AI vendors with SOC 2 Type II
AI vendors with a SOC 2 Type II audit attestation, demonstrating ongoing operational effectiveness of security and availability controls.
SOC 2 Type II is the most common security attestation enterprise buyers ask for during AI vendor diligence. It indicates that an independent auditor has tested the vendor's controls over an observation period (typically 6-12 months) and reported on their effectiveness. A current Type II report is table stakes for most regulated industries and a strong signal of security maturity. The vendors below have a public Type II attestation according to TrustAtlas's most recent verification.
Vendors with SOC 2 Type II
Anthropic
Score 11.44 · low
Amazon (AWS)
Score 12.34 · low
Salesforce
Score 12.74 · low
Adobe
Score 13.74 · low
Cohere
Score 13.79 · low
IBM
Score 14.11 · low
Microsoft
Score 14.68 · low
SAP
Score 16.63 · low
OpenAI
Score 18.36 · low
Google DeepMind
Score 18.85 · low
Oracle
Score 19.89 · low
Palo Alto Networks
Score 19.89 · low
Nuance (Microsoft)
Score 20.86 · moderate
Writer
Score 20.93 · moderate
AI21 Labs
Score 22.34 · moderate
Workday
Score 22.45 · moderate
Mosaic (Databricks)
Score 22.6 · moderate
Nvidia
Score 22.63 · moderate
SentinelOne
Score 22.96 · moderate
Scale AI
Score 23.3 · moderate
Hugging Face
Score 24.05 · moderate
Snowflake
Score 24.36 · moderate
ServiceNow
Score 24.4 · moderate
Datadog
Score 24.41 · moderate
SambaNova
Score 24.5 · moderate
PolyAI
Score 24.72 · moderate
Palantir
Score 25.09 · moderate
Databricks
Score 25.4 · moderate
Cloudflare
Score 25.89 · moderate
Slack
Score 26.47 · moderate
GitHub Copilot
Score 27.12 · moderate
Vanta
Score 27.24 · moderate
Zoom
Score 27.35 · moderate
Atlassian
Score 28.51 · moderate
Synthesia
Score 29.28 · moderate
Kensho (S&P Global)
Score 29.4 · moderate
Khanmigo (Khan Academy)
Score 29.49 · moderate
Casetext
Score 29.77 · moderate
CoreWeave
Score 29.93 · moderate
Stripe
Score 29.97 · moderate
Harvey
Score 30.27 · moderate
LexisNexis
Score 30.29 · moderate
Arize AI
Score 30.6 · moderate
Grammarly
Score 30.74 · moderate
Moveworks
Score 30.84 · moderate
Zendesk
Score 30.94 · moderate
Galileo
Score 30.97 · moderate
Bloomberg
Score 31.1 · moderate
Weights & Biases
Score 31.11 · moderate
Anyscale
Score 31.15 · moderate
Buyer checklist
- Request the most recent SOC 2 Type II report under NDA before contracting.
- Confirm the observation window covers at least the past 12 months.
- Read the auditor's exceptions section — every report has them; the question is severity.
- Verify the trust services criteria in scope (Security is required; Availability and Confidentiality are usually included; Privacy and Processing Integrity are optional).
- Ask for the vendor's plan to address any exceptions in the next attestation cycle.
Compliance is necessary, not sufficient. Holding SOC 2 Type II is a meaningful baseline, but no certification covers AI-specific risk end-to-end. Layer this on top of vendor-specific diligence — sub-processor disclosure, training-data policy, model card transparency, dependency-chain mapping.