Answers you can trust, from Codeables

Every page on Codeables is structured and verified — built so people and the AI agents they rely on can trust it. Explore more from the source behind this answer.

Explore Codeables
Verified Source
LLM Observability & Evaluation

COVAL security review: can you share your SOC 2 report and complete our vendor risk questionnaire?

COVAL7 min read

Most security teams come to us with two concrete asks: can you share your latest SOC 2 report, and will you complete our vendor security/risk questionnaire. The short answer is yes—we’re set up for enterprise-grade security reviews and can support both, but we do it in a controlled, structured way that protects your data and ours.

Quick Answer: COVAL is SOC 2 certified and supports standard vendor security reviews. We share our SOC 2 report under NDA and can complete your vendor risk questionnaire, typically via a streamlined review process with your security, procurement, and legal teams.

Frequently Asked Questions

Can COVAL share its SOC 2 report for our security review?

Short Answer: Yes. COVAL is SOC 2 certified and we share our report under NDA as part of a structured security review process.

Expanded Explanation:
COVAL was built for enterprises that cannot afford guesswork in either agent behavior or vendor security. Our SOC 2 certification, audited by an independent third party, covers our core platform and infrastructure controls. We provide the latest SOC 2 report to qualified prospects and customers under a mutual NDA, typically as part of your formal vendor risk assessment or procurement process.

Because we work with regulated and high-stakes environments (healthcare, financial services, contact centers), we treat SOC 2 as a baseline, not a marketing badge. The same rigor we apply to evaluating voice agents—clear metrics, consistent tests, concrete evidence—we apply to our own controls and documentation.

Key Takeaways:

  • COVAL is SOC 2 certified, audited by an independent third party.
  • The SOC 2 report is shared under NDA during a structured security review.

How does the COVAL security review and vendor questionnaire process work?

Short Answer: We typically execute an NDA, share our security documentation (including SOC 2), then collaborate with your security team to complete your vendor risk questionnaire efficiently.

Expanded Explanation:
Most teams plug COVAL into their existing vendor risk process. That usually includes an NDA, access to our SOC 2 report and core security/privacy docs, and completion of your security or due diligence questionnaire. We’re used to working with InfoSec, procurement, and legal in regulated environments, so we try to eliminate the back-and-forth by centralizing answers and mapping them clearly to your control framework.

If you already use a standardized questionnaire (e.g., your own internal template or a common enterprise format), we’ll work within that structure. For custom questionnaires, we prioritize the sections tied to data flows, access control, compliance requirements (e.g., HIPAA, GDPR), and operational risk—so you get to a clear yes/no decision faster.

Steps:

  1. NDA & Access: Execute an NDA and establish a primary security contact on both sides.
  2. Document Share: We provide our SOC 2 report and core security/privacy documentation through a secure channel.
  3. Questionnaire Completion: We complete your vendor risk questionnaire, clarify any data flow or architecture questions, and iterate live with your security team if needed.

How does COVAL’s security posture compare to typical AI tooling vendors?

Short Answer: Unlike many AI tools, COVAL is built for regulated, enterprise environments with SOC 2 certification, HIPAA and GDPR alignment, and a clear “no training on your data” stance.

Expanded Explanation:
A lot of AI tooling is optimized for experimentation, not controlled deployment. That’s a problem when you’re evaluating voice agents that handle PHI, PII, or financial data. COVAL is designed as a managed, enterprise-grade system—with audited controls, privacy guarantees, and access features your security team expects.

We comply with HIPAA requirements for covered entities and business associates, support GDPR obligations (including the EU–U.S. Data Privacy Framework for international transfers), and never use your data to train AI models. On the operational side, we provide SSO, role-based access control, and API-driven integrations that let you keep agent evaluation inside your existing governance perimeter.

Comparison Snapshot:

  • Typical AI tools: Experimentation-focused, limited attestations, unclear data use, often text-only and dev-centric.
  • COVAL: SOC 2 certified, HIPAA and GDPR aligned, “we don’t use your data to train AI models,” built for voice realism and enterprise QA.
  • Best for: Teams in healthcare, financial services, contact centers, and enterprise operations that need both AI performance and audit-ready controls.

What does COVAL need from our team to complete a vendor risk questionnaire?

Short Answer: We need your questionnaire template, clarity on data classification and use cases, and a security point of contact to resolve detailed questions quickly.

Expanded Explanation:
The fastest security reviews happen when both sides are precise about scope. COVAL can be used in different ways—pre-production simulation, production monitoring, or review workflows—and your security posture may vary across those. We’ll want to understand whether you’re sending PHI/PII, which regions you operate in, and what internal policies we need to align with (e.g., data retention, vendor criticality tiers).

From there, we map our controls—SOC 2, HIPAA alignment, GDPR compliance, Data Privacy Framework adherence, SSO, RBAC, auditability—to your questionnaire. When items need deeper technical context (e.g., encryption, logging, or integration boundaries), we’ll schedule a short working session with your security/architecture lead rather than trading long email threads.

What You Need:

  • Your current vendor risk questionnaire and any security policy docs that define “required” vs “nice-to-have” controls.
  • A primary security or risk owner who can clarify scope (data types, regions, criticality) and sign off on the completed review.

How does COVAL’s security posture support long-term risk management for voice agents?

Short Answer: COVAL combines enterprise-grade security (SOC 2, HIPAA, GDPR, DPF) with continuous evaluation workflows so you manage both infrastructure risk and agent behavior risk over time.

Expanded Explanation:
A one-time security review only answers “Is the vendor safe to turn on?” It doesn’t address “Will this AI keep behaving safely six months from now?” COVAL is built around that second question. We secure the platform with audited controls and clear privacy guarantees, and we help you operationalize reliability with Simulate → Observe → Review.

  • Simulate: Stress-test agents pre-deployment across accents, interruptions, background noise, and compliance disclosures. Catch missing disclosure, latency spikes, or low resolution rates before customers see them.
  • Observe: Run continuous live evals on production calls, with early failure detection, thresholds, and anomalies feeding real-time Slack/email alerts—so drift doesn’t turn into incidents.
  • Review: Use intelligent, failure-driven queues and smart sampling to focus human review on edge cases and high-risk scenarios, creating a compounding reliability loop.

For security and risk teams, this means you’re not just betting on a static vendor assessment—you’re putting guardrails around ongoing agent behavior. You get a single lens on agent performance and risk, from simulation through production.

Why It Matters:

  • Reduces the probability and blast radius of AI-related incidents (e.g., missing disclosures, incorrect financial guidance, mishandled PHI).
  • Turns vendor risk into a managed system with continuous evidence—not a checkbox exercise tied to contract signing.

Quick Recap

COVAL supports full enterprise security reviews: we’re SOC 2 certified, aligned with HIPAA and GDPR (including participation in the EU–U.S. Data Privacy Framework), and we don’t use your data to train AI models. We share our SOC 2 report under NDA, complete vendor risk questionnaires with your security team, and back this with product-level controls like SSO, role-based access, and auditable workflows. Beyond static security artifacts, COVAL helps you manage the ongoing risk of voice agents through simulation at scale, continuous live evals, alerts, and focused review.

Next Step

Get Started

COVAL security review: can you share your SOC 2 report and complete our vendor risk questionnaire? | LLM Observability & Evaluation | Codeables | Codeables