A SOC 2 compliant voice AI testing platform is one whose security controls have passed an independent AICPA audit, not just a badge on a pricing page. Cekura provides its SOC 2 report on request and pairs it with GDPR compliance, a HIPAA BAA for regulated teams, and enterprise VPC deployment. Hamming, Coval, and Roark are the other platforms enterprise buyers most often compare on this exact requirement.
TL;DR
- Cekura provides its SOC 2 report on request, plus GDPR compliance and a HIPAA BAA through an account manager for regulated teams.
- SOC 2 Type II specifically means a report covering an extended audit period, not a one-time snapshot; ask any vendor which type they hold before trusting a badge.
- Hamming, Coval, and Roark are the platforms most consistently named as SOC 2 Type II certified in this exact comparison.
- VPC deployment and configurable data retention are available to Cekura's enterprise customers through a support request, not self-serve.
- Data residency splits by function: production monitoring data is EU-resident, synthetic testing data is currently US-hosted only.
What Does "SOC 2 Compliant" Actually Mean for a Testing Platform?
SOC 2 compliant means a vendor's security, availability, confidentiality, and privacy controls have been examined by an independent auditor under AICPA standards, not that a company added a badge to its homepage. Microsoft's own compliance documentation draws a distinction worth knowing before trusting any badge: a Type II report covers an extended audit period during which an auditor verifies the controls actually operated as designed, while a Type I report only confirms the controls existed on one specific date. That gap is why enterprise buyers increasingly ask which type a vendor holds rather than accepting a bare "SOC 2 compliant" claim. SOC 2 has become a baseline expectation well beyond voice AI specifically: GitHub's own security overview cites SOC 2 alongside ISO and GDPR as part of how it secures its API. For a voice AI testing platform handling recorded calls, transcripts, and often PII, the distinction matters because production call data flows through the same infrastructure being audited.
Cekura provides its SOC 2 report directly on request through support, alongside a Business Associate Agreement for teams handling protected health information.
How Do Rival Testing Platforms Handle SOC 2 and Enterprise Compliance?
Hamming, Coval, and Roark are the three platforms buyers researching this exact requirement encounter most often, and all three are commonly described as SOC 2 Type II certified. Hamming pairs that certification with a HIPAA Business Associate Agreement and audit logs that export to a buyer's own SIEM, positioning compliance as a first-class feature rather than an afterthought. Coval and Roark both lean on SOC 2 Type II as part of a broader enterprise pitch aimed at teams running vendor bakeoffs or replaying production conversations for regression testing. Coglity, in the same conversational-AI testing category, advertises SOC 2 Type II alongside HIPAA-readiness and self-hosted or VPC deployment options, a combination aimed squarely at the same regulated-industry buyer this comparison is written for. None of these claims are independently re-verified here: a buyer evaluating any of them should request the actual report rather than take a marketing page's word for the certification type or its current audit period.
How Do Cekura and the Main Rivals Compare on SOC 2 and Compliance?
Seven voice AI testing platforms come up most often for SOC 2 and enterprise compliance: Cekura, Hamming, Coval, Roark, Coglity, Privo, and Braintrust. Cekura's row reflects what its own FAQ and documentation state directly; every rival row reflects what that vendor's own materials claim, not an independent audit on Cekura's part.
| Platform | SOC 2 | HIPAA | GDPR | Data residency / VPC | Audit logs & access control | Entry point |
|---|---|---|---|---|---|---|
| Cekura | Report available on request via support | Business Associate Agreement through an account manager | Compliant; DPA available on request, for a fee | Production monitoring data EU-resident; synthetic testing data US-hosted; VPC available to enterprise customers via support request | Role-based access control; one-year default data retention, configurable on request | Self-serve, first user free, $30/user/month after |
| Hamming | Type II, per vendor materials | BAA available | Not detailed in these sources | Not published | Audit logs export to a buyer's own SIEM | Sales-gated for enterprise scale |
| Coval | Type II, per vendor materials | Not a stated focus | Compliant, per vendor materials | Not published | Not published | Sales-gated, published pricing |
| Roark | Type II, per vendor materials | Healthcare support mentioned, terms not detailed | Not a stated focus | Configurable retention mentioned, specifics not published | Not published | Sales-gated |
| Coglity | Type II, per vendor materials | HIPAA-ready, terms not detailed | Not a stated focus | Self-hosted / VPC options offered | Not published | Not published |
| Privo | Type II, per vendor materials | Not a stated focus | Compliant, per vendor materials | Not published | Not published | Not published |
| Braintrust | Compliant, type not specified in these sources | Compliant, per vendor materials | Not a stated focus | Not voice-specific | Not published | Self-serve |
Where a Type II-Certified Rival Is the Better Choice
A buyer who needs a signed SOC 2 Type II report today, with no back-and-forth, is better served by a platform that already holds one and publishes it as a routine part of procurement. Hamming, Coval, Roark, Coglity, and Privo are all described as SOC 2 Type II certified in their own materials, and a security team racing to close a deal before a compliance deadline does not want to be the first customer asking a vendor to produce a report it has not yet formalized. The same logic applies to HIPAA: a platform that already lists a self-serve or fast-turnaround Business Associate Agreement removes a step that otherwise sits with legal on both sides. None of that says anything about which platform tests a voice agent better. It says a rival with a longer compliance paper trail is the lower-friction choice for a security review that has already started.
