AIXYRA
All Frameworks
Security & resilienceOngoing attestation regime (Type I / Type II). The default B2B trust report in North America.

SOC 2

SOC 2 — AICPA Trust Services Criteria attestation

The attestation enterprise buyers ask for first: independent examination of controls against the Trust Services Criteria — security, availability, confidentiality, and more.

56 individual requirements seeded and assessable in AIXYRA.

SOC 2 is an attestation, not a certification: an independent auditor examines an organization's controls against the AICPA Trust Services Criteria — security (required), plus availability, processing integrity, confidentiality, and privacy as selected. A Type II report covers operating effectiveness over a period, and has become table stakes in North American B2B sales.

AI complicates SOC 2 in familiar ways: controls presume a known system landscape, and AI adoption adds systems, vendors, and data flows fast. Change management, logical access, and vendor management criteria all now get asked with an AI accent — 'how do you control which AI systems reach production?' is a SOC 2 question.

Who it applies to

Service organizations whose customers demand independent assurance — SaaS vendors above all — and any company whose enterprise deals stall without a SOC 2 report.

Key requirement themes

Security (Common Criteria)

Access control, change management, risk assessment, and monitoring — the required baseline of every SOC 2 report.

Change management for AI

Evidence that new AI systems and model changes follow a controlled, approved path to production.

Vendor management

AI providers and APIs are subservice organizations and vendors — with assessment and monitoring expectations.

Audit evidence over time

Type II requires records that controls operated all period long — not artifacts assembled the week before the audit.

Orientation for evaluators — not legal advice. Consult counsel for obligations specific to your organization.

How AIXYRA helps

  • Governance checkgates give 'how does AI reach production?' a documented, enforced answer — including in CI/CD via the governance gate
  • The registry and dependency graphs enumerate AI vendors and services for vendor-management review
  • The tamper-evident, time-stamped audit trail supplies period-long operating evidence auditors ask for
  • Assessments against seeded SOC 2 criteria track coverage and evidence continuously, not audit-week

SOC 2 FAQ

How does AI adoption affect a SOC 2 audit?

Auditors apply existing criteria to the new surface: change management must cover AI deployments, logical access must cover AI platforms, and vendor management must cover model providers. Ungoverned AI adoption shows up as control exceptions.

Is AIXYRA itself SOC 2 certified?

SOC 2 certification for the AIXYRA platform is in progress — stated plainly on our Security & Trust page, where we also describe the identity, encryption, audit-immutability, and deployment controls behind the platform.

Assess your AI systems against SOC 2

SOC 2 ships built into AIXYRA — and the same assessment maps to every other enabled framework at once.