Get a Quote
Compliance › SOC 2

SOC 2 Compliance for AI-Built Apps

SOC 2 isn't a law — it's an AICPA attestation where an independent CPA firm audits your controls against the Trust Services Criteria. Nobody is legally required to have it; it's triggered the moment enterprise procurement asks "do you have a current SOC 2 Type 2?" First-year cost for a startup typically runs K–K, and the key nuance for AI-built apps is this: your builder's or host's SOC 2 covers their own infrastructure, not the app you shipped on top of it.

Get a Free Compliance Scan See Audit Pricing
Who It Applies To

What triggers a SOC 2 requirement

There's no statutory penalty for skipping SOC 2 — the "penalty" is lost revenue. Enterprise buyers routinely send ~200-item security questionnaires where SOC 2 Type 2 is the headline question, and not having a report can end a deal outright. Type I attests to control design at a single point in time; Type II attests to design and operating effectiveness over an observation window, typically 3–12 months — and Type II is what enterprise buyers actually require.

TriggerWhy it happens
First enterprise dealThe #1 reason companies start the process — a prospect's security team requests the report before signing.
Vendor-risk reviewsThird parties account for over 60% of enterprise cyber risk, so buyers formally review every vendor.
Fundraising / partnershipsVendor-published surveys suggest roughly 70% of VCs prefer SOC 2-compliant startups and over 60% of businesses are more likely to partner with one (directional, not audited stats).
Sales-cycle frictionCompliance gaps reportedly add 2–4 weeks to B2B SaaS sales cycles even when the deal survives; SOC 2 adoption reportedly surged 40% in 2024.

Sources: aicpa-cima.com; trycomp.ai/hub/soc-2-cost-breakdown; drata.com/learn/soc-2; acalytica.com/itgc-audit-vibe-coded-apps.

The Rule

What auditors actually test

Control areaWhat's evaluated
Access controlMFA or SSO on sensitive systems, RBAC, documented provisioning/deprovisioning, quarterly access reviews with sign-off.
EncryptionTLS 1.2+ in transit; AES-256 (or equivalent) at rest for databases and backups; documented key rotation and revocation.
Change managementEvery production change approved before deploy, peer-reviewed via PR, tested, with a rollback procedure — auditors sample deployment logs against approvals.
Logging & monitoringCentralized logging, alerting on high-risk events, periodic review with sign-off (Lovable cites 1-year log retention as an example bar).
Vendor managementComplete vendor/subprocessor inventory, due diligence at onboarding, annual re-review of critical vendors.
Incident responseWritten IR plan with severity levels, a named team, 24/7 contacts, and an annual tabletop exercise with documented outcomes.
Backup / DRTested backups, documented recovery objectives, restore-test evidence.

The underlying evidence principle: every control has to be shown as designed, assigned, performed, reviewed, and documented across the entire observation period — not just true on the day of the audit.

Sources: secureframe.com/hub/soc-2/trust-services-criteria; drata.com/learn/soc-2; soc2auditors.org/insights/soc-2-controls-list.

The Core Problem

Why AI-built apps fail SOC 2 audits

  • No change-management trail. "Prompt-to-production in minutes" with no PRs, peer review, or design docs is the single most common ITGC/SOC 2 failure for AI-built apps.
  • No audit logging or error handling by default. Tenzai tested 15 production AI-built apps in December 2025 and found 69 vulnerabilities total, including missing security headers and CSRF protection across all 15.
  • Broken access control. Roughly 70% of Lovable apps reportedly ship with Supabase Row Level Security disabled; Wiz found a critical Base44 auth-bypass (any private app reachable via its public app ID), fixed within 24 hours in July 2025.
  • Secrets shipped in client code. The Moltbook AI-built social app exposed 1.5 million API auth tokens and 35,000 emails within 72 hours of launch, in January 2026.
  • Baseline vulnerability rates. Veracode's 2025 research found 45% of AI-generated code introduces OWASP Top 10 flaws; the Cloud Security Alliance cites a figure around 62%.
  • No vendor inventory or written policies. AI-built apps routinely lack the structural elements — audit logs, consent flows, access-control granularity — that SOC 2 requires as evidence.
  • The key nuance: platform SOC 2 ≠ your SOC 2. AWS's own language is explicit — its SOC 2 "only validates that AWS has secured its environment," and customers "still need to show you've configured services correctly." Supabase publishes a formal Shared Responsibility Model requiring customers to implement their own controls, and Cursor's SOC 2 explicitly excludes the code users write or the infrastructure they deploy to.

Sources: acalytica.com/itgc-audit-vibe-coded-apps (2026); techtarget.com/searchcio (Tenzai, Moltbook, Veracode 45%); wiz.io/blog/critical-vulnerability-base44 (July 2025); secureprivacy.ai/blog/why-you-cant-vibe-code-to-compliance.

