Is Your Legal AI Tool SOC 2 Certified? How to Check

A legal AI tool is "SOC 2 certified" only if an independent CPA firm has examined its controls and issued a SOC 2 report, and the version that matters is Type 2, which tests whether those controls worked over a stretch of time rather than on a single day. SOC 2 is technically an attestation report, not a certificate, so the phrase "SOC 2 compliant" on a marketing page proves nothing until you have seen the report itself. To check a vendor, ask for the current report under NDA, confirm it is Type 2, confirm the observation period is recent, confirm the product you are buying is inside the scope, and read the auditor's opinion and the exceptions section. "In progress" and "aligned with SOC 2" mean the audit has not finished or has not happened.
We run a directory of AI legal software and we don't sell any of it. That matters here, because almost everything written on this topic comes from a vendor that holds the report and wants you to know it. This is the buyer's side of the table: what the claim means, how to test it, and what eight vendors in our directory actually say on their own security pages today.
This is software evaluation guidance, not legal or compliance advice. Your own professional obligations depend on your jurisdiction and your clients' contracts.
What does SOC 2 actually test?
SOC 2 is a reporting framework maintained by the AICPA, the US accounting body. A licensed CPA firm examines a service organization and writes a report on its controls against the Trust Services Criteria. Per the AICPA's SOC suite of services, a SOC 2 examination covers controls relevant to security, availability, processing integrity, confidentiality, or privacy.
Two details change how you read any vendor claim.
The vendor chooses which categories go in the report. Security is the baseline, and availability, processing integrity, confidentiality and privacy are additions a vendor opts into. For a legal AI tool, confidentiality is the one you care about most, so check which categories are inside the report, not just that a report exists. Gavel's security page, for example, says its report covers security, availability and confidentiality. That is a specific, checkable statement. "SOC 2 certified" with no categories named is not.
The vendor writes the description of its own system. The auditor tests whether the controls the vendor described are designed and operating. The scope is the vendor's choice. A company can have a clean report on its corporate IT environment or its core platform while a newer AI feature, a new model integration or an acquired product sits outside it. That gap is where most real risk hides.
Type 1 or Type 2: which one should you ask for?
Ask for Type 2.
A Type 1 report describes whether controls are suitably designed at a single point in time. Think of it as a photograph of the building plans. A Type 2 report tests whether the controls operated effectively over an observation period, usually several months to a year. It is the inspection record, not the blueprint.
| Type 1 | Type 2 | |
|---|---|---|
| What it tests | Design of controls on one date | Design and operation over a period |
| Typical use | A young company's first report | The report buyers should require |
| What it can't tell you | Whether anyone followed the controls | Anything outside the stated scope or period |
| Red flag if it's all they have | Product has handled client files for a year or more | Observation period ended long ago |
A Type 1 is not a bad sign for a young vendor. It is a stage. It becomes a bad sign when a vendor with real customers and real client files still has nothing past it, or when a sales deck blurs the two. If the page says "SOC 2" and nothing else, the next question is the type, and the answer should arrive in one email.
What should you read in the report itself?
Most buyers never open the report, which is the whole reason a badge works as marketing. A SOC 2 report runs long, but five sections do the work.
- The auditor's opinion. Is it unqualified (clean), qualified, or adverse? A qualified opinion means the auditor found a problem serious enough to say so in the opinion itself.
- The system description. What products, infrastructure and locations are in scope? Is the AI feature you are buying named, or only "the platform"?
- The observation period. The dates the controls were tested. A period that ended 14 months ago is stale. A period that ended last quarter is current.
- The testing results and exceptions. Every control tested, and every deviation found. A few exceptions with documented management responses are normal and often more reassuring than a report with none. What you want is exceptions you can understand and a response that fixed them.
- Subservice organizations and complementary controls. Which parts of the stack belong to someone else (the cloud host, the model provider), and what the vendor expects customers to do on their side. If a model provider handles your prompts, ask whether that provider is inside the scope or carved out.
That last point is the one legal buyers miss most. A vendor can hold a valid report and still send your documents to a third-party model that the report excludes. The report tells you the carve-out exists. Only you reading it will see it. Our guide to legal AI data security covers the sub-processor questions in more depth.
Also note the difference between the report and its public cousin. Everlaw's security page, for instance, offers both its SOC 2 Type 2 report and a SOC 3 report. Everlaw describes the SOC 3 as a less granular summary than the SOC 2 report. It is useful as a signal, but it does not contain the testing detail that makes the full report worth reading.
Which legal AI vendors publish their certifications?
Here is what eight tools in our directory say on their own security or trust pages. We read each page on October 2, 2026. Where a cell says "not stated on page," that means we did not find a claim on the page we read, not that the vendor lacks the certification. Trust centers often hold more than the public page shows, and vendors change these pages without notice. Treat this table as a starting point for the request, not a verdict.
| Vendor | SOC 2 as stated on its page | ISO 27001 as stated | Trust center or portal |
|---|---|---|---|
| Harvey | SOC 2 Type II listed among its compliance badges | Listed (ISO 27701 and ISO 42001 also listed) | Security portal |
| Spellbook | "SOC 2 Type II Compliant" | Not stated on page | Trust portal |
| Legora | "SOC2 Type 2" listed; page wording is "we meet SOC 2 requirements" | "Fully certified" | Trust center |
| Everlaw | SOC 2 Type 2 attestation, with the latest report downloadable on its trust page | Listed (ISO 27017 and 27018 also listed) | Trust page with report download |
| Gavel | Gavel Exec "SOC 2 Type II certified" (security, availability, confidentiality) | Not stated on page | Not stated on page |
| Genie AI | States plainly that it does not hold a SOC 2 report | ISO/IEC 27001:2022 certified, with certificate number and issuing body given | Not stated on page |
| Luminance | SOC 2 Type II examinations described as regular | Listed | Trust center |
| SpotDraft | Its page mentions SOC 2 Type II only for its cloud hosting provider | "ISO/IEC 27001:2022 Certified Company" | Trust center |
Four patterns are worth noticing.
