Does Profound or Peec AI meet SOC 2 requirements for our data: A Practical Decision Framework
As of September 1, 2026, Profound publicly states that it is SOC 2 Type II compliant, and its Trust Center lists a SOC 2 report available through controlled access. Peec AI's official public AI Instructions page says it is pursuing SOC 2 and is not yet certified. If your policy requires a current SOC 2 Type II report, Profound can advance to document review; Peec AI does not clear that gate on public evidence alone. Neither vendor should be approved from a badge or web claim. Review the current report, system scope, period, opinion, exceptions, subprocessors, customer controls and the exact data flow you plan to use.

On this page
Does Profound or Peec AI meet the SOC 2 standard for your data? Public evidence gives different answers. As of September 1, 2026, Profound publicly states that it is SOC 2 Type II compliant. Its Trust Center lists a SOC 2 report behind controlled access. Peec AI's own public page says it is pursuing SOC 2 and is not yet certified.
If a current SOC 2 Type II report is mandatory, Profound can move to document review. Peec AI does not clear that gate on public evidence alone. This is not a final security approval for either vendor. The report, service scope, contract and planned data flow must still match your needs.
What do Profound and Peec AI publicly document about SOC 2?
The comparison below records public evidence, not a substitute for restricted assurance documents. Status and report periods change, so date the procurement record and ask both vendors for a current response.
Review point | Profound | Peec AI | Procurement meaning |
|---|---|---|---|
Public SOC 2 status | Trust Center lists SOC 2 Type 2 | Official AI Instructions says “Pursuing SOC 2 (not yet certified)” | One vendor can enter report review; the other needs current evidence or an exception |
Report access | Trust Center lists a SOC 2 report under controlled access | No public SOC 2 report is identified on the reviewed canonical page | A badge or summary cannot replace the report itself |
Published security controls | Profound's SOC 2 announcement states AES-256 at rest and TLS 1.2 or greater in transit | Peec AI's privacy policy states encryption in transit and at rest, access limits and regular reviews | Control claims help scope questions but do not create equivalent assurance |
Public data terms | Profound's DPA describes security duties, subprocessors and incident notice | Peec AI's privacy policy lists GCP, PostHog EU, Intercom, Sentry and other processors | Map the actual plan, region, integration and data recipients |
Decision today | Continue only after reviewing current restricted evidence | Request current status; apply policy or an approved exception | “Meets our requirement” is a buyer decision, not a vendor slogan |
According to Profound, backups run daily and are retained for 7 days. Its DPA promises notice without undue delay and within 72 hours after awareness of a defined security incident. Those terms are useful inputs, but the signed agreement and purchased service control.
According to Peec AI's policy, core product data is hosted on Google Cloud and product analytics uses PostHog's EU Cloud. It says deletion can leave data briefly in backups. These are relevant data-flow facts. They do not change the company's published statement that SOC 2 is still being pursued.
What does SOC 2 Type II actually establish?
The AICPA describes SOC 2 as a report about controls relevant to security, availability, processing integrity, confidentiality or privacy. Those categories are distinct. A report does not automatically cover all five.
“A SOC 2 examination is a report on controls at a service organization.”
Type II evidence covers control design and operating effectiveness during a stated period. It is not a permanent certificate for every product, region or subprocessor. A clean public claim also does not reveal the auditor's opinion, exceptions, complementary user controls or system boundaries.
For that reason, “SOC 2 compliant” should mean only that the current report is suitable for the decision after review. It should never mean that every security, privacy, legal or AI-governance risk has been accepted.
Which documents should security request before approval?
Use a short evidence packet and assign an owner to each item. The general guide to re-verifying an AI vendor's SOC 2 report explains the deeper renewal review; this table focuses on the initial Profound-or-Peec decision.
Evidence item | What to verify | Pass condition | Escalation trigger |
|---|---|---|---|
Current Type II report | Legal entity, auditor, opinion and testing period | Unmodified or accepted opinion covering the vendor and period | No report, stale period or modified opinion |
System description | Product, environment, regions and data flow | Purchased service and deployment are included | Key module or region sits outside scope |
Test results | Exceptions, causes, affected population and remediation | Findings are understood and residual risk is accepted | Serious or recurring failure lacks proof of closure |
