SOC 2 for recruiting software: how to read the report before you buy
On this page
A SOC 2 report is an independent CPA firm's examination of a vendor's controls over security and, if included, availability, processing integrity, confidentiality and privacy, based on the AICPA's Trust Services Criteria. For recruiting software it is useful evidence that the vendor's systems protecting candidate data are designed and, in a Type 2 report, operating as described. It is not a certificate, and it does not tell you what the vendor is allowed to do with your data; the contract does that.
This page explains how to read a SOC 2 report for an applicant tracking system, video interview platform or AI note-taker: which sections matter, what exceptions and carve-outs mean, and which questions a report will not answer for recruiting data. The contract side, including sub-processors and AI training, is in the DPA guide for recruiting software.
Not legal or audit advice. This describes SOC 2 as the AICPA presents it on the linked pages and as reports are commonly structured, as of September 2026. We could not access the full AICPA guide text, so technical terms are described as commonly used. Have your security or compliance lead review reports for high-risk vendors.
What SOC 2 is, and what it is not
The AICPA describes System and Organization Controls (SOC) as a suite of service offerings CPAs may provide in connection with controls at a service organization. SOC 2 examinations use the 2017 Trust Services Criteria (with points of focus revised in 2022), covering five categories: security, availability, processing integrity, confidentiality and privacy.
| Report | What it covers | Use in vendor review |
|---|---|---|
| SOC 1 | Controls relevant to customers' internal control over financial reporting | Payroll or billing systems; rarely relevant to recruiting tools |
| SOC 2 Type 1 | The system description and the design of controls at a point in time | A starting point for a new vendor; no evidence controls worked over time |
| SOC 2 Type 2 | The description, design and operating effectiveness of controls over a period, including the auditor's tests and results | The report to ask for |
| SOC 3 | A shorter general-use report on the same subject matter, without the detailed tests | Fine for a first look; not enough for a system holding candidate interviews |
The AICPA's illustrative SOC 2 report shows the usual structure of a Type 2: management's assertion, the description of the system, the service auditor's report, and the tests of controls with results. The AICPA has also publicly warned that promises of "fast and easy" SOC engagements threaten the credibility of the reports, which is a reason to read the report rather than trust a badge on a website.
How to read a SOC 2 report in 20 minutes
- The auditor's opinion. Look for whether it is unqualified or qualified. A qualified opinion means the auditor found something significant enough to call out. Note the CPA firm's name.
- Type and period. Type 2, and a period that ended recently. A period of a few months tells you less than a longer one.
- Categories in scope. Security is the baseline. For recruiting data, confidentiality and privacy are the categories most worth having; availability matters if the tool is critical to interview days.
- The system description. Check that the product you are buying is inside the boundary. A report on the vendor's "platform" may exclude a newer AI feature, a mobile app or a desktop client.
- Subservice organizations. Cloud hosts and other providers are often carved out, meaning their controls were not tested in this report. Note which ones, then check their own reports or the vendor's monitoring of them.
- Complementary user entity controls. The list of things you, the customer, are expected to do, such as managing user access and enforcing strong authentication. These are your obligations; if you don't do them, the report's conclusions don't fully apply to your use.
- Exceptions in testing. Read the test results section for deviations, and management's responses. A few isolated exceptions with a clear response are common; repeated exceptions in access reviews or change management are worth a question.
