← All articles
Growing in Sales

SOC 2 Type II for AI Vendors: What the Badge Actually Certifies

The badge is real. It just answers a narrower question than most buyers think.

Alan Tai, GTM Engineering & Strategy Intern, WingRep
GTM Engineering & Strategy Intern, WingRep
SOC 2 Type II for AI Vendors: What the Badge Actually Certifies

A SOC 2 Type II badge on a vendor's website tells you less than you think, and it tells you it about last year.

That is not an accusation. The badge is a real audit and it is expensive to earn. The problem is the gap between what it certifies and what a buyer reads into it. Most people see the logo and conclude "this vendor is secure." What the report says is that an auditor looked at controls the vendor picked, tested them over a window that has since closed, and wrote an opinion.

We hold SOC 2 Type II ourselves, so we have an obvious interest in you taking certifications seriously. We would rather you take them seriously for the right reasons.

What does SOC 2 Type II actually certify?

SOC 2 Type II certifies that an independent auditor tested a set of controls at one company over a defined window and formed an opinion on whether those controls operated effectively during that window. The opinion covers a period that has already ended, not the state of the product on the day you read the badge.

The framework comes from the AICPA. The control criteria are published as the Trust Services Criteria, first issued in 2017 with revised points of focus in 2022. A CPA firm performs the examination and issues an attestation report.

A few things follow from that structure, and they all get lost in translation.

The window matters. Type II reports cover an observation period, commonly three to twelve months. A report with a period ending in September 2025 says nothing about what happened in 2026. Ask for the period, not just the logo.

The scope is chosen. More on this below, because it is the part buyers skip.

It is an opinion, not a pass/fail stamp. Reports can and do contain exceptions, which are instances where a control did not operate as described. A vendor with a clean opinion and a vendor with three noted exceptions both get to put the same badge on the same website.

What is the difference between SOC 2 Type I and Type II?

Type I asks whether the controls are designed appropriately as of a single date. Type II asks whether those controls actually operated effectively across a period of time. Type I is a photograph, Type II is a recording. A vendor that only has Type I has described its controls to an auditor and had the description reviewed, and nothing more.

Type I is a reasonable milestone for a young company. It is often the first report a startup gets, because you can earn one before you have a full observation window behind you. The difference between the two is set out in the AICPA's SOC 2 guidance for service organizations, which is worth a skim if you are the person on the buying side signing off on vendor risk.

What you should not accept is a vendor saying "we're SOC 2 compliant" and letting you assume Type II. Ask which one. Ask when the Type II period ends if they are mid-window. Both are fair questions and both get answered honestly by vendors who are not hiding anything.

Who decides what gets audited?

The vendor does, within limits. Security is the one required criterion in every SOC 2 examination. Availability, processing integrity, confidentiality and privacy are optional, and a company selects which of them to include. It also defines the system boundary: which products, which environments, which parts of the company are in scope.

This is the single most useful thing to understand about the certification, and it is why "SOC 2 Type II" on its own is not an answer to a security question.

Two vendors can both be SOC 2 Type II and have audited very different things. One might have scoped in its entire production platform against all five criteria. The other might have scoped security only, on one product, excluding a newly acquired service. Both badges look identical.

So the follow-up question is not "are you SOC 2." It is:

  • Which trust services criteria were in scope?
  • What was the system boundary, and does it include the product I am buying?
  • What was the observation period?
  • Were there any exceptions, and what did management say about them?

Any vendor with a report in hand can answer all four in a two-minute email. If yours cannot, that is information.

Is ISO 27001 the same thing?

No, and it is worth knowing why, because buyers often treat the two as interchangeable badges. ISO/IEC 27001 certifies an information security management system against an international standard, issued by an accredited certification body with surveillance audits over a three-year cycle. SOC 2 is an attestation report from a CPA firm about controls at one service organization.

The practical differences that matter to a buyer:

SOC 2 Type IIISO/IEC 27001
What it coversControls relevant to the trust services criteria in scopeA management system for information security
Who issues itA licensed CPA firmAn accredited certification body
What you receiveA detailed report, usually under NDAA certificate, plus a Statement of Applicability
RenewalNew report each observation periodThree-year cycle with surveillance audits
GeographyDominant in North American procurementDominant in European and global procurement

Holding both is common for vendors selling into enterprise, and it is a reasonable signal that the security program is a program rather than a project. It is still not a description of what happens to your data.

What does an AI vendor security review ask for now?

The questions changed once vendors started sending customer data to model providers. A 2026 AI vendor review asks about subprocessors, the data processing addendum, whether customer data is used to train models, where data is stored, and how long it is kept. Certifications get checked in the first five minutes. The rest of the review is about data flow.

Here is what a serious reviewer sends over, and what a good answer looks like.