Platform By Platform

SOC 2 status, by platform — and what it doesn't cover

PlatformSOC 2 status
LovableType II as of 2025-08-13 (Prescient Assurance) + Type I + ISO 27001:2022; report under NDA; moved to Vanta late 2025. Covers Lovable's platform only, not a generated app's RLS/auth/logging.
Bolt / StackBlitzbolt.new/enterprise claims Type II with SSO/RBAC/audit on Enterprise, but stackblitz.com/enterprise lists no certs and a March 2026 review found only "public signals" — partially unverified; request the report directly.
ReplitType II, annual independent audit (trust.replit.com). Covers Replit's own infrastructure, not user-deployed apps — its Security Center product exists precisely because generated apps ship vulnerabilities.
v0 / VercelVercel holds Type 2 (Security, Confidentiality, Availability) + ISO 27001:2022 + PCI DSS + HIPAA. Whether v0 itself is explicitly in scope is unverified — v0 has its own AI subprocessors (Cerebras, Baseten, Raindrop.ai).
Base44 (Wix)base44.com/enterprise states Type II + ISO 27001 on Wix infrastructure, but a May 2026 review claimed no attestation was published — conflicting; the July 2025 Wiz auth-bypass shows the platform cert doesn't secure generated apps either way.
SupabaseType 2 since 2023-05-22 (recurring annual audits) + HIPAA add-on with BAA; report available to Team/Enterprise. Formal Shared Responsibility Model — you still own RLS and auth.
NetlifyType 2 since 2019 + ISO 27001 + PCI DSS; report gated to enterprise/NDA.
AWSSOC 1/2/3 via AWS Artifact, covering infrastructure only — customer owns data protection, IAM, and configuration under the Shared Responsibility Model.

Sources: lovable.dev/blog/lovable-security (2025-08-13); trust.lovable.dev; risclens.com (StackBlitz, Mar 2026); trust.replit.com; vercel.com/docs/security/compliance; base44.com/enterprise; supabase.com/blog/supabase-soc2-hipaa; netlify.com/security; aws.amazon.com/compliance/soc-faqs.

The Fix

Remediation path

  • Scope it — pick criteria (usually Security-only first) and the system boundary; run a readiness/gap assessment (K–K, or via an automation platform).
  • Fix engineering gaps — enforce MFA/SSO, RBAC and least privilege, remove secrets from client code into a secrets manager, enable RLS/authorization on the data layer.
  • Add centralized audit logging and alerting, and route every change through PR review and CI with recorded approvals.
  • Test backups and document recovery objectives.
  • Write and adopt the policy set — infosec, access control, incident response, vendor management, change management, data classification — with employee acknowledgment.
  • Build a vendor/subprocessor inventory and collect each vendor's SOC 2 or security documentation (builder, host, database, LLM APIs).
  • Deploy compliance automation (Vanta, Drata, Secureframe, Sprinto; roughly K–K/yr) for continuous monitoring and automated evidence collection.
  • Run the observation window — 3 months is standard for a first Type II — then the CPA audit; consider Type I first for a faster point-in-time report.
What changed recently: There is still no dedicated AICPA "AI module" for SOC 2 as of April 2026 — auditors interpret the existing 2017 Trust Services Criteria (as revised 2022) against AI-specific risks, and AI-aware auditors now ask for model lineage, prompt/inference logs with PII redaction, drift monitoring, and vendor risk assessments for every third-party LLM. Buyers are also probing how compliance-automation reports were produced after scrutiny of one vendor's practices surfaced in 2026, which Lovable publicly addressed by citing its migration to Vanta and its Prescient Assurance audit.
FAQ

SOC 2 compliance questions, answered

Does my app legally need SOC 2 compliance?

No — SOC 2 is an AICPA attestation, not a law, so there's no statutory penalty for not having it. In practice it's required the moment an enterprise buyer's procurement team asks for a current SOC 2 Type 2 report, which can end a deal if you don't have one.

What's the difference between SOC 2 Type 1 and Type 2?

Type I attests that your controls are designed correctly at a single point in time. Type II attests that those controls actually operated effectively over an observation window, typically 3–12 months. Enterprise buyers almost always require Type II.

How much does SOC 2 cost for a startup?

First-year all-in cost typically runs K–K: auditor fees K–K, a compliance-automation platform K–K/yr, readiness work K–K, plus 100–300+ internal engineering hours. Larger scopes can run K–K.

If my host (AWS, Supabase, Vercel) has SOC 2, does my app automatically have it too?

No. A platform's SOC 2 covers only its own infrastructure. AWS states its report "only validates that AWS has secured its environment" and customers must still show they've configured services correctly. Supabase's Shared Responsibility Model and Cursor's SOC 2 scope both explicitly exclude the code you build on top.

Is my Lovable or Base44 app SOC 2 ready out of the box?

No. Roughly 70% of Lovable apps reportedly ship with Supabase Row Level Security disabled, and Wiz found a critical Base44 auth-bypass affecting any private app in July 2025. Auditors test your access control, logging, and change management — not the builder's own platform certification.

How long does a SOC 2 audit take?

Roughly 3–6 months for a first Type II: 4–12 weeks of remediation after the gap assessment, then a 3-month observation window as the standard minimum, followed by the CPA audit itself. Cloud-native startups using automation platforms are sometimes audit-ready in 6–12 weeks.

Would your app pass a SOC 2 evidence request today?

We audit AI-built apps against SOC 2's Trust Services Criteria — access control, logging, change management — and hand you a fix-it list before procurement finds the gap.

Get a Free Compliance Scan

Related searches: soc 2 compliance checklist · soc 2 type 1 vs type 2 · how much does soc 2 cost · how to get soc 2 certified startup · soc 2 requirements for saas · is Lovable/Replit/Vercel soc 2 compliant · does my app need soc 2 · soc 2 audit timeline how long