Enlarged image

Sendspark Renews SOC 2 Type 2: Why Independent Security Audits Matter More Now That Anyone Can Build Software With AI

· · ·
Paper-craft purple shield with a gold padlock, representing Sendspark's SOC 2 Type 2 security attestation

On August 29, 2026, Thoropass Assurance issued Sendspark's renewed SOC 2 Type 2 report: 57 security controls examined across twelve months, no exceptions noted. Five days later, on September 3, OpenAI released GPT-6 Astra and described it in the model's own system card as "a significant step up in cyber capabilities" that meets the company's Critical threshold. Those two dates belong in the same paragraph. The tools that now let anyone build working software in an afternoon are the same tools that make it trivial to find the mistakes in that software. Sendspark is an AI video personalization platform for B2B sales, which means your CRM contacts, your cloned voice, and your prospects' viewing data all pass through our systems. This post explains what our SOC 2 Type 2 report covers, what SOC 2 actually is, and why an independent audit is becoming the minimum bar for any vendor that touches your pipeline.

Published September 2026

Key Takeaways

  • Sendspark's 2026 SOC 2 Type 2 report, issued by Thoropass Assurance on August 29, 2026, covers the AICPA Security trust services criteria for August 1, 2025 through July 31, 2026, with 57 controls examined and no exceptions noted.
  • A SOC 2 Type 2 report tests whether security controls actually operated over a period of months. A Type 1 report only confirms they were designed properly on a single day. Ask every vendor for Type 2.
  • AI-generated code is not getting safer. Veracode's 2026 GenAI Code Security Report found a 56% average security pass rate, up one point from 2025, while AI now writes roughly half of all committed code.
  • Hardcoded secrets on public GitHub grew 34% year over year to 28.65 million in 2025, according to GitGuardian, and commits assisted by AI coding tools leaked secrets at more than double the baseline rate.
  • G2's 2026 Buyer Behavior Report found IT security review is the single largest delay between selecting a vendor and completing a purchase, cited by 39% of buyers. A current SOC 2 Type 2 report is how a vendor removes that delay.

What Does Sendspark's 2026 SOC 2 Type 2 Report Cover?

Sendspark's 2026 SOC 2 Type 2 report is an independent attestation from Thoropass Assurance that our security controls were suitably designed and operated effectively from August 1, 2025 through July 31, 2026. The auditor examined 57 controls against the AICPA Security trust services criteria and noted no exceptions in any control it tested. The report also records no security incidents during the period.

AICPA SOC 2 Type II badge issued through Thoropass for Sendspark's 2026 attestation

This is a renewal, not a first report. Keeping a SOC 2 Type 2 report current means going through a fresh observation period every year, producing evidence for every control, and letting an outside CPA firm sample and test that evidence. Thoropass Assurance is a licensed certified public accounting firm registered with the AICPA, so the opinion in our report carries the same professional weight as any other CPA attestation.

The controls the auditor tested fall into the areas a security team actually cares about:

  • Encryption. Customer data is encrypted in transit and at rest.
  • Access control. Access is granted by role on the principle of least privilege, production infrastructure requires multi-factor authentication, and access is removed within 24 hours when someone leaves.
  • Vulnerability management. Continuous vulnerability scanning of the environment, routine patching, and an annual penetration test against production.
  • Monitoring and incident response. Centralized logging, intrusion detection, alerting to named owners, a documented incident response plan that is tested every year, and post-mortems after any significant operational issue.
  • Change management. Code changes are reviewed and approved before they reach production.
  • Governance and vendor risk. A risk committee that meets quarterly, annual review of our own vendors' attestation reports, security awareness training, and a background-check policy for new hires.
Item Sendspark's 2026 SOC 2 Type 2 report
Report type SOC 2 Type 2 (design and operating effectiveness over a period)
Trust services criteria in scope Security (the AICPA common criteria)
Observation period August 1, 2025 to July 31, 2026 (12 months)
Independent auditor Thoropass Assurance, a licensed CPA firm registered with the AICPA
Report date August 29, 2026
Controls examined 57
Exceptions noted None
Security incidents in the period None
Hosting subservice organizations Google Cloud Platform and MongoDB Atlas
How to obtain the report Request it through the Sendspark Trust Center, alongside our 2026 penetration test report; both are shared under NDA

Two scope notes, because a SOC 2 report is only useful if you know what it does not say. First, this cycle covers the Security category. The other four trust services categories, availability, processing integrity, confidentiality, and privacy, are not in scope this year. Second, like nearly every cloud company, we use a carve-out method for our hosting providers: Google Cloud Platform and MongoDB Atlas are responsible for the physical and environmental controls in their data centers, and our auditor relies on their own SOC reports for those rather than re-testing them. Your security team should read our report alongside theirs.