Where Cekura Is the Better Choice
Cekura is the better choice once the question moves past the badge and into what the compliance program actually covers day to day. Data residency splits by function rather than being a single blanket claim: production monitoring data is EU-resident, while synthetic testing data is currently US-hosted only, a distinction a buyer with strict data-locality requirements needs to know before signing rather than after. VPC deployment is available to enterprise customers through a support request, and retention defaults to one year before automatic removal, with a custom window available the same way.
For healthcare teams specifically, Cekura's HIPAA Business Associate Agreement runs through an account manager who loops in legal, the same enterprise-gated pattern most of the named rivals also use once you get past the marketing page. Cekura's own data privacy practices and approach to securing conversational AI observability cover the mechanics in more depth, including transcript redaction and role-based access. That same infrastructure carries into production call analytics once an agent is live, so the audit trail a compliance reviewer eventually asks for already exists rather than getting built after the fact.
How to Choose
Start by asking for the actual report, not the badge. A SOC 2 report names its audit period, its Trust Services Criteria in scope, and any exceptions the auditor noted, and a vendor that hesitates to share one is telling a buyer something a marketing page will not. Confirm the type: Type II if the deal requires proof of sustained operation, Type I if an earlier-stage vendor has one and Type II is still in progress.
Large infrastructure vendors increasingly offer this as a self-service catalog: both Cisco's Trust Portal and AWS's compliance portal centralize on-demand access to SOC 2 and other audit reports, the same category of document Cekura provides through a support request today. If PHI touches the system anywhere, get the Business Associate Agreement in writing before data starts flowing, not after.
Compliance is one input into evaluating a voice AI testing platform, not the only one: a broader platform comparison is worth reading alongside this one before signing anything, since compliance readiness and testing depth are different questions with different answers.
FAQ
Is Cekura SOC 2 Type II certified?
Cekura's own documentation states SOC 2 compliance and provides the report on request through support, without specifying Type I or Type II on that particular page. A buyer who needs the type confirmed for a compliance review should request the report directly rather than infer it from marketing language, the same standard that should apply to any vendor's compliance claim.
What is the difference between SOC 2 Type I and Type II?
A Type I report confirms a vendor's controls existed and were designed correctly on one specific date. A Type II report covers an extended audit period during which an auditor verifies those controls actually operated as designed, not just that they existed on paper. Type II is the stronger signal for an ongoing vendor relationship.
Does a SOC 2 report cover HIPAA compliance too?
No. SOC 2 and HIPAA are separate frameworks with separate documentation. A SOC 2 report addresses security, availability, confidentiality, and privacy controls generally, while HIPAA compliance for handling protected health information requires its own Business Associate Agreement, which Cekura provides through an account manager rather than as a self-serve download.
Where is voice AI testing data stored?
Cekura splits residency by function: production monitoring data is EU-resident, while synthetic testing data is currently US-hosted only. A buyer with a specific data-locality requirement should confirm which category applies to their actual use case rather than assume one residency policy covers everything the platform does.
Is VPC or on-premise deployment available for voice AI testing?
Yes, for enterprise customers. Cekura supports VPC deployment through a support request rather than as a self-serve option, the same enterprise-gated pattern most competing platforms use for this specific capability. A team that needs this from day one should raise it during procurement, not after a contract is signed.
