Skip to main content
← Learning Center/SOC 2 for AI
Compliance

SOC 2 for AI Systems

How SOC 2 auditors evaluate your AI infrastructure against the five Trust Services Criteria — and what you need to have in place before your next audit.

Security
Availability
Processing Integrity
Confidentiality
Privacy

Trust Services Criteria

SOC 2 evaluates systems across five criteria. Click each to see AI-specific implications and OWASP LLM mappings.

Security

The system is protected against unauthorized access.

AI-Specific Control Considerations

  • API key rotation and secret management for all LLM providers
  • Access control for prompt templates and model fine-tuning data
  • Network segmentation between AI inference and corporate networks
  • Secure model storage with encryption at rest

Mapped OWASP LLM Risks

LLM01: Prompt InjectionLLM05: Supply ChainLLM08: Vector & Embedding Weaknesses

OWASP LLM Top 10 → TSC Mapping

How the OWASP risks for LLM applications map to SOC 2 Trust Services Criteria.

OWASP Risk
Description
SOC 2 Criteria
LLM01Prompt Injection
SecurityIntegrity
LLM02Insecure Output Handling
Integrity
LLM03Model Denial of Service
Availability
LLM04Supply Chain Vulnerabilities
SecurityAvailability
LLM05Insecure Plugin Design
Security
LLM06Sensitive Information Disclosure
ConfidentialityPrivacy
LLM07Data Leakage
ConfidentialityPrivacyIntegrity
LLM08Vector & Embedding Weaknesses
Security
LLM09Misinformation
IntegrityConfidentiality
LLM10Unbounded Consumption
Availability

Audit Readiness Checklist

Interactive checklist — track your SOC 2 readiness for AI systems. 0/12 completed

Frequently Asked Questions

Preparing for a SOC 2 audit?

PurfectShield provides the continuous monitoring, audit trails, and data protection controls that auditors look for in AI systems. Ship AI securely from day one.

Explore PurfectShield