Glossary · Trust

What Is a Trust Service Criteria? (SOC 2 Context)

A trust service criteria is one of five defined categories — Security, Availability, Processing Integrity, Confidentiality, and Privacy — that a SOC 2 audit can be scoped against; only Security is mandatory in every SOC 2 report, and the other four are optional, chosen by the organization being audited.

The five trust service criteria, defined plainly

Security covers protection against unauthorized access, both physical and logical — this is the one mandatory criterion in every SOC 2 report. Availability covers whether systems are accessible and operational as committed or agreed. Processing Integrity covers whether system processing is complete, valid, accurate, timely, and authorized — essentially, does the system do what it is supposed to do correctly. Confidentiality covers whether information designated as confidential is protected as committed or agreed. Privacy covers how personal information is collected, used, retained, disclosed, and disposed of, relative to an organization’s stated privacy notice and applicable criteria.

Why only Security is mandatory

A SOC 2 audit’s scope is a negotiated choice between the audited organization and its auditor, built around which criteria are relevant to the specific service being assessed and what the organization’s customers actually need assurance about. Security is mandatory because it is considered foundational — the other four criteria layer additional, more specific assurances on top of that baseline, and an organization only includes them if it is prepared to have an auditor test controls in that specific area.

Why a bare "we have SOC 2" claim is incomplete

Because only Security is required, two vendors can each truthfully say "we have a SOC 2 report" while one was audited against Security alone and the other was audited against Security, Availability, and Confidentiality — materially different scopes of assurance hiding behind the same three-word claim. A vendor’s SOC 2 claim should specify which criteria were actually included in the audit scope; a report scoped to Security alone says nothing directly about, for example, an organization’s Availability commitments.

How this connects to Type 1 vs. Type 2

The trust service criteria answer "what was tested"; Type 1 vs. Type 2 answers "how rigorously and over what period." A Type 1 report assesses whether controls for the chosen criteria are suitably designed as of a specific date — a design snapshot. A Type 2 report assesses whether those same controls actually operated effectively over an observation period, typically several months to a year, based on evidence the auditor tested. Both dimensions — which criteria, and which type — need to be confirmed together to understand what a specific SOC 2 report is actually evidence of.

Where Voz360 stands

Voz360 has not completed a SOC 2 audit of any type and makes no SOC 2 claim, implied or explicit. Voz360’s hash-chained audit log, per-tenant AES-256-GCM encryption, and role-based access control are the kind of technical controls a SOC 2 audit under the Security criterion would typically examine — that is a description of current control-level posture, not a claim that an audit has occurred. A buyer for whom a completed SOC 2 report against specific criteria is a hard requirement should treat that as an open item to confirm directly.

The practical test

Can the vendor tell you — in one sentence — which of their AI capabilities are rule-based, which are generative, and which are still roadmap?

Questions, answered

What enterprise buying teams want to know.

Self-contained answers, so the questions a security or procurement reviewer asks first don't require reading the whole page.

What are the five SOC 2 trust service criteria?

Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is mandatory in every SOC 2 report; the other four are optional and chosen by the organization being audited based on what is relevant to the specific service.

Is a SOC 2 report always scoped to all five criteria?

No. Only Security is mandatory. An organization can complete a SOC 2 audit scoped to Security alone, or add any combination of Availability, Processing Integrity, Confidentiality, and Privacy — which is why a vendor’s SOC 2 claim should specify which criteria were actually included.

Has Voz360 completed a SOC 2 audit against any trust service criteria?

No. Voz360 has not completed a SOC 2 audit of any type and makes no SOC 2 claim. Its audit logging, encryption, and access-control mechanisms are the kind of controls a Security-criterion audit would typically examine, but that is a description of control-level posture, not a claim that an audit has taken place.

Does adding more trust service criteria to a SOC 2 audit make a vendor more trustworthy?

It means more of that vendor’s controls were independently tested by an auditor, which is generally stronger evidence than a narrower scope — but a buyer should still confirm which specific criteria were included and read the report’s scope section rather than treating the SOC 2 label alone as sufficient.

Talk to Voz360

Make the next decision with more signal.

Bring the guide, the questions, and the real deployment constraints to a Voz360 session.