SOC 2
SOC 2 is an attestation report, defined by the American Institute of Certified Public Accountants (AICPA), in which an independent CPA firm examines a service organization's controls against the Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. A Type I report covers control design at a point in time; Type II covers operating effectiveness over a period.
01why it matters for a business
For a mid-sized company, SOC 2 shows up in two directions. As a buyer, you will ask AI and software vendors for their SOC 2 Type II report to judge whether they can be trusted with your data. As a seller, enterprise customers increasingly ask you for yours, and any AI features you add, along with the vendors behind them, become part of the scope.
SOC 2 is not a certification and not a guarantee. It reports on the controls the company chose to include, over the period examined. Read the report: check the scope, which criteria are covered, any exceptions the auditor found, and the complementary controls the vendor expects you to run on your side. A model provider's report says nothing about the application a contractor built on top of it.
02what it looks like in practice
A software company selling to hospitals adds an AI feature that summarizes support tickets using a third-party model. Its next SOC 2 audit scope includes the new data flow. The team adds the model provider to its vendor management process, reviews the provider's SOC 2 report and data terms, documents how ticket data is filtered before it is sent, adds logging and access reviews for the feature, and updates its risk assessment. Customer security questionnaires about the feature now have documented answers.
03common mistakes
- Calling SOC 2 a certification, or treating a vendor's report as proof its whole stack is secure.
- Accepting a Type I report when you need evidence of controls operating over time.
- Not reading exceptions and the complementary controls expected of customers.
- Adding AI features without updating vendor management and the risk assessment.
04related terms
- AI governanceAI governance is the set of policies, roles, processes, and controls a company uses to decide which AI systems it builds or buys, how they are approved, how risks are assessed, and how they are monitored once running.
- Business associate agreement (BAA)A business associate agreement (BAA) is a contract required by HIPAA between a covered entity, such as a provider or health plan, and a vendor that creates, receives, maintains, or transmits protected health information on its behalf.
- Private LLMA private LLM is a language model deployment in which your data and prompts stay inside an environment you control or have contractually isolated, rather than a shared consumer service.
- HIPAA and AIHIPAA and AI refers to how the US Health Insurance Portability and Accountability Act applies when AI systems create, receive, store, or transmit protected health information.
05where insomnia club fits
Insomnia Club builds software with the access controls, logging, and documentation that SOC 2 audits look for, so new AI features fit into your compliance program instead of opening gaps.
see custom software development →tell us what keeps you up at night.
Scoped by the people who ship it. Priced before we start.
book a call drop your number