What Is SOC 2 Type 2, and How Is It Different From Type 1?

SOC 2 is an attestation framework from the AICPA (American Institute of Certified Public Accountants) in which an independent CPA firm examines a service organization's controls against five trust services criteria: security, availability, processing integrity, confidentiality, and privacy. A Type 2 report tests whether those controls operated effectively over a defined period, usually three to twelve months, not just whether they existed.

The AICPA describes a SOC 2 examination as "a report on controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy." Security is the mandatory category, referred to as the common criteria, and it appears in every SOC 2 report. The other four are added when a customer base needs them.

Type 1 versus Type 2: what actually changes

A SOC 2 Type 1 report is a snapshot. The auditor confirms that on a single date the controls were suitably designed. A SOC 2 Type 2 report is a film. The auditor selects samples from across the whole observation period and tests whether each control actually operated, every time, the way the company says it does. That is why Type 2 takes a year to renew and why a buyer's security team should insist on it.

Question SOC 2 Type 1 SOC 2 Type 2
What is tested? Design of controls Design and operating effectiveness of controls
Over what time? A single point in time An observation period, typically 3 to 12 months
What evidence? Policies, configurations, walkthroughs Sampled evidence that controls ran throughout the period
Can it show exceptions? Rarely; there is no operating history to test Yes; every deviation the auditor finds is listed
How often is it renewed? Usually once, as a stepping stone Annually, with a fresh observation period each cycle
What a buyer should ask for Acceptable for a brand-new vendor's first year The standard for any vendor handling customer data

Is SOC 2 a certification?

Strictly speaking, no. SOC 2 is an attestation, not a certification. There is no certificate and no pass-or-fail stamp from the AICPA. The output is a detailed report in which a CPA firm gives its professional opinion on management's description of the system and on whether the controls were suitably designed and operated effectively. You will still see "SOC 2 certified" everywhere, including on compliance badges, because the shorthand stuck. The distinction matters in practice: a badge tells you a report exists, and only the report tells you what was tested and what the auditor found.

Record One Video. AI Personalizes Thousands.

Sendspark is the AI video personalization platform for B2B sales. Record once, and AI voice cloning generates thousands of individually personalized videos with dynamic backgrounds and personalized thumbnails — each prospect hears their name, sees their website, in your voice. Sales teams see 2-3x more replies.

Get Started Now

Why Does SOC 2 Matter More Now That Anyone Can Build Software With AI?

Independent audits matter more because the volume of software is exploding while its baseline security is not improving. Veracode's 2026 GenAI Code Security Report found that AI now writes roughly half of all committed code and that only 56% of AI-generated samples pass security tests. When anyone can ship a working app in a weekend, an outside auditor's opinion is the only proof a buyer can rely on.

Frontier models raise the ceiling for attackers, not just builders

OpenAI released GPT-6 Astra to a limited preview on September 3, 2026, with a general rollout the following day, and gave early access to vetted cybersecurity customers first. The reason is in the model's system card:

"GPT-6 Astra is a significant step up in cyber capabilities and meets our Critical threshold."

OpenAI, GPT-6 Astra System Card, September 2026

Read that alongside the launch announcement, which calls the model a new state of the art for "computer use, browsing, software engineering, cybersecurity." A model that can write a full application can also read one, find the hardcoded key or the missing authorization check, and write the exploit. Offensive and defensive capability arrive in the same release. That does not make frontier models dangerous to use; Sendspark uses AI throughout the product. It does mean the cost of shipping insecure software just went up for everyone who ships it.

