
Jacob Sidford
5 min read

Nylon has achieved SOC 2 Type 2 compliance. It sits alongside our SOC 2 Type 1 report and our ISO 27001 certification, and it's the security standard that enterprise and mid-market firms increasingly ask for by name before they'll let any tool near their client data.
Security standards matter more for AI tools than for almost any software your firm has adopted before. AI is unusually data-hungry, and the risks are easy to trigger without realising. A colleague can paste a confidential client matter into a generic AI tool in seconds, with many general-purpose tools, that data can then be used to train the model. A standard like SOC 2 Type 2 is how you separate the AI tools that handle client data properly from the ones that simply promise they do.
If these standards feel like alphabet soup, this post is for you. Below, we explain what SOC 2 is, the difference between SOC 2 Type 1 and Type 2, and, most importantly, why it should change how you choose the AI tools your firm relies on.
What is SOC 2?
SOC 2 (System and Organization Controls 2) is a voluntary security standard developed by the American Institute of CPAs (AICPA). It sets out how a technology company should manage customer data, and it is verified by an independent external auditor rather than self-declared.
SOC 2 is built on five Trust Services Criteria:
Security: keeping unauthorised people out (the one criterion every SOC 2 audit must cover)
Availability: the service is reliably up and performing as promised
Processing integrity: the system does what it's meant to, accurately and on time
Confidentiality: sensitive data is only visible to those with permission, protected by encryption and access controls
Privacy: personal information is collected, used, and shared responsibly
Because the review is independent, a SOC 2 report is evidence, not a marketing claim.

SOC 2 Type 1 vs Type 2: what's the difference?
SOC 2 Type 1 is a snapshot; SOC 2 Type 2 is a track record. A Type 1 report confirms that the right controls are designed and in place at a single point in time. A Type 2 report goes further: an independent auditor tests whether those controls operated effectively over a sustained period, typically many months.
Think of it as the difference between a photo and a film. Type 1 proves you have a lock on the door. Type 2 (also written SOC 2 Type II) proves the door stayed locked, every day, across the whole audit window.
Type 2 is much harder to earn because you can't cram for it. It reflects how an organisation genuinely operates day to day. That's exactly why enterprise buyers and larger firms ask for it by name.
Why SOC 2 matters when you put client data into an AI tool
When you or your team paste a client's information into an AI tool, you're deciding on that client's behalf where their confidential information goes and what happens to it. Two questions determine whether that's a safe decision:
Is the data encrypted and access-controlled, or is it sitting somewhere it could be exposed?
Is the data used to train the AI model? If it is, fragments of your client's affairs can influence answers given to complete strangers.
This is the sharp edge of the issue. Many general-purpose AI tools may use what you type to improve their models unless you're on a specific paid or enterprise tier and have actively opted out. So the moment a colleague pastes a sensitive matter into a consumer chatbot to "just check something", your firm may have handed client data to a third party's training pipeline.
With Nylon, your data is never used to train AI models. A SOC 2 Type 2 report is how you verify that a vendor's security claims hold up under independent scrutiny, rather than taking them on trust.
Security that doesn't stop at the platform
Passing a SOC 2 Type 2 audit isn't something a product can fake with a good architecture diagram. It reaches into how the whole company works: how staff are onboarded and offboarded, how access is granted and revoked, how we monitor for issues, and how we respond when something looks wrong.
That's the part we care about most. Good security isn't a feature you bolt on. It's a set of habits the whole team lives by. Our SOC 2 Type 2 report is independent proof that those habits hold up over time, not just on the day someone comes to check.
SOC 2 vs ISO 27001: what's the difference, and do you need both?
SOC 2 and ISO 27001 answer two different questions, which is why leading vendors hold both. ISO 27001 is the leading international standard for an information security management system (ISMS). It certifies that you have the right framework and processes to manage security across the whole organisation. SOC 2 is an independent auditor's report on how effectively a specific set of controls actually operates in practice.
Put simply: ISO 27001 proves you have the system; SOC 2 Type 2 proves the controls worked over time. One is a certification against an international standard; the other is an ongoing attestation of operating effectiveness.
For a firm assessing an AI supplier, the strongest position is a vendor that holds both: the recognised framework and the independent evidence it works. Nylon does: we are ISO/IEC 27001:2022 certified and SOC 2 Type 1 and Type 2 attested, and we're actively pursuing ISO/IEC 42001, the emerging international standard for AI management systems.
Where Nylon stands today
For firms evaluating an AI research tool, here's the full picture:

