DEFINITION
SOC 2
A security audit framework for service organisations that tests whether controls over security, availability, processing integrity, confidentiality, and privacy are suitably designed and operating effectively.
In depth
SOC 2 (System and Organisation Controls 2) is an auditing standard developed by the American Institute of Certified Public Accountants (AICPA). It is the de-facto security attestation for B2B SaaS companies and is increasingly required in enterprise software procurement. SOC 2 audits are conducted against the Trust Service Criteria (TSC): Security (mandatory), Availability, Processing Integrity, Confidentiality, and Privacy. A Type I report assesses whether controls are suitably designed at a point in time; a Type II report assesses whether they operated effectively over a period (typically 6–12 months). For AI tool usage, the Confidentiality criterion is the most directly implicated: it requires controls that identify, protect, and dispose of information designated as confidential. Transmitting confidential information to unapproved AI tools degrades Confidentiality controls. The Security criterion (CC9.2) also requires that vendor risks be assessed and managed — unapproved AI tools not on the vendor inventory create a gap. Organisations seeking or maintaining SOC 2 certification need to address AI tool use in their acceptable-use policies, vendor risk programs, and (increasingly) as explicit audit evidence.
Examples
- An engineer pasting proprietary source code into ChatGPT for a code review — confidential information transmitted to a vendor not on the vendor inventory.
- A customer success manager summarising customer support tickets in Claude without a DPA — customer PII reaching an unassessed vendor.
- A SOC 2 auditor asking for evidence of controls over AI tool usage and receiving no documented policy or vendor assessments.
How Locke handles soc 2
Locke provides a technical control that reduces the risk of confidential information reaching unapproved AI tools — it detects and masks sensitive content before the prompt leaves the device, regardless of which AI tool is in use. For organisations building SOC 2 evidence, Locke's local-first architecture means it can be deployed without adding a new vendor to the vendor inventory.
See the productRelated terms
- Shadow AI
Employees using AI tools at work without organisational sanction — the AI-era version of shadow IT.
- Data Loss Prevention (DLP)
A category of security tooling that inspects outbound data flows to prevent sensitive content from leaving an organisation's control.
- Personally Identifiable Information (PII)
Any information that can identify a specific person, either directly (name, SSN) or in combination with other data (zip code + birthdate).