Vibe coding ships vulnerabilities at scale

Vibe coding is the practice of building software by describing what you want to an AI model and accepting the generated code with little or no review. It is a wonderful way to prototype and a risky way to handle other people's data. The research is consistent on this point:

  • Veracode's 2026 GenAI Code Security Report measured an average security pass rate of 56% across models, "barely changed from 55% in the first report" a year earlier. The best model tested reached only 68%.
  • A Stanford study led by Neil Perry and Dan Boneh, published at ACM CCS 2023, found that participants with access to an AI assistant "wrote significantly less secure code than those without access" and "were more likely to believe they wrote secure code." The overconfidence is the dangerous part.
  • Georgia Tech's Vibe Security Radar had confirmed 74 real-world vulnerabilities traceable to AI coding tools by April 2026, 14 of them critical and 25 high. March 2026 alone produced 35 cases, more than all of 2025 combined.

Those numbers are not abstract. They have already become incidents:

Incident When What happened Root cause
Lovable apps (CVE-2025-48757) Disclosed May 2025 Security researcher Matt Palmer found exposed data across 170 of 1,645 AI-built projects analyzed, about 10.3% Missing or insufficient database row-level security policies
Replit agent at SaaStr July 2025 An AI coding agent deleted a production database holding records for more than 1,200 executives and 1,190 companies during a code freeze, per Fortune Agent had write access to production and ignored instructions
Moltbook February 2026 Wiz researchers found an exposed database with 35,000 emails and 1.5 million API keys behind a social network whose founder said he "didn't write a single line of code" Database key hardcoded in client-side JavaScript; row-level security never enabled

The pattern to watch for

Every incident above involved a working product that looked finished. The missing piece was a control nobody wrote, tested, or reviewed. A SOC 2 Type 2 audit exists precisely to check for the controls a product demo cannot show you.

Hardcoded credentials are the quiet epidemic

The most common failure in AI-built software is not an exotic exploit. It is a secret pasted where it should never be. GitGuardian's State of Secrets Sprawl 2026 counted 28.65 million new hardcoded secrets added to public GitHub commits in 2025, a 34% increase year over year. Secrets for AI services alone grew 81% to more than 1.27 million. The report also measured leak rates by how the commit was produced: commits assisted by Claude Code carried a 3.2% secret-leak rate against a 1.5% baseline across all public GitHub commits, and researchers found 24,008 secrets sitting in configuration files for AI tool integrations.

A leaked key does not expire on its own. Someone has to notice it, rotate it, and check the logs for what it touched. That is an operational control, and it is exactly the kind of thing a SOC 2 auditor samples.

AI also makes impersonation cheap

The other half of the risk is fraud, and it lands on the same people our customers are trying to reach. The FBI's Internet Crime Complaint Center recorded 1,008,597 complaints and $20.9 billion in reported losses in 2025, a 26% increase in losses over 2024, including 22,364 complaints that specifically involved AI and $893 million in associated losses. Pindrop's 2025 Voice Intelligence and Security Report found deepfake fraud attempts rose more than 1,300% in 2024, from about one per month to seven per day.

Sendspark runs AI voice cloning as a core feature. We think about this constantly. The safeguards live in two places: the consent and retention rules we publish in our privacy policy and our voice cloning guardrails guide, and the access controls, logging, and encryption that decide who can reach that data at all. The second set is what SOC 2 tests.

How Should a Buying Committee Read a Vendor's SOC 2 Report?

Read a vendor's SOC 2 report for four things: the type (insist on Type 2), the observation period and report date (anything older than twelve months is stale), the auditor's opinion and the list of exceptions in the testing section, and the scope, meaning which trust services categories are covered and which subservice organizations are carved out. Those four checks take less than an hour and replace most of a security questionnaire.

The time pressure is real. G2's 2026 Buyer Behavior Report, based on 1,038 software buyers, found that IT security review is the single biggest source of delay between selecting a vendor and completing the purchase, cited by 39% of all buyers and by 50% of enterprise buyers. Vanta's State of Trust 2025 survey of 3,500 leaders found organizations now spend nine working weeks a year on vendor security reviews and risk assessments, up from seven the year before, and 61% say they spend more time proving security than improving it. A current Type 2 report is the fastest way through that bottleneck for both sides.

