SOC 2 isn't a law — it's an AICPA attestation where an independent CPA firm audits your controls against the Trust Services Criteria. Nobody is legally required to have it; it's triggered the moment enterprise procurement asks "do you have a current SOC 2 Type 2?" First-year cost for a startup typically runs K–K, and the key nuance for AI-built apps is this: your builder's or host's SOC 2 covers their own infrastructure, not the app you shipped on top of it.
Get a Free Compliance Scan See Audit PricingThere's no statutory penalty for skipping SOC 2 — the "penalty" is lost revenue. Enterprise buyers routinely send ~200-item security questionnaires where SOC 2 Type 2 is the headline question, and not having a report can end a deal outright. Type I attests to control design at a single point in time; Type II attests to design and operating effectiveness over an observation window, typically 3–12 months — and Type II is what enterprise buyers actually require.
| Trigger | Why it happens |
|---|---|
| First enterprise deal | The #1 reason companies start the process — a prospect's security team requests the report before signing. |
| Vendor-risk reviews | Third parties account for over 60% of enterprise cyber risk, so buyers formally review every vendor. |
| Fundraising / partnerships | Vendor-published surveys suggest roughly 70% of VCs prefer SOC 2-compliant startups and over 60% of businesses are more likely to partner with one (directional, not audited stats). |
| Sales-cycle friction | Compliance gaps reportedly add 2–4 weeks to B2B SaaS sales cycles even when the deal survives; SOC 2 adoption reportedly surged 40% in 2024. |
Sources: aicpa-cima.com; trycomp.ai/hub/soc-2-cost-breakdown; drata.com/learn/soc-2; acalytica.com/itgc-audit-vibe-coded-apps.
| Control area | What's evaluated |
|---|---|
| Access control | MFA or SSO on sensitive systems, RBAC, documented provisioning/deprovisioning, quarterly access reviews with sign-off. |
| Encryption | TLS 1.2+ in transit; AES-256 (or equivalent) at rest for databases and backups; documented key rotation and revocation. |
| Change management | Every production change approved before deploy, peer-reviewed via PR, tested, with a rollback procedure — auditors sample deployment logs against approvals. |
| Logging & monitoring | Centralized logging, alerting on high-risk events, periodic review with sign-off (Lovable cites 1-year log retention as an example bar). |
| Vendor management | Complete vendor/subprocessor inventory, due diligence at onboarding, annual re-review of critical vendors. |
| Incident response | Written IR plan with severity levels, a named team, 24/7 contacts, and an annual tabletop exercise with documented outcomes. |
| Backup / DR | Tested backups, documented recovery objectives, restore-test evidence. |
The underlying evidence principle: every control has to be shown as designed, assigned, performed, reviewed, and documented across the entire observation period — not just true on the day of the audit.
Sources: secureframe.com/hub/soc-2/trust-services-criteria; drata.com/learn/soc-2; soc2auditors.org/insights/soc-2-controls-list.
Sources: acalytica.com/itgc-audit-vibe-coded-apps (2026); techtarget.com/searchcio (Tenzai, Moltbook, Veracode 45%); wiz.io/blog/critical-vulnerability-base44 (July 2025); secureprivacy.ai/blog/why-you-cant-vibe-code-to-compliance.
| Platform | SOC 2 status |
|---|---|
| Lovable | Type II as of 2025-08-13 (Prescient Assurance) + Type I + ISO 27001:2022; report under NDA; moved to Vanta late 2025. Covers Lovable's platform only, not a generated app's RLS/auth/logging. |
| Bolt / StackBlitz | bolt.new/enterprise claims Type II with SSO/RBAC/audit on Enterprise, but stackblitz.com/enterprise lists no certs and a March 2026 review found only "public signals" — partially unverified; request the report directly. |
| Replit | Type II, annual independent audit (trust.replit.com). Covers Replit's own infrastructure, not user-deployed apps — its Security Center product exists precisely because generated apps ship vulnerabilities. |
| v0 / Vercel | Vercel holds Type 2 (Security, Confidentiality, Availability) + ISO 27001:2022 + PCI DSS + HIPAA. Whether v0 itself is explicitly in scope is unverified — v0 has its own AI subprocessors (Cerebras, Baseten, Raindrop.ai). |
| Base44 (Wix) | base44.com/enterprise states Type II + ISO 27001 on Wix infrastructure, but a May 2026 review claimed no attestation was published — conflicting; the July 2025 Wiz auth-bypass shows the platform cert doesn't secure generated apps either way. |
| Supabase | Type 2 since 2023-05-22 (recurring annual audits) + HIPAA add-on with BAA; report available to Team/Enterprise. Formal Shared Responsibility Model — you still own RLS and auth. |
| Netlify | Type 2 since 2019 + ISO 27001 + PCI DSS; report gated to enterprise/NDA. |
| AWS | SOC 1/2/3 via AWS Artifact, covering infrastructure only — customer owns data protection, IAM, and configuration under the Shared Responsibility Model. |
Sources: lovable.dev/blog/lovable-security (2025-08-13); trust.lovable.dev; risclens.com (StackBlitz, Mar 2026); trust.replit.com; vercel.com/docs/security/compliance; base44.com/enterprise; supabase.com/blog/supabase-soc2-hipaa; netlify.com/security; aws.amazon.com/compliance/soc-faqs.
No — SOC 2 is an AICPA attestation, not a law, so there's no statutory penalty for not having it. In practice it's required the moment an enterprise buyer's procurement team asks for a current SOC 2 Type 2 report, which can end a deal if you don't have one.
Type I attests that your controls are designed correctly at a single point in time. Type II attests that those controls actually operated effectively over an observation window, typically 3–12 months. Enterprise buyers almost always require Type II.
First-year all-in cost typically runs K–K: auditor fees K–K, a compliance-automation platform K–K/yr, readiness work K–K, plus 100–300+ internal engineering hours. Larger scopes can run K–K.
No. A platform's SOC 2 covers only its own infrastructure. AWS states its report "only validates that AWS has secured its environment" and customers must still show they've configured services correctly. Supabase's Shared Responsibility Model and Cursor's SOC 2 scope both explicitly exclude the code you build on top.
No. Roughly 70% of Lovable apps reportedly ship with Supabase Row Level Security disabled, and Wiz found a critical Base44 auth-bypass affecting any private app in July 2025. Auditors test your access control, logging, and change management — not the builder's own platform certification.
Roughly 3–6 months for a first Type II: 4–12 weeks of remediation after the gap assessment, then a 3-month observation window as the standard minimum, followed by the CPA audit itself. Cloud-native startups using automation platforms are sometimes audit-ready in 6–12 weeks.
We audit AI-built apps against SOC 2's Trust Services Criteria — access control, logging, change management — and hand you a fix-it list before procurement finds the gap.
Get a Free Compliance ScanRelated searches: soc 2 compliance checklist · soc 2 type 1 vs type 2 · how much does soc 2 cost · how to get soc 2 certified startup · soc 2 requirements for saas · is Lovable/Replit/Vercel soc 2 compliant · does my app need soc 2 · soc 2 audit timeline how long