Back to Blog
Compliance & Security

How to read a SOC 2 report for a voice AI vendor

Review the service scope, reporting period, exceptions and customer responsibilities rather than treating a SOC 2 label as a product guarantee.

Burki
(Updated: September 25, 2026)
2 min read

A SOC 2 report is an independent examination report about a described service organization's controls. It should not be treated as a universal product certification or a guarantee that a specific voice AI configuration is suitable for your data.

The AICPA's SOC resources describe the relevant trust-services framework. The buyer's job is to compare the actual report with the system they intend to use.

Request the document, not only the badge

Ask for the service covered, the reporting period, the auditor's opinion and the permitted distribution terms. A cloud provider's report does not automatically cover the application built on that cloud, its employees or every external model provider.

A Type 1 report addresses a point in time; a Type 2 report covers a period and includes tests of operating effectiveness. Use the dates printed in the report rather than assuming a standard number of months. The AICPA report-review checklist provides a practical review structure.

Match the boundary to a voice call

Trace the carrier, media service, model providers, transcripts, recording storage and connected business tools. Identify which are inside the report's system description and which are separately assessed. If a report excludes a subservice organization, obtain the relevant evidence instead of assuming inherited coverage.

Read control exceptions in context. Ask what failed, when it occurred, what was affected and whether corrective evidence exists. Also identify controls your organization must operate, such as account access reviews or protecting exported recordings.

Turn the report into a deployment decision

Record the reviewed service and dates, open questions, customer responsibilities and the person accepting any remaining risk. Revisit that decision when the model, recording location or tool integration changes.

For Burki, request current evidence directly rather than inferring certification from a blog, a cloud vendor logo or an administrative setting. This article does not claim that Burki holds a SOC 2 report. Browser tests with fictional data can help evaluate conversation behavior while the security review proceeds, but they do not replace that review.

Continue with the vendor security worksheet to cover operational questions that a report may not answer by itself.

Ready to try Burki?

Create an assistant and check your available browser practice allowance.

Create your assistant

Trial eligibility and available practice are shown in your workspace.

Related Articles