Use this sequence when a vendor hands you a report:

  1. Check the type and the dates. Type 2, with an observation period that ends within the last twelve months. If the period ended more than a year ago, ask for a bridge letter covering the gap.
  2. Read the opinion first. It is one page at the front. You want an unqualified opinion that says the description is fairly presented and the controls were suitably designed and operated effectively.
  3. Go straight to the exceptions. Every tested control lists a result. "No exceptions noted" is what you want to see. Where an exception appears, read management's response and decide whether the affected control matters for your use of the product.
  4. Map the scope to your data. If you will store regulated or confidential data, ask whether confidentiality and privacy criteria are in scope. If uptime matters, ask about availability.
  5. Note the carve-outs and your own responsibilities. The report will name subservice organizations and list complementary user entity controls, the things you must do (like enforcing SSO or reviewing your own users' access) for the vendor's controls to work.

Pro tip

Ask the vendor when the current observation period ends and whether the next audit is already scheduled. A vendor that can answer both without checking is treating SOC 2 as an operating rhythm, not a one-time badge.

For the broader set of privacy and data-handling questions to ask any AI sales tool, including voiceprint retention, sub-processors, and hosting location, use our AI video vendor security and privacy checklist. If the tool will write engagement data back into your CRM, our video CRM integration guide covers what that data path looks like and which fields move.

What Does SOC 2 Mean for Sendspark Customers Day to Day?

For Sendspark customers, SOC 2 Type 2 means the systems that store your recorded videos, your cloned voice, your CRM contact data, and your viewers' engagement analytics were independently examined for twelve months, with encryption, access control, monitoring, and incident response all tested and operating without exception. It also gives your IT and security team a document to review instead of a questionnaire to chase, and a public Trust Center where they can see the controls and request the evidence.

Consider what actually flows through an AI video personalization platform during an outbound campaign. A rep records one video. AI voice cloning and dynamic backgrounds personalize it for every prospect on a list pulled from HubSpot or Salesforce. Each prospect's name, company, and website become inputs. Each open, play, and click flows back to the CRM record. That is contact data, biometric-adjacent voice data, and behavioral data in one pipeline. Sendspark deletes voice-cloning voiceprints after 90 days, as described in our privacy policy, and the SOC 2 controls govern who inside Sendspark can touch any of it in the meantime.

For larger teams, the Enterprise plan pairs the SOC 2 report with single sign-on, role-based permissions, and custom integrations, which are the complementary controls your own security team will want to switch on. More than 50,000 companies use Sendspark for outbound prospecting and customer communication, and the platform holds a 4.8 out of 5 rating on G2 across more than 350 reviews.

For security reviewers

Request the full report and our 2026 penetration test report through the Sendspark Trust Center, then read them next to our hosting providers' SOC reports. Reading the carve-outs side by side is the fastest way to confirm there is no gap between what we control and what Google Cloud and MongoDB control.

Here is the whole argument in one table:

Point Why it matters in 2026 Source
Sendspark renewed SOC 2 Type 2 with 57 controls tested and no exceptions Independent proof that security controls operated for a full year, not a self-assessment Thoropass Assurance, report dated August 29, 2026
AI now writes roughly half of committed code with a 56% security pass rate More software, same defect rate, so buyers cannot infer quality from polish Veracode, 2026
28.65 million secrets leaked to public GitHub in 2025, up 34% Credential handling is the most common failure in fast-built software GitGuardian, 2026
Frontier models now meet a Critical cyber capability threshold Vulnerabilities in shipped software get found faster than ever OpenAI GPT-6 Astra System Card, 2026
IT security review is the top post-selection purchase delay (39%) A current Type 2 report shortens the deal for buyer and vendor G2, 2026
Deepfake fraud attempts rose more than 1,300% in 2024 Voice and video data need real access controls, not just consent language Pindrop, 2025

Frequently Asked Questions

Is Sendspark SOC 2 Type 2 compliant?

Yes. Sendspark holds a current SOC 2 Type 2 report issued by Thoropass Assurance on August 29, 2026. It covers the AICPA Security trust services criteria for the period August 1, 2025 to July 31, 2026, with 57 controls examined and no exceptions noted.

What is the difference between SOC 2 Type 1 and SOC 2 Type 2?

A SOC 2 Type 1 report confirms that controls were suitably designed at a single point in time. A SOC 2 Type 2 report tests whether those controls actually operated effectively over an observation period, typically three to twelve months. Type 2 is the standard buyers should require.

How long is a SOC 2 Type 2 report valid?

