Guide · Compliance Beyond HIPAA

SOC 2: what it actually tests, and what it doesn’t.

A SOC 2 report is an independent auditor’s assessment of a service organization’s controls against a defined set of trust service criteria — it is real, useful evidence, but it is narrower and more conditional than the badge alone communicates. Voz360 has not completed a SOC 2 audit and makes no SOC 2 claim. This article is general information, not legal advice. Confirm current requirements with qualified counsel before making a compliance decision.

Type 1 vs. Type 2: a point-in-time snapshot vs. a period of actual operation

A SOC 2 Type 1 report assesses whether an organization’s controls are suitably designed as of a specific date — it is a design review, not proof the controls actually worked over time. A SOC 2 Type 2 report assesses whether those controls operated effectively over an observation period, typically several months to a year, based on evidence the auditor actually tested — meaningfully stronger evidence than Type 1. A buyer comparing two vendors’ SOC 2 claims should always ask which type, and for what observation period, since the two are not equivalent evidence despite sharing the "SOC 2" label.

The five trust service criteria, and that only one is mandatory

SOC 2 reports are scoped against up to five trust service criteria: Security (mandatory in every SOC 2 report), Availability, Processing Integrity, Confidentiality, and Privacy. An organization chooses which of the optional four to include in its audit scope. A vendor stating simply "we have SOC 2" without specifying which criteria were included is giving a buyer materially incomplete information — a report scoped to Security alone says nothing directly about, for example, Availability commitments.

What a SOC 2 report is evidence of, precisely

A SOC 2 report demonstrates that an independent, licensed CPA firm reviewed a defined set of controls against a defined criteria set, for a defined period, and reached a specific opinion (unqualified, qualified, or adverse) about whether those controls were suitably designed and, for Type 2, operating effectively. It is not evidence that the organization has no security incidents, that every system in the company is in scope (audits frequently cover a specific product or environment, not the whole company), or that the controls reviewed match what a specific buyer’s own risk assessment requires.

What SOC 2 does not test, and why that matters to a buyer

A SOC 2 audit does not certify compliance with a specific regulatory framework (HIPAA, PCI-DSS, GDPR) even though its control evidence often overlaps usefully with those frameworks’ requirements — it is a distinct thing from those certifications, not a superset of them. It also does not guarantee the vendor’s product architecture is sound, only that the specific in-scope controls were reviewed. A buyer should read the actual report (or at minimum, the auditor’s opinion and scope section) rather than treating the SOC 2 label alone as sufficient due diligence.

What Voz360 provides today, and what it does not claim

Voz360 has not completed a SOC 2 audit of any type, and makes no SOC 2 claim, implied or explicit. Voz360’s hash-chained audit log, per-tenant AES-256-GCM encryption, and role-based access control are the kind of technical controls a SOC 2 audit under the Security criterion would typically examine — stating that is a description of current control-level posture, not a claim that an audit has occurred. A buyer for whom a completed SOC 2 report is a hard requirement should treat that as an open item to confirm directly, not assume based on the existence of these controls. This article is general information, not legal or audit advice; confirm a specific vendor’s current audit and certification status directly with that vendor.

The practical test

Can the vendor tell you — in one sentence — which of their AI capabilities are rule-based, which are generative, and which are still roadmap?

Questions, answered

What enterprise buying teams want to know.

Self-contained answers, so the questions a security or procurement reviewer asks first don't require reading the whole page.

Has Voz360 completed a SOC 2 audit?

No. Voz360 has not completed a SOC 2 audit of any type and makes no SOC 2 claim. Voz360’s audit logging, encryption, and access-control mechanisms are the kind of controls a SOC 2 Security-criterion audit would typically examine, but that is a description of control-level posture, not a claim that an audit has taken place.

What is the difference between SOC 2 Type 1 and Type 2?

Type 1 assesses whether controls are suitably designed as of a specific date — a design snapshot. Type 2 assesses whether those controls actually operated effectively over an observation period (typically several months to a year) based on tested evidence — meaningfully stronger evidence. The two are not equivalent despite sharing the "SOC 2" label.

Which trust service criteria are included in every SOC 2 report?

Only Security is mandatory. Availability, Processing Integrity, Confidentiality, and Privacy are optional and chosen by the audited organization — a vendor’s SOC 2 claim should specify which criteria were actually included in scope.

Does a SOC 2 report certify HIPAA, PCI-DSS, or GDPR compliance?

No. SOC 2 is a distinct audit against its own trust service criteria. Its control evidence often overlaps usefully with what those other frameworks require, but a SOC 2 report is not itself a certification of compliance with any of them.

Talk to Voz360

Make the next decision with more signal.

Bring the guide, the questions, and the real deployment constraints to a Voz360 session.