SOC 2
A voluntary audit framework from the AICPA that reports on how a service organisation controls customer data across five trust criteria: security, availability, processing integrity, confidentiality and privacy.
SOC 2 is the report enterprise buyers ask a SaaS vendor to produce before trusting it with their data. A Type I report describes controls at a point in time; a Type II report tests that they operated effectively over a period — usually three to twelve months. The audit is performed by an independent CPA firm.
For transcription, a SOC 2 report tells a buyer how a cloud vendor protects the audio it receives. An on-prem tool reframes the question entirely: because the data stays on your own systems, the relevant controls are yours, and a vendor’s SOC 2 matters far less than your own deployment. Note that SOC 2 is not a substitute for a BAA under HIPAA, nor for a lawful basis under GDPR — different frameworks, different obligations.