
What SOC 2 Type II means for your AI answering service
What SOC 2 Type II actually is
SOC 2 is an audit standard from the AICPA. An independent auditor examines how a company handles customer data across five trust criteria: Security, availability, processing integrity, confidentiality, and privacy. The output is a report, not a logo. Any vendor can describe its own security practices on a marketing page. A SOC 2 report is a third party confirming those practices exist and work.
Type I versus Type II: The difference that matters
Type I is a photograph. It says the controls were designed correctly on the day the auditor looked. Type II is a film. It says the controls actually operated correctly across an observation window, usually 6 to 12 months, with the auditor sampling evidence the whole way through.
That gap is the point. A Type I says a company built a security program. A Type II says the company ran it. When a vendor says "SOC 2" without naming a type, ask which one, and ask for the report date. A report from two years ago describes a company that no longer exists.
Why this matters when the vendor is on your phone line
An AI answering service is not a peripheral tool. It sits on your main inbound number and it hears everything: Names, addresses, phone numbers, what is broken inside the house, when the homeowner will be home, and often financing details. It writes into your CRM, which means it holds credentials to the system your whole operation runs on.
That is a larger data surface than most of the software you already put through security review. If you carry cyber insurance, work under a national brand, or sit inside a franchise or private-equity structure, someone in legal will eventually ask for the report. The vendor either has it or your rollout waits.
Which AI answering services are SOC 2 certified
Certification status across the platforms operators shortlist most often:
Platform | SOC 2 Type II certified |
|---|---|
Sameday | No |
Lace AI | No |
Rosie | No |
Goodcall | No |
Revin | Yes |
A "No" means the platform publishes no SOC 2 certification. Several of them describe encryption and role-based access, which are reasonable practices. They are not an audited report, and your legal team knows the difference.
What Revin does beyond the certificate
SOC 2 Type II covers how the platform handles your data. Two things sit outside that scope and matter just as much on a phone line.
The first is telephony compliance. Revin forwards opt-outs and updates do-not-call lists automatically, so TCPA handling is part of how the agent runs rather than a process someone on your team has to remember before every outbound campaign.
The second is who does the configuration. Most incidents start with a misconfiguration, not a broken control. Revin runs a forward-deployed engineering model: A dedicated AI engineer builds and tunes your agent, including the CRM connection and the scope of what the agent can touch. You are never handed a dashboard of permissions to get right on your own.
What to ask before you sign
Four questions cut through most of it. Is the report Type I or Type II, and what was the observation window? Will you share the report itself under NDA, not just the badge? Is our call data used to train models that serve other customers? Who at your company can pull a recording of one of our calls, and is that access logged?
A vendor certified today answers all four in a sentence each. A vendor that is still in process answers with a roadmap. Those are different answers, and only one of them clears legal.
Sources: Sameday, Lace AI, Rosie, and Goodcall websites and public materials, August 2026.
What is the difference between SOC 2 Type I and Type II?
Type I confirms the security controls were designed correctly at a single point in time. Type II confirms they operated correctly across an observation window, usually 6 to 12 months, with an auditor sampling evidence throughout. Type II is the stronger report because it shows the program was actually run, not just built. Enterprise buyers generally require Type II.
Does an AI answering service need to be SOC 2 compliant?
No law requires it, but an AI answering service holds homeowner names, addresses, service history, and credentials to your CRM. That makes it one of the higher-risk vendors in your stack. If you carry cyber insurance, operate under a national brand, or sit inside a franchise or private-equity structure, legal will ask for the report before signing.
What does it mean when a vendor says SOC 2 is in progress?
It means the audit is not finished and no report exists yet. A vendor can display a SOC 2 badge while the trust page behind it says in progress. Certification takes months, and a Type II report additionally requires an observation window to elapse. Ask for the expected report date in writing before you plan a rollout around it.
Is my customer call data used to train the vendor AI?
It depends entirely on the vendor, so ask directly. Some platforms train shared models on aggregated customer data. Revin trains your agent on your own call recordings for your account, so the agent qualifies the way your best CSR does. Get the answer in the contract rather than from a marketing page.
Which AI answering services are SOC 2 Type II certified?
Among the platforms home services operators shortlist, Revin publishes SOC 2 certification. Sameday, Lace AI, Rosie, and Goodcall publish no SOC 2 certification, though several describe encryption and access controls. Verify current status directly with any vendor, since certifications are renewed annually.

About Revin
Put audited AI on every call
Revin answers every inbound call, qualifies the homeowner, and books the job into your CRM on SOC 2 Type II certified infrastructure.








