Screenata

Integrations / HR & people ops

Screenata + Deel

How do you automate SOC 2, ISO 27001, and HIPAA personnel evidence from Deel?

Quick answer

Deel is where personnel controls are proved for employees and contractors alike: joiner-mover-leaver, screening, and signed agreements. Contractors are the population auditors probe, because they are the one teams forget. An onboarding or offboarding policy existing on paper is not the control. The control is the recorded event plus the record that it operated for every worker across the audit period. Screenata runs 8 native checks against those records on a schedule and turns each result into signed evidence mapped to the control it satisfies.

Screenata connects to Deel read-only and runs 8 native checks against your workforce records: employee and contractor lifecycle and contract compliance. Contractors are where personnel controls most often break, and the integration brings them into the same joiner-mover-leaver evidence as employees. Each finding is a signed, timestamped artifact mapped to SOC 2, HIPAA, and ISO 27001 controls.

8 native checks · read-only · signed evidence

What it proves

Deel evidence, mapped to controls.

Each area below is scanned on a schedule. A finding is not a green checkmark: it is a signed artifact an auditor can verify, mapped to the exact requirement it satisfies.
Evidence area
What the checks verify
Maps to
Employee & contractor lifecycle

Starts and ends for employees and contractors, triggering training assignment on start and access verification on departure.

A joiner-mover-leaver record that includes contractors, the population auditors probe because it is the one teams forget.

SOC 2CC6.2SOC 2CC6.3HIPAA§164.308(a)(3)
Contract compliance

Whether workforce engagements carry the signed agreements your policies require.

Proof that the people with access to your systems are under contract, including confidentiality terms.

SOC 2CC1.4ISO 27001A.6.1
Roster reconciliation

The combined employee and contractor roster reconciled against accounts in identity and SaaS systems.

The ground truth access reviews start from, with contractor accounts included rather than invisible.

SOC 2CC6.3ISO 27001A.5.16

Control references are the requirements each evidence area supports, via the shared control catalog. Your auditor decides sufficiency; the artifacts are theirs to verify.

Compliance checks

What Screenata checks on Deel, and why each matters.

Each row is a real native check, the framework control it produces evidence for, and the risk it closes. This is what continuous Deel compliance actually looks like. Checks run on a schedule; a failing check opens a ticket and re-verifies after a human applies the fix.
Check & why it matters
Maps to

Terminated Workers Have End Dates

Verifies terminated employees and contractors have a termination date recorded. Without it access removal cannot be timed and the offboarding trail is incomplete, and an auditor samples leavers to confirm departure was recorded.

SOC 2CC6.3

Timely Offboarding

Flags active workers carrying a past termination date. The mismatch means an offboarding was not finalized and access may still be live, and an auditor checks that departures closed out on time.

SOC 2CC6.3

All Workers Have Managers

Confirms active workers have a manager assigned. Reporting chains underpin access approvals and reviews, and an auditor verifies the structure needed to attribute responsibility covers contractors as well as employees.

SOC 2CC1.3SOC 2CC1.4

Onboarding Records Complete

Verifies active workers have start dates and emails. These anchor the onboarding trail and link the roster to provisioning, and an auditor samples workers to confirm records are complete.

SOC 2CC1.4

No Stale Pending Contracts

Checks that no contract has sat awaiting signature beyond fourteen days. An unsigned contract means someone may hold access without an executed agreement, and an auditor verifies engagements are under signed terms.

SOC 2CC1.3

Worker Classification Documented

Verifies active workers have a hiring type of employee, contractor, or EOR. Personnel controls apply differently by type, and without classification the population cannot be scoped, which an auditor relies on when sampling.

SOC 2CC1.3

Drawn from Screenata’s Deel check library. Control refs are the requirements each check produces evidence for; your auditor decides sufficiency.

How it connects

Read-only, revocable, yours.

You create a read-scoped API token and Screenata uses it for scheduled scans. Vera never receives write access to your Deel workspace, and credentials never touch the Screenata database.

Read-only by construction

OAuth scopes and IAM roles are scoped to read. Vera never gets write access to your systems.

Signed findings

SHA-256 per artifact, RSA/ECDSA signatures, RFC 3161 timestamps. Verifiable without a Screenata account.

Mapped to controls

Each finding lands on the shared control catalog, so one scan satisfies SOC 2, HIPAA, and ISO 27001 at once.

Deel FAQ

What teams ask before connecting.

Full provider list on the integrations page.
What access does Screenata need to Deel?

A read-scoped API token that you create and control. Screenata reads workforce and contract state for scheduled checks and never receives write access. You can revoke the token at any time.

Why do contractors matter for SOC 2?

SOC 2 personnel controls cover everyone with access to systems in scope, not just employees. Contractor onboarding, agreements, and offboarding are sampled like any other workforce records, and they are the ones most often missing. The Deel integration puts contractors in the same evidence stream as employees.

How does Deel help with offboarding evidence?

The integration detects the end of an engagement, checks that access removal followed in your connected identity systems, and records the timeline as signed evidence. A human performs the actual revocation; Vera verifies and chases it.

What are the steps to implement SOC 2 with Deel?

Connect Deel read-only with a scoped API token. Let the first scan establish a baseline so you can see which records are complete and which are not. Fix what fails: record end dates for every terminated employee and contractor and clear anyone still active past that date, complete start dates and emails on the onboarding records, chase contracts that have sat awaiting signature past fourteen days, assign a manager to every active worker, and record a hiring type of employee, contractor, or EOR so the population can be scoped. Collect the passing results as signed evidence on a schedule, so you hold coverage across the whole audit period rather than one snapshot. Then hand the evidence package to an independent auditor. The audit is a separate engagement with a CPA firm; Screenata prepares the evidence and does not issue the report.

What evidence do auditors ask for about onboarding and offboarding?

They sample hires and leavers, contractors included. For each start they expect a start date with the training and acknowledgments that followed it, and screening or a signed agreement completed before access was granted. For each departure they expect an end date with the access removal that followed it. Timing is what gets tested, not just existence. A contract signed after the contractor already had access, or an account disabled two weeks after the engagement ended, is a finding even though the record exists.

Do auditors accept evidence Screenata collects from Deel?

Yes. Every finding is exported as a signed, timestamped artifact, a SHA-256 hash with an RSA or ECDSA signature and an RFC 3161 timestamp, that an auditor verifies outside Screenata with a free CLI. A person reviews and approves the evidence before it reaches the auditor. Screenata collects and signs it; it does not decide the audit result.

Connect and see

Fifteen minutes after connecting Deel, you know your real posture.

Pricing

Related: BambooHR · Gusto · Rippling · Checkr