Enterprise + Sovereign AI

What should buyers verify about SOC 2 and ISO 27001 for AI infrastructure?

Verify four things: which system and controls the report covers, the audit period and whether it is Type I or Type II, what is carved out or handled by subservice organisations, and how the controls map to the AI-specific data path — prompts, embeddings, logs and model providers. For ISO 27001, check the certification scope and statement of applicability, not just the certificate logo.

Key facts

SOC 2 typesType I covers design at a point in time; Type II covers operating effectiveness over a period
ISO materialsCertificate plus certification scope and statement of applicability
Bridge lettersCover the gap between the audit period end and your review date
Carve-outsSubservice organisations, upstream model providers and support tooling must be listed
AI specificsPrompts, completions, embeddings, logs and key management need explicit control coverage
Plugsky statusSOC 2 Type II and ISO 27001 readiness in progress (not yet certified)
Compensating controlsPrivate deployment, BYOK, audit export and SSO/SCIM reduce residual risk
Contractual frameTerms at /legal/terms and service commitments at /legal/sla

TL;DR

  • A logo is not evidence — read scope, period and carve-outs.
  • Check that the AI data path is inside the report boundary.
  • Ask for the bridge letter so the coverage gap is visible.
  • List subservice organisations and where they process data.
  • If certification is in progress, negotiate milestones and compensating controls.

How it works, step by step

  1. Request the current SOC 2 report under NDA and read the scope section first.
  2. Confirm Type I versus Type II and the exact audit period covered.
  3. Check the bridge letter for the period since the report end date.
  4. Read carve-outs and the subservice organisation list for AI-relevant components.
  5. For ISO 27001, review the certificate scope and statement of applicability.
  6. Map the controls to your AI data path: prompts, embeddings, logs and keys.
  7. Document gaps with milestones, compensating controls and contractual remedies.
1Request the currentSOC 2 report underNDA and read the2Confirm Type Iversus Type II andthe exact audit3Check the bridgeletter for theperiod since the4Read carve-outs andthe subserviceorganisation list5For ISO 27001,review thecertificate scope6Map the controls toyour AI data path:prompts,

Try it yourself

Open the sovereign AI readiness score →

Reading a SOC 2 report like a buyer

  • Scope: which system, environments and services are covered — a marketing site inside the boundary proves nothing about inference.
  • Type and period: Type II over a defined window is materially stronger than a Type I snapshot; check both dates.
  • Trust services criteria: security is table stakes; availability, confidentiality and privacy matter for AI workloads handling sensitive data.
  • Exceptions: tests that failed are more informative than the ones that passed. Ask what changed afterwards.
  • Bridge letter: bridges the gap between the audited period and today; a missing bridge letter means you are relying on stale evidence.

Carve-outs and the AI supply chain

Most AI platforms depend on upstream model providers, cloud infrastructure and support tooling. If those components are carved out of the report, their controls are not covered — and they sit directly on your data path. Ask for the subservice organisation list, the flow-down security commitments, and which regions each provider processes data in. Then decide whether the carve-out is acceptable for your data classes or whether you need a deployment tier that removes the dependency, such as VPC, on-prem or air-gapped inference with models you control.

ISO 27001 specifics

The certificate alone is not enough. The certification scope defines which parts of the organisation and platform are covered, and the statement of applicability lists which Annex A controls are implemented and which are excluded with justification. Read both. For AI services, confirm coverage of supplier relationships, cryptography and key management, logging, access control and secure development. ISO 27701 adds privacy management, and ISO 27017/27018 cover cloud-specific and PII-in-cloud controls — useful when your regulator expects them.

When certification is still in progress

Many capable AI platforms are earlier in their audit journey than legacy infrastructure vendors. Plugsky documents SOC 2 Type II and ISO 27001 as readiness in progress rather than completed certification. The workable procurement response is a risk-register entry with milestones, compensating controls you can verify today — private deployment, BYOK/HSM, scoped keys, SSO/SCIM, audit export, PII modes — and contractual remedies if milestones slip. Record what is proven versus pending, and re-check before contract renewal rather than treating the question as settled. Contractual terms belong in /legal/terms and the service commitments in /legal/sla.

Honest comparison

Evidence itemWhat it provesCommon gapWhat to ask next
SOC 2 Type II reportControls operated over a periodStale period or narrow scopeRequest the bridge letter
Type I reportDesign at a point in timeNo operating evidenceAsk for the Type II timeline
ISO 27001 certificateCertified management systemScope excludes the AI serviceRead scope and SoA
Pen test summaryExternal validationOld or narrowly scopedAsk for date, scope and remediations
Subprocessor listSupply chain visibilityLocations missingMap regions to data classes
Plugsky statusReadiness in progress, not certifiedTreating it as completeSet milestones and compensating controls

Frequently asked questions

Is Plugsky SOC 2 Type II certified?

No — SOC 2 Type II and ISO 27001 are documented as readiness in progress rather than completed certifications. Treat the status as pending, request current evidence, and negotiate milestones and compensating controls in the contract.

What is the difference between Type I and Type II?

Type I assesses control design at a single point in time; Type II tests operating effectiveness across a period. For vendor diligence, Type II over a recent window with a bridge letter is the stronger evidence.

Why do carve-outs matter for AI?

Carved-out components are outside the audit scope but may still touch your data. Upstream model providers and support tooling are the usual examples, so their controls and locations need separate review.

What should be in the ISO 27001 package?

The certificate, the certification scope and the statement of applicability. Together they show which parts of the organisation and platform are covered and which controls are implemented or excluded.

How often should we re-verify?

At least annually and at renewal, plus after any material architecture change. Ask for the newest bridge letter and re-check subprocessors and region coverage rather than relying on the initial file.

What compensating controls reduce risk while certification is pending?

Private deployment (VPC, on-prem or air-gapped), BYOK or HSM key custody, scoped keys with rotation, SSO/SCIM, PII modes with redaction, and audit export to your SIEM.

Do pen tests count as certification?

No. Pen test summaries are point-in-time technical evidence and useful supporting material, but they do not replace an audit report or an ISO management-system certification.

What belongs in the contract if certification is pending?

Milestones with dates, notification duties, audit rights, exit assistance and remedies if milestones slip. Reference the terms at /legal/terms and the SLA at /legal/sla for the enforceable commitments.