SOC 2
SOC 2 is an auditable security framework (Type I = point in time, Type II = sustained over months) that customers — especially enterprises — require before trusting a vendor with their data.
SOC 2 is table stakes for selling AI software to enterprise. The five trust principles (security, availability, processing integrity, confidentiality, privacy) translate to controls: access reviews, encryption, logging, incident response, vendor management. AI vendors specifically must extend SOC 2 controls to their model providers via DPAs.
Example
Acme requires every AI vendor to be SOC 2 Type II before approving them. The AI vendor's report includes its sub-processors (Anthropic, OpenAI, Pinecone) so the chain of custody is auditable end-to-end.
How OpenLabor uses it
OpenLabor maintains SOC 2 Type II and shares the report under NDA on request.
Is SOC 2 the same as ISO 27001?
Different frameworks, overlapping controls. SOC 2 is more common in US enterprise sales; ISO 27001 in international markets.
Related: audit-trail, data-residency, role-based-access.
AI Labor Glossary