A worksheet for each vendor report
SOC 2 REVIEW — [vendor] — [product] — reviewed by [name] on [date]
Report
Type: [Type 1 / Type 2]
Period: [start] to [end] Months since end: [ ]
Auditor (CPA firm): [ ]
Opinion: [unqualified / qualified: reason]
Categories in scope: [security / availability / processing
integrity / confidentiality / privacy]
Scope
Product we use in scope? [yes / partly: which parts excluded]
AI features in scope? [yes / no / not mentioned]
Subservice orgs carved out:[cloud host, speech-to-text, LLM, email]
Their assurance checked: [report / certification / vendor monitoring]
Our obligations (CUECs)
[list each] Owner on our side: [ ] Done? [ ]
Exceptions
[control]: [deviation] — [management response] — [our view]
Gaps for recruiting data (ask separately)
Candidate data used for model training? [ ]
Retention in sub-processors? [ ]
Per-candidate export and deletion? [ ]
Bridge letter covering [period end] to [today]: [received / requested]
Decision: [approve / approve with conditions / reject] Next review: [ ]
What a SOC 2 report won't tell you about recruiting data
A SOC 2 examination tests the controls the vendor describes against the criteria. It is not designed to answer the questions that matter most about candidate data, so ask them separately and get the answers into the contract:
| Question | Why the report may not answer it | Where to get the answer |
|---|---|---|
| Is our candidate data used to train AI models? | A permitted use, if described, is not a control failure | DPA and product terms |
| How long do speech-to-text and language model providers keep audio and text? | They are often carved-out subservice organizations | Sub-processor list with retention, in the DPA |
| Can we delete one candidate everywhere within 30 days? | Deletion processes may be described but not tested against your deadline | A test before rollout |
| Are AI scores fair across groups? | Outside the Trust Services Criteria | Vendor's adverse impact testing; see Title VII disparate impact and AI hiring |
| Are recordings kept only as long as our policy says? | Retention settings are usually the customer's responsibility | Product configuration and your retention schedule |
| What happens to data on recruiters' laptops? | Endpoints you manage are outside the vendor's system boundary | Your own device controls |
The last row matters more as tools change shape. Some interview tools keep transcripts in the vendor's cloud, where a SOC 2 report covers the storage. Others, Interview Signal among them, keep transcripts and notes on the recruiter's computer, so the vendor holds less candidate data but your own laptop controls, such as disk encryption, screen locks and access when someone leaves, carry more of the weight. Whichever model you choose, know which side of the boundary each copy of the data sits on.
When there is no SOC 2 report
Many smaller recruiting tools do not have one, especially new products. That is not automatically a reason to reject them, but it moves the burden onto other evidence:
- An ISO/IEC 27001 certificate, checking the certificate's scope and issuing body, which is a different kind of assurance from a SOC 2 examination.
- A SOC 2 Type 1 or a readiness assessment with a date for the Type 2 period to start.
- The subservice organizations' own reports, for example the cloud host's, plus the vendor's description of what it adds.
- A completed security questionnaire with specific answers on encryption, access control, logging, incident response, backups and deletion.
- Architecture that reduces what the vendor holds, such as not retaining audio, which changes what you need assurance about.
- Contract terms that give you notice of breaches, sub-processor changes and a right to ask questions. See the DPA guide.
Scale the review to the risk. A scheduling link that sees names and emails needs less than a system that records and scores every interview your agency runs.
Common misreadings
| Belief | Reality |
|---|---|
| "SOC 2 certified" means the product is secure | There is no SOC 2 certificate; a report says what was examined, for which period, and with what exceptions |
| A SOC 3 is the same as a SOC 2 | A SOC 3 is the short general-use version, without the detailed description and tests |
| A report covers everything the vendor sells | Only the system described; new features and acquired products are often outside it |
| SOC 2 means GDPR or CCPA compliance | Privacy law obligations are separate; the report can support, not replace, your own assessment |
| Carved-out providers were checked | Carve-out means their controls were not tested in this report |
| Once reviewed, done | Reports describe a past period; request the new one each year |
A checklist for recruiting teams
- Rank vendors by the candidate data they hold: recordings and scores first, scheduling last.
- Request the full SOC 2 Type 2 report under NDA, not the badge or the SOC 3, for high-risk vendors.
- Confirm the product and features you use are inside the system description.
- List carved-out subservice organizations, especially speech-to-text and language model providers, and check their retention.
- Assign an owner for each complementary user entity control, starting with access management and authentication.
- Read the exceptions and management's responses; ask about anything repeated.
- Get a bridge letter if the report period ended more than a few months ago.
- Ask the recruiting-specific questions the report won't answer, and put the answers in the DPA.
- Diary the next review for when the vendor's next report is due.
Questions people ask
Is a SOC 2 certification?
No. SOC 2 is an examination report issued by an independent CPA firm, not a certificate. Vendors that say they are "SOC 2 certified" usually mean they have a report; ask for the report itself, its type and its period.
What is the difference between SOC 2 Type 1 and Type 2?
As commonly described, a Type 1 report covers whether controls are suitably designed at a point in time, while a Type 2 report also tests whether they operated effectively over a period, and includes the auditor's tests and results. For a system that will hold candidate data for years, a Type 2 is the more useful evidence.
Does a small recruiting agency need its own SOC 2?
Rarely. SOC 2 reports are usually obtained by service organizations whose customers ask for them. Agencies are more often on the receiving end: reviewing their vendors' reports, and answering client security questionnaires about their own practices.
How old can a SOC 2 report be?
There is no fixed expiry, but a report describes a past period. Many buyers look for a period that ended within the last 12 months and ask for a bridge letter from the vendor covering the gap since the period end.