Private GPT

· 6 min read

SOC 2 Compliant AI Assistant

Is a private AI assistant SOC 2 compliant? What a SOC 2 report actually certifies, what it does not, and the questions to ask before you trust it.

Is a private AI assistant SOC 2 compliant? SOC 2 is not a checkbox a product either has or lacks. It is an independent auditor's report on the controls a specific vendor ran, over a specific service, during a specific period. A vendor can be honest about holding one and still leave your review incomplete, because a report answers questions about that vendor's own operations, not about how the deployment your team actually uses is scoped, configured, or connected to your data. Treat a SOC 2 claim as the start of a review, not the end of one.

What a SOC 2 report actually covers

A SOC 2 report is produced by an independent auditor who tests a vendor's controls against the trust service criteria the vendor selected for the engagement, typically security and some combination of availability, processing integrity, confidentiality, and privacy. A Type I report says the controls were designed appropriately as of one date. A Type II report says the auditor tested those controls over a period, usually several months to a year, and found they operated as described. The two are not interchangeable, and the difference matters more than most vendor one-pagers make it sound.

Why 'are you SOC 2 compliant' is the wrong question

A yes or no answer to that question tells your reviewer almost nothing. The report that matters is the one covering the exact service you would actually use, for the period you need, issued against criteria that match what you are trying to verify. A vendor can hold a valid report for one product line while the AI feature you want sits outside its scope entirely. The useful question is not whether a report exists. It is whether the vendor will produce the current report, typically under a mutual NDA, so your security team can read the scope, the exceptions, and the auditor's opinion themselves.

What a private deployment can document for your review

  • A defined boundary for the deployment, so your reviewers know exactly what system the report and the architecture describe
  • A documented list of subprocessors and model providers that can see request data, and what each one's own agreement says
  • Role based access configured to your org chart, reviewable line by line instead of taken on faith
  • Retention and logging settings scoped to your policy, with audit data available to your security team
  • Written architecture your reviewers can walk through request by request, not a diagram on a marketing page

What a report alone does not solve

A SOC 2 report is a snapshot of a past period, not a live guarantee about today. It typically does not automatically extend to every subprocessor a vendor uses, and a change to the vendor's stack after the audit period is not something the report reflects until the next cycle. Reading the report is still your organization's job, not the vendor's marketing claim about it. A dedicated deployment gives your reviewers something concrete to check the report against. It does not replace reading the report, and it does not replace your own vendor risk process.

Questions to bring to your vendor security review

  • Is this a Type I or Type II report, and what period does it cover
  • Which trust service criteria are included, and do they match what we are trying to verify
  • Will you provide the current report under NDA, rather than a badge or a summary page
  • Does the report's boundary include the specific product or deployment we would use
  • Which subprocessors and model providers fall inside the audited scope, and which do not
  • Is there a bridge letter covering the gap between the report date and today

None of this turns a SOC 2 report into an automatic pass, and a vendor who treats the label as the whole answer should be the first thing your security reviewer questions. What it does is give your organization something to check against a documented deployment instead of a badge on a page. Book a meeting to walk through your vendor security review, the reports and documentation you will need, and how the deployment would be scoped.

Ready to own your AI?

Book a meeting to see a live private deployment and talk through your team, data sources, requirements, and pricing.

Book a meeting