SOC 2 Type 1 and Type 2: independently examined, covering both the design and the ongoing operation of our controls
ISO/IEC 27001:2022: certified to the leading international standard for information security management
ISO/IEC 42001 (AI Management System): actively pursuing certification to the emerging international standard for responsible AI governance
Encryption in transit and at rest, Microsoft SSO and MFA at no extra cost, and continuous compliance monitoring
Your data is never used to train AI models
You don't have to take our word for any of it. Review our certifications and security posture for yourself at our Trust Center.
Why this matters more for AI than almost anything else
AI tools are unusually data-hungry and unusually easy to use badly. The friction that used to protect client information, the effort of moving files around, has all but disappeared. Anyone can paste anything anywhere in seconds.
For professionals who must meet standards of client confidentiality, this is even more important. These professional obligations are paramount and one of the reasons Nylon is built to such a high standard of security and privacy.
That's precisely why the standards a vendor holds itself to matter so much. A tool that came together quickly, without security built in from the ground up, might give you a slick answer, but it can't give you the assurance that your clients' information is being handled the way your professional obligations require. For firms in the mid-market and above, where procurement and IT teams scrutinise every new supplier, SOC 2 Type 2 has quietly become the price of entry.
Nylon was built for professionals who are accountable for what they send to clients. The security standards behind it are held to the same measure.
Frequently asked questions
Is Nylon SOC 2 compliant?
Yes. Nylon is SOC 2 Type 1 and Type 2 compliant, following independent audits, and is also ISO/IEC 27001:2022 certified.
What is SOC 2?
SOC 2 (System and Organization Controls 2) is a voluntary security standard from the American Institute of CPAs (AICPA) that defines how a technology company should manage customer data across five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. It is verified by an independent auditor.
What is the difference between SOC 2 Type 1 and Type 2?
SOC 2 Type 1 confirms the right controls are designed and in place at a single point in time. SOC 2 Type 2 goes further, with an independent auditor testing that those controls operated effectively over a sustained period, typically many months.
Is SOC 2 a certification?
Strictly, no. SOC 2 results in an independent auditor's attestation report rather than a certificate. In everyday use, "SOC 2 compliant" and "SOC 2 certified" are used interchangeably to mean a company has passed a SOC 2 audit.
What is the difference between SOC 2 and ISO 27001?
ISO/IEC 27001 is an international standard for an information security management system, the framework for managing security. SOC 2 is an independent report on how effectively specific controls operate. They complement each other, and Nylon holds both.
Does Nylon use my data to train AI models?
No. Your data is never used to train AI models.
Is my client data encrypted?
Yes. Data is encrypted both in transit and at rest, with Microsoft SSO and MFA available at no extra cost.
Where can I see Nylon's security certifications?
You can review them any time at our Trust Center.
Ready to see it for yourself?
If you're new to Nylon, you can request a demo or start a 7-day trial.

WRITTEN BY
Jacob Sidford
CTO
Jacob is the co-founder and CTO of Nylon, with 10+ years leading engineering teams at companies like Atlassian and Deputy. He writes about the technology behind AI legal research and what it takes to make it accurate enough for professionals to rely on. Off the clock he's usually in the garden, outnumbered by chickens - all of whom remain sceptical of AI.