Wording varies, and wording is evidence. Gavel and Everlaw describe an examination by an independent auditor. Spellbook uses "compliant." Legora lists "SOC2 Type 2" as a badge but writes "we meet SOC 2 requirements" in the body. Each of those might be backed by a full Type 2 report. The soft phrasing is simply the cue to ask for it.
Genie AI is the model of a clear negative. It says it does not hold SOC 2 and names the ISO 27001 certificate it does hold, with the number and the certification body. A vendor that tells you what it lacks is easier to trust than one that lets you assume. It also shows why SOC 2 is not the only credible path, which the FAQ below covers.
A hosting provider's report is not the vendor's report. SpotDraft's page references SOC 2 Type II for the cloud platform it runs on. That is a real and useful fact about infrastructure. It is a different thing from an examination of SpotDraft's own controls, and a careless reader could merge the two. Ask which one you are being shown.
A public page and a trust center are different tiers. Several vendors route the real documents through a gated portal. That is fine, and often better, since reports are confidential. The test is whether you can get in once you ask.
Compliance automation tools like Vanta and Drata sit in our directory too. Companies can use platforms like these to collect control evidence and run a trust center. That is process, not a result: the report still comes from an independent auditor. We cover that category in AI governance platforms compared.
How do you get a vendor's SOC 2 report?
Ask in writing, and ask early, before anyone uploads a client file.
- Request the current SOC 2 Type 2 report. Name the product and the version you are buying, not just the company.
- Expect an NDA. Reports are confidential. A vendor that refuses to share even under NDA, or only offers a summary, is telling you something.
- Check the dates. Note the observation period and when the report was issued. Ask for the bridge letter if a gap has opened since.
- Confirm the scope includes the AI features and any model providers that touch your data.
- Read the exceptions and the opinion, then ask the vendor about anything that looks unresolved.
- Put it in the contract. Ask for annual delivery of the current report and notice if a qualified opinion is ever issued.
If you already have a structured vendor review, this fits inside it. Our buyer's checklist for evaluating legal AI tools has the surrounding questions on accuracy, pricing and ownership.
What does SOC 2 not cover?
SOC 2 is a statement about a company's controls, and that is all it is. It does not tell you several things you still need to know.
- Whether the vendor trains on your data. That is a contract term, not an audit finding. Get it in the master agreement.
- Whether the model is accurate. A tool can have flawless access controls and still invent a citation. Controls over security say nothing about hallucination. See our coverage of AI hallucination sanctions.
- Whether it meets your regulatory duties. Privilege, HIPAA, export rules and client outside-counsel guidelines are separate questions. A report supports your diligence. It does not replace it.
- Whether the vendor will still be the same company next year. Ownership changes can move your data to a new parent. Our legal AI acquisitions tracker follows those.
- AI-specific risk. SOC 2 predates generative AI. Standards like ISO/IEC 42001 aim at AI management systems, and you may see them listed next to SOC 2 on a trust page. Treat them as additional evidence, not replacements.
Frequently asked questions
Is SOC 2 required for legal AI tools?
No law requires a legal AI vendor to hold a SOC 2 report. It is a market expectation, and it is often written into law firm and corporate client security requirements. If your clients' outside-counsel guidelines or your own insurer's questionnaire ask for it, it is required for you in practice. Whether any particular use is acceptable under your professional rules is a question for your jurisdiction.
What is the difference between SOC 2 Type 1 and Type 2?
Type 1 looks at whether controls are suitably designed on a single date. Type 2 tests whether they operated effectively over an observation period. For a product that will hold client files, Type 2 is the report to ask for, because it shows the controls working over time instead of only existing on paper.
How do I get a vendor's SOC 2 report?
Email the vendor's sales or security contact and ask for the current SOC 2 Type 2 report for the specific product, under NDA. Many vendors fulfill this through a trust center or portal. Check the observation period, the scope and the exceptions before you rely on it.
Is ISO 27001 better than SOC 2?
Neither is better. They are different instruments. ISO/IEC 27001 is an international standard for an information security management system, and a certification body audits a company against it and issues a certificate. SOC 2 is a US-framed attestation report from a CPA firm that includes detailed test results. The ISO overview of ISO/IEC 27001 explains the management-system model. A vendor with a current ISO 27001 certificate and a clear scope is a legitimate alternative to SOC 2, and Genie AI's page shows one in practice. Many larger vendors hold both.
Apply the check to any listing
Every tool in our legal AI directory is verified active, and vendors can add their security documentation to a free listing. If you run a legal AI product and your trust center is public, say so through submit a tool. Buyers who ask for the report will look for it.