SOC 2

Trust, Privacy & Compliancealso: SOC 2 Type IIalso: SOC 2 Type Ialso: SOC 2 reportalso: Trust Services Criteria

Not legal advice. This page describes legal and regulatory frameworks in general terms. Jurisdiction changes the answer, and the same voice deployment can be lawful in one market and unlawful in another. Take advice on your specific circumstances.

In one sentence

SOC 2 is an independent audit report, issued under the AICPA Trust Services Criteria, giving an auditor's opinion on whether the controls an organization has described are suitably designed and, in a Type II report, whether they operated effectively over a period.

AICPA Trust Services Criteria AICPA Trust Services Criteria, 2026Last reviewed 30 July 2026

Not to be confused with HIPAA, or PCI DSS.

Definition

SOC 2 is an outside auditor's report on how well a company controls its systems and data.

It is the document enterprise buyers most often ask a software vendor to produce, and it is an opinion within a defined scope rather than a pass-or-fail badge.

SOC 2 reports are produced under the Trust Services Criteria of the AICPA by an independent auditor. Calling it a certification misdescribes it. There is no badge to pass or fail. There is an audit opinion on controls the organization itself described.

The five Trust Services Criteria

  • Security, which is mandatory, covering protection against unauthorized access.
  • Availability, covering system uptime and accessibility commitments.
  • Processing integrity, covering complete and accurate processing.
  • Confidentiality, covering protection of information designated as confidential.
  • Privacy, covering the handling of personal information.
  • Only security is required. Which of the other four are in scope is a choice the organization makes, and a report covering security alone is narrower than buyers often assume.

Type I against Type II, the distinction that decides what a report is worth

  • Type I judges only whether the controls are suitably designed at a single moment. It is a snapshot, quicker and cheaper to obtain.
  • Type II asks whether those controls were suitably designed and, across a period of typically three to twelve months, actually operated as intended. It carries far more weight.
  • Enterprise buyers generally hold out for Type II. For a young company a Type I is a fair interim step, and the honest thing is to describe it as exactly that.

What the report does and does not tell a buyer

  • It tells them an independent auditor looked at the controls as described, reached an opinion, and recorded any exceptions along the way.
  • It does not stamp the product secure, does not take in every system, and promises nothing about what comes later.
  • The scope section is the part of the report that matters most and gets read least. A report can quite properly leave out systems a buyer cares about.

What it means in a voice pipeline specifically

  • A voice pipeline runs through several sub-processors, and a vendor's own SOC 2 does not cover their controls. Vendor management of sub-processors is itself a control, and it is the one worth examining.
  • Transcript and recording stores are the sensitive systems. A buyer should check they are in scope rather than assume it.

The practical position for a young company

  • SOC 2 costs time and money, and a Type II needs an observation window, so no amount of sales pressure can produce one quickly.
  • The honest interim position is a documented security program, a completed security questionnaire, and a stated timeline to SOC 2. Buyers take that better than vendors expect, as long as it is said plainly rather than dressed up.

Common misconception

That SOC 2 means secure. It means audited against described controls within a defined scope. A narrow-scope report carrying exceptions is a weaker signal than an unaudited but rigorous security program, though it is far easier for procurement to process, which is why it is the thing asked for.

Why it matters commercially

SOC 2 is a procurement gate rather than a security outcome. In enterprise sales it often decides whether a vendor gets evaluated at all or is dropped at the questionnaire stage. Knowing it well enough to talk about scope with a straight face is worth more than most young vendors expect.

In voice specifically

Voice adds sub-processors a text product does not have. Speech recognition, the language model and speech synthesis are usually three separate companies, and none of their controls sits inside the vendor's report. The systems a buyer should name in the scope question are the transcript store and the recording store, because those hold what was actually said.

Where AsqVox fits

SOC 2 is a procurement consideration for enterprise deployments rather than a product feature, so it is not something a widget has or does. The honest position for any early-stage vendor is the current state and the timeline, stated plainly, and that is the position taken here.

Visual

What a SOC 2 report actually covers

What a SOC 2 report actually coversScopeWhat it meansSecurityMandatoryProtection against unauthorized access. A report coveringsecurity alone is narrower than buyers assume.AvailabilityOptional, the organization choosesSystem uptime and accessibility commitments.Processing integrityOptional, the organization choosesComplete and accurate processing.ConfidentialityOptional, the organization choosesProtection of information designated as confidential.PrivacyOptional, the organization choosesHandling of personal information.Type IOne point in timeAn opinion that controls are suitably designed. A snapshot,faster and cheaper to obtain.Type IIA period, typically three to twelve monthsAn opinion that controls were suitably designed and operatedeffectively. What enterprise buyers generally want.Sub-processorsOutside the report boundaryA vendor's report covers the vendor. The speech recognition,language model and speech synthesis providers sit outside it.

