AI Receptionist
SOC 2 and AI Phone Vendors: What to Ask Before You Sign
SOC 2 comes up on almost every AI receptionist sales call, usually within the first ten minutes. It gets mentioned the way a restaurant mentions being “chef-owned”: a credential that sounds reassuring whether or not you know what it means. Here is what it actually is, what it proves, and what it does not.
SOC 2 is an audit framework from the AICPA, the accounting standards body. An independent auditor examines a company’s controls around security, availability, processing integrity, confidentiality, and privacy, then writes a report saying whether those controls exist and work. It is a report you can request and read. It is not a badge, a certification you buy once, or a guarantee that nothing bad will ever happen.
Type I vs Type II: the distinction that matters
A SOC 2 Type I report says the controls were designed properly at a single point in time. A Type II report says the controls were designed properly and actually worked over a period, usually six to twelve months. Type II is the one worth reading. Type I is a snapshot; Type II is a track record.
Many small AI receptionist vendors have neither, and that is not automatically disqualifying. A two-year-old startup handling calls for local plumbers may not have had the time or budget for an audit. But if you are a clinic, a law firm, or anyone handling sensitive information, a current Type II report should be close to a requirement. And any vendor that claims to be “SOC 2 compliant” without being able to show you the report is using the words without the substance. Ask for the report itself, then check the date and the scope.
What the report covers and what it skips
SOC 2 covers the vendor’s own systems: how it stores data, who can access it, how it monitors for intrusions, how it backs things up. What it does not necessarily cover is the sub-processors: the telephony provider, the transcription service, the AI model provider. A vendor can pass SOC 2 while its audio lives with a carrier that was never audited in the same way. That is why the follow-up question matters: “Does your report’s scope include your telephony and AI providers?”
It also does not cover the AI’s behavior. SOC 2 will not tell you whether the AI gives accurate quotes or refuses to discuss topics it should not touch. It tells you the data is guarded. It says nothing about what the AI says with it. Those are separate questions, and you need to ask both.
The questions to ask before you sign
- Can I see the actual SOC 2 report, and is it Type I or Type II?
- What period does it cover, and what systems are in scope?
- Which of your subprocessors (telephony, transcription, AI models) are covered?
- Do you offer a data processing agreement, and a BAA if we handle health information?
- Is our call data used to train your models, and can we opt out in writing?
- How long do you retain recordings and transcripts, and can we set our own retention?
These pair well with the demo questions we recommend in what to ask on an AI receptionist demo. Security questions deserve their own time on the call, not a rushed minute at the end.
When SOC 2 is not enough
If you run a medical practice, ask about a HIPAA Business Associate Agreement. The AI is touching protected health information the moment it takes a patient’s name and appointment reason, and a BAA is the legal instrument that makes the vendor accountable for it. We wrote a full HIPAA and BAA checklist for clinic owners if that is your situation.
If your callers are in Europe or California, ask about GDPR and CCPA handling: data subject requests, deletion workflows, and whether data ever leaves the agreed region. And if the vendor is cagey about any of this, remember the red flags when choosing a provider. Security posture is one of the fastest ways to separate a real company from a reskinned demo.
Frequently asked questions
Is SOC 2 required for an AI receptionist?
Not by law, for most industries. It is a trust signal, and a strong one, but healthcare buyers should treat a BAA as the legal requirement and SOC 2 as supporting evidence.
Can a small vendor be secure without SOC 2?
Yes. A small team with encrypted storage, tight access controls, clear retention policies, and honest answers can be safer than a big vendor with a stale report. The report is evidence of process. Its absence just means you have to do more checking yourself.
What if the vendor says “we’re SOC 2 certified”?
There is no such thing as SOC 2 certification in the way people use the word. There is a report. Ask to read it. The phrasing alone tells you whether the person you are talking to understands their own compliance posture.



