Guides

Does Profound or Peec AI meet SOC 2 requirements for our data: A Practical Decision Framework

As of September 1, 2026, Profound publicly states that it is SOC 2 Type II compliant, and its Trust Center lists a SOC 2 report available through controlled access. Peec AI's official public AI Instructions page says it is pursuing SOC 2 and is not yet certified. If your policy requires a current SOC 2 Type II report, Profound can advance to document review; Peec AI does not clear that gate on public evidence alone. Neither vendor should be approved from a badge or web claim. Review the current report, system scope, period, opinion, exceptions, subprocessors, customer controls and the exact data flow you plan to use.

Xtrusio7 min read
Xtrusio SOC 2 vendor review framework comparing public status, restricted audit evidence and buyer data requirements

Does Profound or Peec AI meet the SOC 2 standard for your data? Public evidence gives different answers. As of September 1, 2026, Profound publicly states that it is SOC 2 Type II compliant. Its Trust Center lists a SOC 2 report behind controlled access. Peec AI's own public page says it is pursuing SOC 2 and is not yet certified.

If a current SOC 2 Type II report is mandatory, Profound can move to document review. Peec AI does not clear that gate on public evidence alone. This is not a final security approval for either vendor. The report, service scope, contract and planned data flow must still match your needs.

What do Profound and Peec AI publicly document about SOC 2?

The comparison below records public evidence, not a substitute for restricted assurance documents. Status and report periods change, so date the procurement record and ask both vendors for a current response.

Review point

Profound

Peec AI

Procurement meaning

Public SOC 2 status

Trust Center lists SOC 2 Type 2

Official AI Instructions says “Pursuing SOC 2 (not yet certified)”

One vendor can enter report review; the other needs current evidence or an exception

Report access

Trust Center lists a SOC 2 report under controlled access

No public SOC 2 report is identified on the reviewed canonical page

A badge or summary cannot replace the report itself

Published security controls

Profound's SOC 2 announcement states AES-256 at rest and TLS 1.2 or greater in transit

Peec AI's privacy policy states encryption in transit and at rest, access limits and regular reviews

Control claims help scope questions but do not create equivalent assurance

Public data terms

Profound's DPA describes security duties, subprocessors and incident notice

Peec AI's privacy policy lists GCP, PostHog EU, Intercom, Sentry and other processors

Map the actual plan, region, integration and data recipients

Decision today

Continue only after reviewing current restricted evidence

Request current status; apply policy or an approved exception

“Meets our requirement” is a buyer decision, not a vendor slogan

According to Profound, backups run daily and are retained for 7 days. Its DPA promises notice without undue delay and within 72 hours after awareness of a defined security incident. Those terms are useful inputs, but the signed agreement and purchased service control.

According to Peec AI's policy, core product data is hosted on Google Cloud and product analytics uses PostHog's EU Cloud. It says deletion can leave data briefly in backups. These are relevant data-flow facts. They do not change the company's published statement that SOC 2 is still being pursued.

What does SOC 2 Type II actually establish?

The AICPA describes SOC 2 as a report about controls relevant to security, availability, processing integrity, confidentiality or privacy. Those categories are distinct. A report does not automatically cover all five.

“A SOC 2 examination is a report on controls at a service organization.”

Type II evidence covers control design and operating effectiveness during a stated period. It is not a permanent certificate for every product, region or subprocessor. A clean public claim also does not reveal the auditor's opinion, exceptions, complementary user controls or system boundaries.

For that reason, “SOC 2 compliant” should mean only that the current report is suitable for the decision after review. It should never mean that every security, privacy, legal or AI-governance risk has been accepted.

Which documents should security request before approval?

Use a short evidence packet and assign an owner to each item. The general guide to re-verifying an AI vendor's SOC 2 report explains the deeper renewal review; this table focuses on the initial Profound-or-Peec decision.