Audited against described controls. Not a guarantee of security.

The scope section is the most important part of the report and the least read. A report can legitimately exclude systems a buyer cares about, and in voice the two systems to check by name are the transcript store and the recording store.

Statistics

Every figure carries its source and year. Vendor numbers are labelled as vendor numbers, and where no reliable figure exists this page says so rather than borrowing one.

SOC 2 reports are issued under the AICPA Trust Services Criteria by independent auditors.

AICPA Trust Services Criteriaindustry range

AICPA Trust Services Criteria, 2026 - A framework fact rather than a measurement. It is also the reason SOC 2 is an audit opinion rather than a certification, which is the distinction most often lost in a sales conversation.

Five criteria exist: security, availability, processing integrity, confidentiality and privacy. Security is mandatory and the other four are included at the election of the organization.

Five criteria, one mandatoryindustry range

AICPA Trust Services Criteria, 2026 - The election is the part buyers miss. A report covering security alone is a much narrower document than the name suggests, and nothing about the name says which criteria were chosen.

Type I addresses control design at a point in time. Type II addresses design and operating effectiveness over a period, commonly three to twelve months.

Three to twelve monthsindustry range

AICPA Trust Services Criteria, 2026 - The observation period is why a Type II cannot be produced quickly under sales pressure, and why a young vendor with a Type I should say which one it holds.

No published statistic exists for SOC 2 adoption among AI voice vendors, and no comparative data exists on how broad their report scopes are.

-no reliable figure

So a vendor claiming SOC 2 is standard in the category, or that it is rare, is asserting something nobody has measured.

Audit costs and timelines vary substantially by organization size and by auditor, and any figure quoted would be unreliable.

-no reliable figure

Obtain quotes rather than trusting a published number, including the refusal to publish one here. A cost figure in a glossary is a figure somebody made up.

Examples

In practice

A buyer receives a vendor's SOC 2 Type II report and reads the scope section. The transcript storage system is excluded, because it was migrated during the observation period. The report is valid and the exclusion is disclosed. The buyer asks for either an interim control description covering that system or an updated report. This is a normal, healthy procurement exchange, and it only happens when somebody reads the scope.

The everyday version

SOC 2 is an independent auditor confirming that a software company actually does what it claims about security, then writing that up. It is the report large buyers want in hand before they will sign. What it is not is a promise that nothing will ever fail, and it reaches only the systems named inside it.

Usage

Who says it

  • Enterprise procurement and vendor risk management, as a standard requirement.
  • Security and compliance teams at software vendors.
  • Sales teams, who meet it as a gate and sometimes overstate where they are with it.

Where it turns up

  • Usually in the same clause as security certifications, penetration testing, vulnerability management, incident response, sub-processor management and business continuity.
  • Frequently in the initial security questionnaire that decides whether a vendor proceeds at all.

Common misuse

  • Describing SOC 2 as a certification implying security. It is an audit opinion within a scope.
  • Claiming SOC 2 while holding only a Type I, without stating which.
  • Assuming a vendor's report extends to its sub-processors. It does not, and in a voice pipeline that gap has teeth.

Questions people ask

Is SOC 2 a certification?

No. It is an independent auditor's opinion on controls the organization itself described, issued under the AICPA Trust Services Criteria. There is no pass-or-fail badge. A report can carry exceptions and remain a valid report, which is why the exceptions and the scope section matter more than the existence of a report.

What is the difference between SOC 2 Type I and Type II?

Type I is an opinion on whether controls are suitably designed at a single point in time. Type II is an opinion on whether they were suitably designed and operated effectively over a period, commonly three to twelve months. Enterprise buyers generally want Type II. A Type I is a reasonable interim step for a young company and should be described as one rather than reported simply as SOC 2.

Does a vendor's SOC 2 report cover its sub-processors?

No. The report covers the vendor. In a voice pipeline the speech recognition, language model and speech synthesis providers are usually separate companies, and none of their controls is inside that report. What can be examined is how the vendor manages its sub-processors, which is itself a control.

What should I read first in a SOC 2 report?

The scope section. It is the most important part of the report and the least read, and a report can legitimately exclude systems you care about. In voice the systems to check by name are the transcript store and the recording store. Read the exceptions next.

Share this definition

Last reviewed 30 July 2026. Written and reviewed by Dhruv Dholakia, founder of AsqVox.