SOC 2
SOC 2 is an auditing framework developed by the American Institute of CPAs (AICPA) that evaluates an organization's information systems on five trust service criteria: security, availability, processing integrity, confidentiality, and privacy. A SOC 2 report provides assurance to customers that a service organization manages data with appropriate controls.
Why It Matters
SOC 2 audits are table stakes for B2B SaaS companies. Enterprise buyers routinely require a current SOC 2 Type II report before signing contracts, making the audit cycle a commercial prerequisite, not a compliance bonus.
For organizations deploying AI agents, SOC 2 creates a specific challenge: auditors ask "how do you govern AI?" and existing controls built for human access do not answer the question. Agent governance systems that produce immutable audit trails, enforce deterministic policies, and log every tool call provide the evidence auditors need.
SOC 2 reports come in two types: Type I evaluates controls at a point in time; Type II evaluates controls over a period (typically 6-12 months). Type II is what buyers and auditors require for meaningful assurance.