Blue network cables converging into a server switch

SOC 2 for AI Companies

AI apps are split into different types based on what they do. With the rapid growth of AI, companies face a litany of new challenges in managing AI-related risks and protecting sensitive data. As AI companies handle vast amounts of data, compliance frameworks have struggled to adapt.

While compliance control frameworks catch up, you can begin mapping common AI-related threats to controls that align with the criteria found in SOC 2. It's an established framework AI companies can use today to demonstrate security and build customer trust.

Is Your AI Company Considering SOC 2 Compliance?

Some prospects ask for a SOC 2 outright. More of them never mention it and quietly factor the missing report into their decision. Most enterprises have AI governance activities in place, but is it audit-ready and at par with the maturity needed to stand out? Identifying these gaps and proving out your governance with your organization early can help separate your organization from others who only assume they can.

A SOC 2 report puts an independent CPA firm and their assurance report details between your claims and your prospective customers' doubts. We test whether you do what you say you do, around your data and your models, over a period of months, and we sign an opinion your customers can rely on. It takes compliance concerns off the table so the deal can be about your product.

Three streams: two tributaries rise in your watershed, a third arrives from one you cannot see, and they join into one river.

Not sure if you need a SOC 2?

Take our free 2-minute assessment. Instant results, no email required.

Take the Assessment

Where Customer Data Goes, and What We Test at Each Step

When a security team reviews an AI product, their questions trace a path: how does our data get in, what happens when it reaches your models, and who else ends up with it. An astute security-minded individual may go deeper than just a data flow document.

Ingestion and Storage

How does customer data get into your product and where is storage and transmission mapped and handled? A buyer has worries over their data being used to train models or other confidentiality concerns. Consider where prompts are stored and the outputs. How these are retained and how this can be verified.

Prompts and Processing

What actually gets sent to a model? Not everything in your database ends up in a prompt, and prospects may ask about what is utilized. Processing integrity controls or other common confidentiality controls, such as data masking and system log monitoring, areas where humans are in the loop to verify data, need appropriate levels of governance to meet the risks enterprise customers would want to verify.

Model Providers and Vendors

If you build on OpenAI, Anthropic, or another provider, your customers' data goes there too. Have you reviewed your vendor agreements and their applicable compliance documents? How were API integrations confirmed to be configured as appropriate? When development is shipping quick, how are config checks scheduled and verified to match what your customer contracts are committing towards? These key controls and appropriate governance in policy need to be considered.

The Boundary

Your Provider's Report Is Not Your Report

What Their Report Covers

You cannot use your model provider's SOC 2 Report. It helps support your system, but it cannot be relied upon to explain your system and your processes over how you implemented their solution. Your model provider's SOC 2 speaks to their controls over their infrastructure. It tells your customers nothing about your tenancy model, your retention, or your access controls.

AICPA SOC for Service Organizations seal

How the Relationship Appears in Yours

The provider (eg Anthropic) is disclosed as a subservice organization, typically under the carve-out method. Your report describes what you rely on them for, and your vendor management of them is tested: selection, terms, configuration, and review.

The Claims on Your Security Page

Zero-retention modes, no-training guarantees, region pinning: if you advertise it, an examination asks how you know it is true. This is where independent third-party assurance helps.

Report Scope

What the SOC 2 Criteria Reach Inside an AI System

Depending on the type of AI your organization deploys, a range of risks must be thoughtfully evaluated. A SOC 2 has Trust Services Categories that can be applied to help tie in framework criteria to controls that you define that can address key AI risks your customers are asking about. Every SOC 2 examination includes the Security category. Confidentiality covers what you promise about customer data reaching models. And where your product makes decisions for customers, the Processing Integrity category can cover model inputs, processing, and outputs directly.

The examination has no opinion on whether your model is good. It tests whether the machinery around the model is controlled. More on how we approach technology audits is on our auditing tech with tech page.

Approved Training Data

Which datasets may a model train on? Where did they come from, and who approved them?

Validation Before Release

How are accuracy, bias, and error rates tested before a model version ships? Are the results written down, or just remembered?

Versioning Through Change Management

Do retraining and architecture changes move like code releases? Are they proposed, reviewed, approved, and reversible?

Access to Models and Weights

Who can modify or retrain a model? Is access to training data least-privilege, and do your logs show who touched what?

Monitoring and Drift

Is model performance watched over time? What is the error handling and incident path for the day outputs go wrong?

AI Vendor Questions, Answered

What founders and security leads at AI companies ask us first.

Talk to a Partner

Frankly, it depends. Sometimes you can get by and win deals with security questionnaires alone, and a SOC 2 Report has an ROI you need to budget: your team's time, your industry, the classification of the data you handle, the risks you present to prospective customers, and your growth strategy all factor in.

Selling into enterprises, or processing regulated or sensitive data, usually brings the request early, sometimes at the first pilot. A SOC 2 isn't right for everyone; when prospects' security teams start asking, it is time to start.

It covers the controls around them. SOC 2 does not evaluate model quality, bias, or safety; it examines how data enters your pipelines, who can access it, how long it is retained, which vendors receive it, and whether the commitments you make about training use are backed by working controls.

If your contracts promise that customer data never trains models, the examination can test the controls that keep that promise true.

No, and their own reports say so. A model provider's SOC 2 covers its controls over its infrastructure, and reports like Anthropic's and OpenAI's list complementary user entity controls and user entity responsibilities, the criteria that remain yours to cover. Their terms of service draw the same line.

The provider appears in your report as a subservice organization, typically under the carve-out method, and what gets tested is your vendor management process: how you vet, contract with, and monitor your subservice providers, the key vendors that support your system.

Security applies in the framework as "Common Criteria" and carries many of the organizational common controls seen. Confidentiality is the usual second category for AI products: it examines how information designated confidential is identified, protected, and disposed of, which maps onto prompts, context data, and model inputs.

Where your product makes decisions for customers, Processing Integrity is worth considering too, because it covers whether model inputs, processing, and outputs work as intended.

A Type I runs 1 to 2 months from kickoff to issued report, and a Type II covers an observation window of typically 6 to 12 months, with the final report within 5 to 7 weeks of period end.

The step-by-step timeline is on our SOC 2 reporting page.

We quote one fixed fee before work begins. The drivers are the categories in scope, Type I versus Type II, and the complexity of your pipeline and vendor chain.

Our pricing calculator gives you an estimate in a few minutes.

Transparent Pricing

Get Your 
Custom Quote

Our pricing is structured and fixed-fee. What drives it is the complexity of your environment, the key vendors that support your system, and the commitments you have made to customers, along with how you want those aligned to the Trust Services Categories you put in scope. Share a few details about your situation and we will follow up personally, usually with a quick call, to walk through scope and get you a clear fixed quote you can plan around.

Put Evidence Behind Your Answers

Procurement will still have questions; a report means your answers carry an independent opinion. Walk us through your architecture and hosted APIs, and we will help with clarity on scoping your system boundary and can answer questions about the SOC 2 compliance process.

Book a Free 30-Minute Call