SOC 2 for AI and software companies
SOC 2 is the report most SaaS buyers ask for first. It covers how you handle security, availability, processing integrity, confidentiality, and privacy.
Which edition this covers
2017 Trust Services Criteria, with the revised points of focus issued in 2022
Checked against the source on 2026-09-13 · read the source
Not covered
- The 2016 Trust Services Principles and Criteria, which the 2017 criteria replaced.
- SOC 1 (ICFR) and SOC 3, which are different reports against different criteria.
- The Type II observation period itself. Mapping addresses criteria, not the operating effectiveness an auditor tests over time.
What Trooth witnesses
Read on a schedule, republished with the date
- Encryption in transit and at rest, read from your live endpoints
- Access and authentication posture on the systems you connect
- Audit logging and retention settings where your providers expose them
- Your published sub-processors, incident channel, and data-deletion commitments
What Trooth does not do
Said plainly, so nobody guesses
- Issue a certification, attestation, or audit opinion. Only a licensed auditor can do that.
- Replace a SOC 2 Type II audit or the evidence collection an auditor requires.
- Give legal advice or tell you whether you are compliant. That call is yours and your counsel's.
Why this is worth anything to a buyer
A questionnaire answer is a claim typed once and never checked again. SOC 2 here is the rulebook, not the product: what Trooth publishes for it is read from your live systems on a schedule and republished with the date it was last seen, so a buyer checking your company can tell the difference between what was true a year ago and what is true this morning. That is a smaller promise than an audit, and it is one we can actually keep. The full method is on the methodology page.