CustomGPT.ai is SOC 2 Type 2 compliant
That means faster security reviews, and confidence we handle your data the right way
SOC 2 compliance
What SOC 2 compliance means
SOC 2 is an independent audit of how a company controls access to data, keeps it available, and keeps it confidential. For customers, it means you can trust a vendor with your data instead of relying on their word alone. Read more about SOC 2 Type 2
See the full report and more detail in our Trust Center.
Your Data belongs to you
- Encrypted in transit and at rest
- Each agent is its own isolated workspace
- Not used to train any AI model, ours or anyone else’s
- You control deletion of your source files
Testimonials
Trusted by security leaders
Compliance
Related Compliance Resources
Questions about SOC 2 compliance
Is CustomGPT.ai SOC 2 Type 2 compliant?
Yes. Report issued July 27, 2026 by INTERCERT CPA LLC, covering May 24, 2025 to May 23, 2026, across Security, Availability, and Confidentiality, with zero exceptions across all 165 controls tested.
Who performed the audit?
INTERCERT CPA LLC, an independent CPA firm.
What’s the difference between SOC 2 Type 1 and Type 2?
Type 1 checks whether controls are designed correctly at a single point in time. Type 2 checks whether those controls actually worked over a longer period. Ours covers twelve months, which is what most security teams look for.
How do I get a copy of the report?
Request it through our Trust Center.
Does this mean my data isn’t used to train AI models?
That’s a separate commitment, and yes — your content isn’t used to train any model. SOC 2 is what gives you independent proof the controls behind that commitment were actually tested, not just promised.
Which parts of SOC 2 does this cover?
Security, Availability, and Confidentiality.
Is SOC 2 the same as GDPR?
No. SOC 2 covers security controls. GDPR covers how EU personal data is handled. We address both — see our GDPR page for that side.
Should I ask for more than just a SOC 2 report when evaluating an AI vendor?
Yes, SOC 2 covers security controls, not whether an AI’s answers are accurate. We handle that separately: every answer CustomGPT.ai gives includes a source citation you can check.
Do you train any AI model on my data — not just the main chat model?
No. That includes embeddings, spam filters, and any other model we run — none of them are trained on your data.
How is my data kept separate from other customers?
Each agent is its own isolated workspace, controlled by account and user-level access settings. Content in one agent isn’t visible to another, even within the same account.
What happens when I delete a file?
Deletion starts immediately when you request it.