GLOSSARY
SOC 2
By Sygnet Research. Written by Sygnet, sourced, checked before publication.
SOC 2 is an audit standard from the American Institute of Certified Public Accountants (AICPA) that evaluates how a service provider manages customer data across five criteria: security, availability, processing integrity, confidentiality, and privacy. A SOC 2 report tells a prospective customer whether a vendor's internal controls, not just its marketing claims, hold up to independent scrutiny. For document AI vendors, it's the baseline evidence that sensitive files (contracts, invoices, ID documents) are handled with real safeguards rather than good intentions.
How it works
An independent auditor examines a vendor's actual controls: access management, encryption practices, incident response, change management, vendor risk management, and more. There are two report types. Type I checks whether controls are designed properly at a single point in time. Type II checks whether those controls actually operated effectively over a period, usually six to twelve months. Type II is the stronger signal, since it tests behavior over time rather than a snapshot.
Vendors choose which of the five "trust services criteria" to include; security is mandatory, the rest are optional depending on what the service does. A company processing invoices or KYC documents should reasonably be expected to cover confidentiality and privacy alongside security, since the data at stake is often personal or financial.
The report itself is not public. Vendors share it under NDA with prospective or existing customers, along with a bridge letter if the audit period has lapsed. Buyers should read the actual report, not just a badge on a website: the scope section defines exactly which systems and processes were tested, and gaps outside that scope matter.
SOC 2 is a US-centric framework built on AICPA standards, distinct from ISO 27001 (international) or GDPR (EU legal obligation), though the practical controls often overlap.
Why it matters for document processing
Document processing systems touch identity documents, contracts, invoices, and claims, all of which can contain sensitive personal or financial data. A SOC 2 report gives a buyer independently verified evidence that the vendor's access controls, encryption, and monitoring meet a recognized bar, rather than relying on a sales deck.
For regulated workflows like KYC onboarding or AML checks, procurement teams often require SOC 2 Type II as a contractual gate before a vendor is even considered. It doesn't replace GDPR compliance or data residency guarantees, which are separate legal and architectural questions, but it does demonstrate operational discipline: who can access data, how incidents get handled, how changes to production systems are controlled. Combined with practices like zero data retention, SOC 2 gives a fuller picture of how a document AI vendor actually protects the files running through its pipelines.
Related terms
- Security and compliance
- Zero data retention
- Data residency
- GDPR and document processing
- KYC onboarding
FAQ
Is SOC 2 the same as GDPR compliance?
No. SOC 2 is a voluntary US audit standard focused on operational controls; GDPR is an EU legal framework governing personal data rights and obligations. A vendor can hold SOC 2 certification and still fail to meet GDPR requirements on data residency or lawful basis for processing. Ask for both, not one as a substitute for the other.
Why does Type II matter more than Type I?
Type I confirms controls are designed correctly on a single audit date. Type II confirms those controls actually worked as intended over an extended period, typically six months or longer. For document processing, where data flows continuously, Type II gives a much more reliable signal that the vendor's security practices hold up under real, sustained operation.
NEXT STEP
See it on your own documents
One email when we publish something worth your time.