AI vendors with SOC 2 Type I attestation
AI vendors with a SOC 2 Type I attestation — controls in place at a point in time. Less comprehensive than Type II but a meaningful baseline for early-stage vendors.
SOC 2 Type I attests that an organisation has documented security and operational controls in place at a single point in time. SOC 2 Type II goes further by testing whether those controls operated effectively over a period (typically 6-12 months). Type I is a common starting point for early-stage vendors pursuing the full Type II certification; enterprise buyers generally prefer Type II but will accept Type I plus a remediation plan for vendors clearly on the path.
Vendors with SOC 2 Type I
Anthropic
Score 11.44 · low
Amazon (AWS)
Score 12.34 · low
Salesforce
Score 12.74 · low
Adobe
Score 13.74 · low
Cohere
Score 13.79 · low
IBM
Score 14.11 · low
Microsoft
Score 14.68 · low
SAP
Score 16.63 · low
OpenAI
Score 18.36 · low
Google DeepMind
Score 18.85 · low
Oracle
Score 19.89 · low
Palo Alto Networks
Score 19.89 · low
Mistral AI
Score 21.81 · moderate
AI21 Labs
Score 22.34 · moderate
Workday
Score 22.45 · moderate
Nvidia
Score 22.63 · moderate
Scale AI
Score 23.3 · moderate
Hugging Face
Score 24.05 · moderate
ServiceNow
Score 24.4 · moderate
Datadog
Score 24.41 · moderate
Palantir
Score 25.09 · moderate
Cloudflare
Score 25.89 · moderate
Stripe
Score 29.97 · moderate
Weights & Biases
Score 31.11 · moderate
Anyscale
Score 31.15 · moderate
Pinecone
Score 31.15 · moderate
Naver
Score 31.18 · moderate
Twilio
Score 31.65 · moderate
Meta AI
Score 32.15 · moderate
Weaviate
Score 32.35 · moderate
Together AI
Score 32.37 · moderate
LangChain
Score 33.29 · moderate
Runway
Score 33.61 · moderate
ElevenLabs
Score 37.76 · moderate
Alibaba Cloud
Score 42.24 · elevated
Buyer checklist
- Confirm whether this is Type I or Type II — Type I is a point-in-time snapshot, not effectiveness over time.
- Ask when the Type II audit is scheduled to complete (most vendors move from I to II within 12 months).
- Verify the scope statement covers the specific service you intend to use.
- Request the report under NDA; review the management response and any exceptions noted.
- For Type I-only vendors, layer compensating controls into your contract (audit rights, incident notification SLAs).
Compliance is necessary, not sufficient. Holding SOC 2 Type I is a meaningful baseline, but no certification covers AI-specific risk end-to-end. Layer this on top of vendor-specific diligence — sub-processor disclosure, training-data policy, model card transparency, dependency-chain mapping.