Perimattic
Perimattic AI Suite

AI Observability for SOC 2 Type II Compliance

Produce continuous evidence of AI system controls — CC7 system operations, CC8 change management — for SOC 2 Type II audits.

Building for production since 2018DevOps discipline behind every buildGlobal delivery · US · UK · EU · UAE · Singapore · Canada · IndiaEnterprise-grade security by default

99.9%

Uptime SLA

< 5ms

Trace overhead

SOC 2

Certified

OTel

Native

Overview

SOC 2 AI

SOC 2 Type II requires evidence that security controls operated effectively over an audit period. AI observability provides that evidence for LLM systems: immutable traces demonstrating CC7 operational monitoring, CC8 change management documentation, and system integrity signals that auditors can sample and verify.

SOC 2 and AI systems — what auditors look for

Instrument once, observe everything

One OTel SDK, one OTLP exporter. No proprietary agents or middleware sitting in the critical request path.

Eval scores on production traffic

Faithfulness, answer relevancy, and hallucination rates measured on live requests — not just curated test sets.

Compliance evidence built in

Structured audit logs formatted for HIPAA, EU AI Act, DORA, and MAS FEAT. No manual export, no post-processing.

LLM systems are in SOC 2 scope

SOC 2 auditors increasingly encounter LLM systems in scope. The question is not whether a chatbot or agent is a 'system' under SOC 2 — it clearly is if it handles data — but which Trust Services Criteria apply and what evidence satisfies them.

CC6, CC7, and CC8 all apply to AI

Common Criteria 6 (Logical and Physical Access Controls) applies if your LLM system handles customer data. CC7 (System Operations) applies to monitoring — specifically CC7.2 which requires monitoring of the environment for anomalies. CC7.4 requires identifying and responding to incidents. CC8 (Change Management) requires change authorization — relevant when deploying new model versions or updating system prompts.

The evidence gap observability fills

The key gap is evidence: SOC 2 Type II auditors need to sample control operation over the audit period. Without observability infrastructure, you can assert that controls exist but you cannot demonstrate they operated. AI observability provides the audit-ready evidence trail.

Regulation overview

What is
SOC 2 Type II?

A reference overview of SOC 2 Type II — its governing authority, enforcement timeline, applicable penalties, and what it requires of AI systems in practice.

Regulation

SOC 2 Type II

Authority

AICPA (American Institute of CPAs)

In force

Ongoing — annual attestation

Penalties

No direct fines — loss of attestation, customer trust, and contract eligibility

Trust Services Criteria (TSC) for security, availability, processing integrity, confidentiality, and privacy. Type II requires evidence of controls operating effectively over a defined period — typically 6 or 12 months.

Capabilities

Observability controls for SOC 2 AI compliance

Everything your team needs to instrument, evaluate, and audit AI systems in production — with evidence that satisfies your compliance requirements.

CC7 System Operations Evidence

Continuous monitoring traces demonstrating operational oversight of LLM and agent systems, including anomaly detection (unusual prompt patterns, cost spikes, error rate changes).

CC8 Change Management Documentation

Trace evidence of system prompt changes, model version deployments, and configuration updates with timestamps and responsible parties.

Audit-Period Evidence Export

Generate a structured evidence package covering the audit period: control operation logs, incident response records, access logs.

Incident Detection and Response

CC7.4-aligned incident alerting when AI systems exhibit anomalous behaviour (hallucination rate spike, prompt injection attempt, unauthorised model change).

Compliance mapping

How observability satisfies SOC 2 Type II

How AI observability satisfies SOC 2 Trust Services Criteria

RequirementObservability capability
CC6.1 Logical Access ControlsUser-level attribution in traces, role-based trace access
CC7.2 Monitoring for AnomaliesReal-time alerting on hallucination rate, cost spikes, error rate
CC7.4 Incident ResponseIncident detection alerts + structured incident log in traces
CC8.1 Change AuthorizationModel version change logs, system prompt change audit trail
Availability TSC — Uptime MonitoringLLM API latency p99 tracking, circuit-breaker event logs
Frequently Asked Questions

Common questions, answered

Answers to the most common questions about this regulation, what it requires, and how AI observability helps you meet it.

Do LLM systems fall within SOC 2 scope?

Yes, if they handle in-scope data (customer data, financial data, health data). The LLM system — including the model API, orchestration layer, vector database, and observability platform — becomes an in-scope system component. All vendors in the flow need either SOC 2 reports of their own or be covered by your controls.

What SOC 2 evidence do AI traces provide?

AI traces provide: timestamped records of every LLM call (CC7 operational monitoring), access logs by user (CC6 access controls), incident alerts and response records (CC7.4), system prompt change history (CC8 change management), and performance metrics over the audit period (availability TSC).

How does SOC 2 handle AI hallucinations?

SOC 2 doesn't name hallucinations specifically, but CC7.2 (environmental monitoring) and CC7.4 (incident identification and response) cover anomalous system behaviour. A spike in hallucination rate or a pattern of factually incorrect outputs is an operational anomaly that should trigger your CC7 incident process. Observability makes that detection possible.

What is a SOC 2 evidence package for AI systems?

A structured export of: LLM call logs covering the audit period, access control records, incident alerts and response documentation, model deployment change logs, and system availability metrics. Perimattic AI Suite can generate this package on demand for the audit period specified by your auditor.

Does my observability platform need to be SOC 2 compliant?

If your observability platform stores or processes customer data (prompts containing customer information, completions that include PII), yes — it's in scope. Ask your observability vendor for their SOC 2 Type II report. Self-hosting the observability platform keeps it within your own control environment.

Get started

Ready to add observability to your AI systems?

Join the waitlist and we'll show you how Perimattic AI Suite traces your agents, catches hallucinations, and proves compliance.