Type 1 vs. Type 2: a point-in-time snapshot vs. a period of actual operation
A SOC 2 Type 1 report assesses whether an organization’s controls are suitably designed as of a specific date — it is a design review, not proof the controls actually worked over time. A SOC 2 Type 2 report assesses whether those controls operated effectively over an observation period, typically several months to a year, based on evidence the auditor actually tested — meaningfully stronger evidence than Type 1. A buyer comparing two vendors’ SOC 2 claims should always ask which type, and for what observation period, since the two are not equivalent evidence despite sharing the "SOC 2" label.
The five trust service criteria, and that only one is mandatory
SOC 2 reports are scoped against up to five trust service criteria: Security (mandatory in every SOC 2 report), Availability, Processing Integrity, Confidentiality, and Privacy. An organization chooses which of the optional four to include in its audit scope. A vendor stating simply "we have SOC 2" without specifying which criteria were included is giving a buyer materially incomplete information — a report scoped to Security alone says nothing directly about, for example, Availability commitments.
What a SOC 2 report is evidence of, precisely
A SOC 2 report demonstrates that an independent, licensed CPA firm reviewed a defined set of controls against a defined criteria set, for a defined period, and reached a specific opinion (unqualified, qualified, or adverse) about whether those controls were suitably designed and, for Type 2, operating effectively. It is not evidence that the organization has no security incidents, that every system in the company is in scope (audits frequently cover a specific product or environment, not the whole company), or that the controls reviewed match what a specific buyer’s own risk assessment requires.
What SOC 2 does not test, and why that matters to a buyer
A SOC 2 audit does not certify compliance with a specific regulatory framework (HIPAA, PCI-DSS, GDPR) even though its control evidence often overlaps usefully with those frameworks’ requirements — it is a distinct thing from those certifications, not a superset of them. It also does not guarantee the vendor’s product architecture is sound, only that the specific in-scope controls were reviewed. A buyer should read the actual report (or at minimum, the auditor’s opinion and scope section) rather than treating the SOC 2 label alone as sufficient due diligence.
What Voz360 provides today, and what it does not claim
Voz360 has not completed a SOC 2 audit of any type, and makes no SOC 2 claim, implied or explicit. Voz360’s hash-chained audit log, per-tenant AES-256-GCM encryption, and role-based access control are the kind of technical controls a SOC 2 audit under the Security criterion would typically examine — stating that is a description of current control-level posture, not a claim that an audit has occurred. A buyer for whom a completed SOC 2 report is a hard requirement should treat that as an open item to confirm directly, not assume based on the existence of these controls. This article is general information, not legal or audit advice; confirm a specific vendor’s current audit and certification status directly with that vendor.
Can the vendor tell you — in one sentence — which of their AI capabilities are rule-based, which are generative, and which are still roadmap?