves, and the source is published in the sources list above alongside the date.