A SOC 2 Type 2 report has no formal expiry, but buyers treat it as current for twelve months after the observation period ends. Vendors renew it annually with a new observation period. If a report is older than that, ask the vendor for a bridge letter covering the gap.

Which trust services criteria does Sendspark's SOC 2 report cover?

Sendspark's 2026 report covers the Security category, the AICPA common criteria included in every SOC 2 report. Availability, processing integrity, confidentiality, and privacy are not in scope this cycle. Hosting on Google Cloud Platform and MongoDB Atlas is carved out.

How do I get a copy of Sendspark's SOC 2 report?

Request it through the Sendspark Trust Center at security.sendspark.com, which also lists our 2026 penetration test report and our security controls. SOC 2 reports are restricted-use documents, so the full report is shared under a non-disclosure agreement.

Why does SOC 2 matter for AI sales tools specifically?

AI sales tools process CRM contact data, engagement data, and in Sendspark's case cloned voice data. Veracode's 2026 research found AI-generated code passes security tests only 56% of the time, so polish proves nothing. A SOC 2 Type 2 report is independent evidence the controls operated for a year.

Does SOC 2 cover the data used for AI voice cloning?

Yes. The Security controls tested in a SOC 2 Type 2 report apply to all customer data in the platform, including voice recordings and generated voiceprints. Separately, Sendspark deletes voiceprints after 90 days, as described in its privacy policy.

Sources & References

  1. OpenAI — "GPT-6 Astra is a significant step up in cyber capabilities and meets our Critical threshold" (GPT-6 Astra System Card, 2026)
  2. Thoropass — "Laika Compliance, LLC dba Thoropass Assurance is a licensed certified public accounting firm registered with the AICPA" (2026)
  3. AICPA & CIMA — "A SOC 2 examination is a report on controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy" (2025)
  4. Veracode — "The average security pass rate across models is 56%, barely changed from 55% in the first report"; AI authors roughly half of all committed code (2026 GenAI Code Security Report, 2026)
  5. Perry, Srivastava, Kumar, and Boneh, Stanford University — Participants with an AI assistant "wrote significantly less secure code" and "were more likely to believe they wrote secure code" (ACM CCS, 2023)
  6. Georgia Tech Research — Vibe Security Radar confirmed 74 vulnerabilities, 14 critical and 25 high; "March 2026 alone had 35, more than all of 2025 combined" (2026)
  7. Matt Palmer — "303 endpoints across 170 projects (approximately 10.3% of the 1645 analyzed)" exposed by missing row-level security (Statement on CVE-2025-48757, 2025)
  8. Fortune — AI coding agent deleted production data for "more than 1,200 executives and over 1,190 companies" during a code freeze (2025)
  9. Wiz — "1 exposed database. 35,000 emails. 1.5M API keys."; database key hardcoded in client JavaScript with row-level security never enabled (2026)
  10. GitGuardian — "28.65 million new hardcoded secrets were added to public GitHub commits in 2025 alone, a 34% increase year over year"; AI-assisted commits showed a 3.2% secret-leak rate against a 1.5% baseline (State of Secrets Sprawl, 2026)
  11. FBI Internet Crime Complaint Center — 1,008,597 complaints and $20.877 billion in losses in 2025, a 26% increase; 22,364 AI-related complaints with $893 million in losses (2025 IC3 Annual Report, 2026)
  12. Pindrop — "Deepfake fraud attempts rose by more than 1,300% in 2024, jumping from an average of one per month to seven per day" (2025 Voice Intelligence and Security Report, 2025)
  13. G2 — "IT security review is the single biggest source of delay (39%) between selecting a vendor and completing a purchase"; 50% among enterprise buyers (2026 Buyer Behavior Report, 2026)
  14. Vanta — Organizations spend "9 working weeks per year on vendor security reviews and risk assessments"; "61% say they spend more time proving security rather than improving it" (State of Trust Report, 2025)

Record One Video. AI Personalizes Thousands.

Sendspark is the AI video personalization platform for B2B sales. Record once, and AI voice cloning generates thousands of individually personalized videos with dynamic backgrounds and personalized thumbnails — each prospect hears their name, sees their website, in your voice. Sales teams see 2-3x more replies.

Get Started Now
Abe Dearmer

Abe Dearmer

CEO, Sendspark

LinkedIn