The subprocessor list. Every third party that touches customer data, what each one processes, and where it sits. For an AI product this includes the model providers, which is the row people actually care about. Under Article 28 of the GDPR, a processor cannot engage another processor without the controller's written authorisation, and where that authorisation is general the processor has to notify the controller of additions and give it a chance to object. A vendor with no published list and no notification policy has a contract problem, not just a documentation problem.

The DPA. A countersignable data processing addendum, with the standard contractual clauses attached if data leaves the EEA. Ask whether they will sign yours or only theirs.

Model training. The question every AI review now leads with: is customer data used to train models, including the model provider's models? The only acceptable answer is a single unambiguous sentence, backed by the contractual commitment the vendor holds from its own model providers. Hedged language here is the loudest signal in the whole review.

Data residency. Where recordings, transcripts and derived data are stored, and whether regional options exist. "US only" is an answer. "Our cloud provider is global" is not.

Retention and deletion. How long each data type is kept, what deletion on termination looks like, how long it takes, and whether it covers backups and derived artifacts like embeddings and summaries. Derived data is where most retention policies quietly stop applying.

Access controls on the human side. Who at the vendor can read your call recordings, under what circumstances, and whether that access is logged.

None of those six are covered by the fact of a SOC 2 badge. Some may be covered inside the report, depending on scope. You will not know which without reading it.

What should you actually ask for?

Ask for the report under NDA, the observation period, the scope, the subprocessor list, the DPA and a written answer on model training. That set takes a vendor under an hour to produce if the program is real and weeks if it is not, which makes the response time itself a useful measurement.

A short version you can paste into an email:

  1. Please send the most recent SOC 2 Type II report under NDA, including the observation period and any noted exceptions.
  2. Which trust services criteria were in scope, and does the system boundary include the product we are evaluating?
  3. Where is your current subprocessor list published, and what is your change notification policy?
  4. Will you sign a DPA, and do you accept ours?
  5. Is customer data used to train any model, yours or a provider's? A yes or no, then the detail.
  6. Where is data stored, how long is it retained, and what is deleted on termination?

One more thing worth saying, since this is a sales blog and the same dynamic shows up on the other side of the table. If you sell software, the buyer asking these questions is doing you a favor. They are telling you exactly what has to be true for the deal to close. Reps who treat the security review as an obstacle lose weeks. Reps who have the answers in a folder before the first call do not.

Where does WingRep fit?

WingRep holds SOC 2 Type II, and the details live on our trust page rather than being scattered through marketing copy.

The reason we publish it as its own page instead of a badge in a footer is the argument above. A logo answers nothing. A page with the certifications, the subprocessor list and the DPA on it answers the questions a reviewer actually has, and it means the person evaluating us can do their job without waiting on a sales cycle. We publish pricing for the same reason.

If you are comparing us against other tools in this category, the security questions are the same for all of them, and we wrote up the rest of the comparison in WingRep vs Gong and WingRep vs notetakers. Ask every vendor on your list the six questions above. The variation in the answers will tell you more than any feature grid.


Common questions

Does SOC 2 Type II mean a vendor is secure?

No. It means an auditor tested a set of controls the vendor selected, over a period that has already closed, and issued an opinion on whether they operated effectively. Scope, observation period and exceptions all vary between reports carrying the identical badge.

How long is a SOC 2 Type II report valid?

There is no formal expiry, but the report covers a specific observation period and most buyers treat anything older than twelve months as stale. Vendors on a continuous program produce a new report each period, often with a bridge letter covering the gap between the period end and today.

What is the difference between SOC 2 Type 1 and Type 2?

Type I evaluates whether controls are suitably designed as of one date. Type II evaluates whether they operated effectively over a period of time, usually three to twelve months. Type II is the one enterprise procurement asks for.

Do I need both SOC 2 and ISO 27001 from a vendor?

It depends on where you operate. North American procurement leans on SOC 2, European and global procurement leans on ISO 27001. Vendors selling into both usually hold both. Neither one tells you whether your data trains a model, which is a separate question you have to ask directly.

Should an AI vendor publish its subprocessor list?

Yes. Under GDPR Article 28 a processor needs written authorisation to engage subprocessors, and general authorisation requires notifying the controller of changes so it can object. A published list with a change policy is the practical way to meet that, and gating it behind a form defeats the purpose.


Sources

  • AICPA, 2017 Trust Services Criteria (with revised points of focus, 2022): aicpa-cima.com
  • AICPA, SOC 2 for service organizations resources: aicpa-cima.com
  • ISO/IEC 27001:2022, Information security management systems: iso.org
  • GDPR Article 28, Processor: gdpr-info.eu
Share this articleXLinkedInFacebookemail

Keep reading

Types of Salespeople: What the Evidence Actually Supports
Growing in Sales

Types of Salespeople: What the Evidence Actually Supports

AI is a GPT! (“General Purpose Technology”)
Growing in Sales

AI is a GPT! (“General Purpose Technology”)

Building a Challenger Sales Culture
Book Series: The Challenger Sale

Building a Challenger Sales Culture