Trust Services Categories | Security plus any required availability, confidentiality, processing integrity or privacy criteria | Required categories appear in scope | Buyer assumes a category that was not examined |
Complementary user controls | Access, configuration, monitoring and offboarding duties assigned to the customer | Every buyer-side control has an owner | Required control is unavailable or unowned |
Subservice organizations | Cloud, model, analytics and support providers; inclusive or carve-out method | Critical dependencies are mapped and reviewed | Important provider is carved out without evidence |
DPA and contract | retention, deletion, training use, location, incident notice and audit rights | Terms match policy and data classification | Marketing language conflicts with signed terms |
Gap evidence | changes after the report period, incidents and remediation | Bridge evidence covers the interval adequately | Material change has no independent or contractual support |
Set a process target: 100% of mandatory evidence items must be resolved before signature. A file that closes 7 out of 8 items is 87.5% complete, but the missing item can still be decisive.
How should the planned data flow change the answer?
Start with the information the service will receive. AI visibility platforms can process user identities, brand names, domains, competitor lists, buyer questions, generated answers, cited URLs, reports and integration credentials. Some deployments can also involve server logs or analytics connections.
Classify each field and remove data the workflow does not need. Then map storage region, retention, deletion, support access, subprocessors and cross-border transfer. Confirm whether prompts or uploaded materials can be used for model training. Do not assume that a SOC 2 report answers an unstated contract question.
A low-risk public-question monitoring pilot can justify a different decision from a deployment that ingests customer records, confidential product plans or server logs. Approval should follow the actual architecture, not the vendor category.
What is the practical decision for each vendor?
For Profound, request the current Type II report and complete the evidence table. Confirm that the report covers the legal entity, platform and period you are buying. Review findings, customer controls, carve-outs and the current DPA. Public status supports further review, not automatic approval.
For Peec AI, ask whether its status has changed since the July 2026 public update. If it now has a report, review it through the same gate. If it remains uncertified and Type II is mandatory, document an approved exception with compensating controls or stop procurement.
The commercial decision should stay separate from assurance. The guide to renewing an AI visibility contract covers value and operating fit. Security approval answers a different question: whether the evidence and controls reduce the planned data risk to an acceptable level.
This framework is security and procurement guidance, not legal advice. The safest conclusion is precise: Profound publicly presents Type II evidence for review; Peec AI's current public page does not. Your team decides whether either vendor satisfies its rule after examining restricted evidence and signed terms.
Which primary sources support this assessment?
Frequently asked questions
Is Profound SOC 2 Type II compliant?
Profound publicly states that it is SOC 2 Type II compliant, and its Trust Center lists a SOC 2 report available through controlled access. Request and review the current report before relying on that status.
Is Peec AI SOC 2 certified?
Peec AI's official AI Instructions page, updated July 2026, says it is pursuing SOC 2 and is not yet certified. Ask the vendor for current written evidence because assurance status can change after a public-page update.
Does SOC 2 Type II prove that our data is safe?
No. It provides scoped assurance about described controls over a stated period. Your team must still assess whether the purchased service, data flow, regions, subprocessors, findings and contract match its requirements.
Can we approve a vendor that does not have SOC 2?
That depends on your policy, data sensitivity, criticality and compensating controls. If a current Type II report is a mandatory gate, an uncertified vendor needs a documented exception or cannot be approved.
Topics
- Profound SOC 2
- Peec AI SOC 2
- AI visibility vendor security
- SOC 2 Type II vendor review
- AI vendor data requirements
Xtrusio
AI visibility research
See what AI says about your brand
Access requests are temporarily paused while the new platform is prepared.
View access updateKeep reading

Reddit Pro for AI Visibility: A Practical Business Guide
A practical guide for businesses to listen, contribute and measure on Reddit while protecting community trust and improving AI visibility.

AEO Tools and GEO Tools: What Actually Works for Tracking Your Brand in AI Answers
Compare AEO and GEO tools for tracking brand visibility in ChatGPT, Gemini and other AI answers, with 2026 pricing, use cases and practical buying criteria.