activeUnited States (AICPA)

SOC 2 (Service Organization Control 2)

SOC 2 is an AICPA auditing standard for service organizations, evaluating controls relevant to security, availability, processing integrity, confidentiality, and privacy. While not AI-specific, SOC 2 Type II reports are table stakes for B2B SaaS vendors — including AI governance platforms — and are frequently mapped to AI-specific risk frameworks.

Jurisdiction

United States (AICPA)

Enforcement

See overview

Maximum penalty

Varies by violation

Vendors that support SOC 2

Sorted by coverage level. Full coverage shown first.

5 vendors

VendorHQFoundedSizePricingCoverageLast verified
Scrut AutomationPalo Alto, US202151-200Contact for pricingComprehensiveApr 24, 2026
BraintrustSan Francisco, US202351-200Contact for pricingComprehensiveApr 24, 2026
WhyLabsSeattle, US201911-50Contact for pricingComprehensiveApr 24, 2026
DrataSan Francisco, US2020501-1000Contact for pricingComprehensiveApr 24, 2026
GiskardParis, France202111-50Contact for pricingComprehensiveApr 24, 2026

Compare across industries

See which vendors support SOC 2 in your sector.

Last verified April 24, 2026. Informational summary only — not legal advice. Consult qualified counsel for specific obligations.