The five trust service criteria, defined plainly
Security covers protection against unauthorized access, both physical and logical — this is the one mandatory criterion in every SOC 2 report. Availability covers whether systems are accessible and operational as committed or agreed. Processing Integrity covers whether system processing is complete, valid, accurate, timely, and authorized — essentially, does the system do what it is supposed to do correctly. Confidentiality covers whether information designated as confidential is protected as committed or agreed. Privacy covers how personal information is collected, used, retained, disclosed, and disposed of, relative to an organization’s stated privacy notice and applicable criteria.
Why only Security is mandatory
A SOC 2 audit’s scope is a negotiated choice between the audited organization and its auditor, built around which criteria are relevant to the specific service being assessed and what the organization’s customers actually need assurance about. Security is mandatory because it is considered foundational — the other four criteria layer additional, more specific assurances on top of that baseline, and an organization only includes them if it is prepared to have an auditor test controls in that specific area.
Why a bare "we have SOC 2" claim is incomplete
Because only Security is required, two vendors can each truthfully say "we have a SOC 2 report" while one was audited against Security alone and the other was audited against Security, Availability, and Confidentiality — materially different scopes of assurance hiding behind the same three-word claim. A vendor’s SOC 2 claim should specify which criteria were actually included in the audit scope; a report scoped to Security alone says nothing directly about, for example, an organization’s Availability commitments.
How this connects to Type 1 vs. Type 2
The trust service criteria answer "what was tested"; Type 1 vs. Type 2 answers "how rigorously and over what period." A Type 1 report assesses whether controls for the chosen criteria are suitably designed as of a specific date — a design snapshot. A Type 2 report assesses whether those same controls actually operated effectively over an observation period, typically several months to a year, based on evidence the auditor tested. Both dimensions — which criteria, and which type — need to be confirmed together to understand what a specific SOC 2 report is actually evidence of.
Where Voz360 stands
Voz360 has not completed a SOC 2 audit of any type and makes no SOC 2 claim, implied or explicit. Voz360’s hash-chained audit log, per-tenant AES-256-GCM encryption, and role-based access control are the kind of technical controls a SOC 2 audit under the Security criterion would typically examine — that is a description of current control-level posture, not a claim that an audit has occurred. A buyer for whom a completed SOC 2 report against specific criteria is a hard requirement should treat that as an open item to confirm directly.
Can the vendor tell you — in one sentence — which of their AI capabilities are rule-based, which are generative, and which are still roadmap?