← Security at Voiceflow
SOC 2 badge

Compliance

SOC 2 Type II

Voiceflow is SOC 2 Type II compliant.

Our latest independent audit report is available in the Trust Center.

SOC 2 Type II report

Independent audit report

Visit Trust Center

Independent assurance, over time.

SOC 2 Type II is an independent examination of how an organization’s controls operate over a defined period. It gives teams a way to evaluate a service provider’s controls as part of their vendor review.

Voiceflow’s SOC 2 Type II report is available through our Trust Center. The report is the source for the systems covered, applicable Trust Services Criteria and audit period. Review those details alongside your own deployment, connected services and data requirements.

Frequently asked questions

What is the difference between SOC 2 Type I and Type II?
Type I examines the design of controls at a point in time. Type II also examines how those controls operated over a specified period.
How can I access Voiceflow’s SOC 2 report?
Visit our Trust Center and locate the SOC 2 Type II report. Follow the access instructions there to review the document.
Which services and audit period does the report cover?
The report identifies the systems in scope, the Trust Services Criteria covered and the examination period. Check the report in our Trust Center for those details.
Does using Voiceflow make my organization SOC 2 compliant?
No. Voiceflow’s report concerns the controls in its own audited scope. Your organization’s controls, configuration and connected services need to be assessed separately.
Where can I learn about Voiceflow’s security controls?
Our security overview explains data protection, application security, infrastructure and organizational practices. Voiceflow’s security practices include access controls, audit logging and alerting. Automated and manual code reviews, vulnerability scanning and external penetration testing support our security program.