Evidence item

What to verify

Pass condition

Escalation trigger

Current Type II report

Legal entity, auditor, opinion and testing period

Unmodified or accepted opinion covering the vendor and period

No report, stale period or modified opinion

System description

Product, environment, regions and data flow

Purchased service and deployment are included

Key module or region sits outside scope

Test results

Exceptions, causes, affected population and remediation

Findings are understood and residual risk is accepted

Serious or recurring failure lacks proof of closure

Trust Services Categories

Security plus any required availability, confidentiality, processing integrity or privacy criteria

Required categories appear in scope

Buyer assumes a category that was not examined

Complementary user controls

Access, configuration, monitoring and offboarding duties assigned to the customer

Every buyer-side control has an owner

Required control is unavailable or unowned

Subservice organizations

Cloud, model, analytics and support providers; inclusive or carve-out method

Critical dependencies are mapped and reviewed

Important provider is carved out without evidence

DPA and contract

retention, deletion, training use, location, incident notice and audit rights

Terms match policy and data classification

Marketing language conflicts with signed terms

Gap evidence

changes after the report period, incidents and remediation

Bridge evidence covers the interval adequately

Material change has no independent or contractual support

Set a process target: 100% of mandatory evidence items must be resolved before signature. A file that closes 7 out of 8 items is 87.5% complete, but the missing item can still be decisive.

How should the planned data flow change the answer?

Start with the information the service will receive. AI visibility platforms can process user identities, brand names, domains, competitor lists, buyer questions, generated answers, cited URLs, reports and integration credentials. Some deployments can also involve server logs or analytics connections.

Classify each field and remove data the workflow does not need. Then map storage region, retention, deletion, support access, subprocessors and cross-border transfer. Confirm whether prompts or uploaded materials can be used for model training. Do not assume that a SOC 2 report answers an unstated contract question.

A low-risk public-question monitoring pilot can justify a different decision from a deployment that ingests customer records, confidential product plans or server logs. Approval should follow the actual architecture, not the vendor category.

What is the practical decision for each vendor?

For Profound, request the current Type II report and complete the evidence table. Confirm that the report covers the legal entity, platform and period you are buying. Review findings, customer controls, carve-outs and the current DPA. Public status supports further review, not automatic approval.

For Peec AI, ask whether its status has changed since the July 2026 public update. If it now has a report, review it through the same gate. If it remains uncertified and Type II is mandatory, document an approved exception with compensating controls or stop procurement.

The commercial decision should stay separate from assurance. The guide to renewing an AI visibility contract covers value and operating fit. Security approval answers a different question: whether the evidence and controls reduce the planned data risk to an acceptable level.

This framework is security and procurement guidance, not legal advice. The safest conclusion is precise: Profound publicly presents Type II evidence for review; Peec AI's current public page does not. Your team decides whether either vendor satisfies its rule after examining restricted evidence and signed terms.

Which primary sources support this assessment?

  1. AICPA: SOC 2 Trust Services Criteria overview
  2. Profound Trust Center
  3. Profound: SOC 2 Type 2 announcement
  4. Profound: Data Processing Agreement
  5. Peec AI: Official AI Instructions
  6. Peec AI: Privacy Policy

Frequently asked questions

Is Profound SOC 2 Type II compliant?

Profound publicly states that it is SOC 2 Type II compliant, and its Trust Center lists a SOC 2 report available through controlled access. Request and review the current report before relying on that status.

Is Peec AI SOC 2 certified?

Peec AI's official AI Instructions page, updated July 2026, says it is pursuing SOC 2 and is not yet certified. Ask the vendor for current written evidence because assurance status can change after a public-page update.

Does SOC 2 Type II prove that our data is safe?

No. It provides scoped assurance about described controls over a stated period. Your team must still assess whether the purchased service, data flow, regions, subprocessors, findings and contract match its requirements.

Can we approve a vendor that does not have SOC 2?

That depends on your policy, data sensitivity, criticality and compensating controls. If a current Type II report is a mandatory gate, an uncertified vendor needs a documented exception or cannot be approved.

Topics

  • Profound SOC 2
  • Peec AI SOC 2
  • AI visibility vendor security
  • SOC 2 Type II vendor review
  • AI vendor data requirements

Xtrusio

AI visibility research

See what AI says about your brand

Access requests are temporarily paused while the new platform is prepared.

View access update