close
breadcrumb right arrowGlossary
breadcrumb right arrowSOC 2 Compliance
SOC 2 Compliance

SOC 2 is administered by an independent auditor who examines a company's actual controls, not just its written policies, against five trust service criteria: security, availability, processing integrity, confidentiality, and privacy. The result is a formal report that a customer's own security team can review as evidence rather than taking the vendor's word for it.

For an AI agent vendor specifically, SOC 2 typically covers things like access controls, data encryption, incident response procedures, and change management, the operational discipline behind the product, not the AI model's behavior itself, which usually needs separate, AI-specific evaluation.

Frequently Asked Questions

What's the difference between SOC 2 Type I and Type II?

Type I assesses whether controls are properly designed at a single point in time. Type II is stricter, evaluating whether those controls actually operated effectively over an extended period, typically 6 to 12 months, which most enterprise buyers require specifically.

Does SOC 2 certify anything about an AI model's accuracy or safety?

No. SOC 2 covers operational and security controls around how a company handles data and runs its systems, not the quality or safety of an AI model's actual outputs, which is a separate evaluation an enterprise buyer needs to conduct on its own.

Why do enterprise buyers require a SOC 2 report before signing a contract?

It's independently verified evidence of security discipline, letting a buyer's security team assess risk without conducting a full audit of the vendor themselves, which would be impractical to do for every vendor a large company evaluates.

How often does a company need to renew its SOC 2 report?

Annually, typically, since a Type II report covers a specific observation period and buyers generally expect a current report, not one that's a year or more stale.