/

Support Quality

Best SOC 2, HIPAA, and GDPR-Compliant AI Customer Support Platforms (2026)

Best SOC 2, HIPAA, and GDPR-Compliant AI Customer Support Platforms (2026)

Lorikeet Logo

Lorikeet News Desk

·

Updated

·

Fact-checked against Gartner & Forrester data

Most AI support vendors will hand you a SOC 2 logo and a deflection rate. Your auditor will ask who can read a customer's PHI, where the data lives, and whether you can replay every action the AI took. The platforms that answer those three questions cleanly are the only ones worth a shortlist.

SOC 2 and HIPAA-compliant AI customer support is a category of AI agent platforms that resolve regulated support tickets end-to-end while meeting the controls auditors and Business Associate Agreements require: SOC 2 Type II attestation, a signed HIPAA BAA where protected health information is involved, tenant data isolation, role-based access, PII redaction, and a replayable audit trail. In 2026, the platforms that clear this bar resolve the majority of inbound volume autonomously and still survive a security review at a bank or a healthtech.

  • A SOC 2 logo on a marketing page is not a control. The report scope, the trust service criteria covered, and the exceptions noted are what matter, and they only show up in the report itself under NDA.

  • HIPAA has no certification. A vendor is HIPAA-compliant only if it will sign a BAA and can show the safeguards behind it. "HIPAA-ready" without a signed BAA is marketing, not coverage.

  • Data isolation, model no-train commitments, and data residency now decide more deals than raw resolution rate, because they decide whether a regulated buyer can deploy at all.

  • The audit trail is the artifact your compliance team and your regulator actually examine. A transcript is not an audit trail. Every tool call, prompt, and reasoning step, in order, with timestamps, is.

  • Gartner predicts 80% of common customer service issues will be resolved autonomously by 2029, which raises the stakes on getting the controls right before you scale.

Key Data Points

  • Healthcare data breaches cost an average of $9.77 million per breach in 2024, the highest of any industry for the 14th consecutive year (IBM and Ponemon Institute, Cost of a Data Breach Report 2024).

  • GDPR enforcement authorities have imposed €5.88 billion in cumulative fines since May 2018 (DLA Piper GDPR Fines and Data Breach Survey, January 2026).

  • Personal data breach notifications in Europe reached 443 per day in 2025, a 22% year-over-year increase (DLA Piper, February 2026).

  • The breach notification clock differs sharply by regime: HIPAA allows up to 60 days, while GDPR requires notification within 72 hours. The encryption baselines auditors expect are AES-256 at rest and TLS 1.2 or higher in transit.

Last updated: July 15, 2026

Regulated support has a different failure mode than e-commerce or generic SaaS. A wrong answer in a fintech or healthtech context is not a churn risk, it is an audit finding, a breach notification, or a regulator notice. That is why this ranking is built on a security and compliance lens first: SOC 2 posture, HIPAA and BAA readiness, data isolation, and auditability. Resolution rate matters, but it sits downstream of whether your compliance team can sign off on the platform at all. The list below is buyer-neutral on capability and honest about where each vendor publishes its posture and where it does not. Where a vendor's exact attestation is not publicly confirmable, this guide says "offers" or "supports" rather than asserting a certification it cannot verify, and you should request the current report under NDA before signing.

What "SOC 2 and HIPAA-Compliant AI Customer Support" Actually Means

SOC 2 and HIPAA-compliant AI customer support means an AI agent platform that resolves support tickets across chat, email, voice, and messaging while satisfying two distinct compliance regimes. SOC 2 is an attestation, produced by an independent auditor, that the platform's security controls meet the AICPA trust service criteria over a period of time. HIPAA is a US law governing protected health information, with no certification body; compliance is demonstrated by a signed Business Associate Agreement and the safeguards behind it. The two are not interchangeable, and a vendor can hold one without the other.

The category splits on depth. A first-generation bot answers questions from a knowledge base and never touches a system of record, so its compliance surface is small. An agentic platform takes actions: it looks up an account, files a dispute, updates a record, locks a card, or checks a claim status. The moment it touches customer data and acts on it, every one of those steps has to be controlled, logged, and replayable. That is where SOC 2 scope and HIPAA safeguards stop being a checkbox and start being a design constraint.

SOC 2 Type II: An independent auditor's report confirming that a vendor's security controls were designed correctly and also operated effectively over a review period, typically 6 to 12 months. The report includes scope, the trust service criteria covered, and any exceptions. Type I, by contrast, only tests design at a single point in time.

HIPAA BAA: A Business Associate Agreement, the contract that makes a vendor legally accountable for protecting protected health information on your behalf. Without a signed BAA, no platform is HIPAA-compliant for your data, regardless of what its safeguards look like.

Data isolation: The architectural guarantee that one customer's data, prompts, and model interactions cannot reach another customer's environment, combined with contractual commitments that your data is not used to train shared models.

GDPR and the DPA: The EU General Data Protection Regulation governs the personal data of people in the EU and UK. There is no GDPR certification; compliance is demonstrated through a signed Data Processing Agreement (DPA) plus the safeguards behind it, the same way HIPAA relies on a BAA. GDPR carries real weight: enforcement authorities have imposed €5.88 billion in cumulative fines since May 2018 (DLA Piper, January 2026).

What GDPR Requires From an AI Support Platform

If any of your customers sit in the EU or UK, GDPR applies to your AI support vendor as a data processor. Five requirements decide whether a platform can be deployed compliantly:

  • Data Processing Agreement (DPA): a signed contract binding the vendor to process personal data only on your instructions and for your documented purposes.

  • Lawful basis: every processing activity needs a defensible legal basis, and the vendor's handling of prompts, transcripts, and model calls has to fit inside it.

  • Data residency: the ability to store and process personal data in a specific region (EU, US, AU, or UK) so you can meet your own transfer and localization obligations.

  • Right to erasure: the ability to delete a data subject's personal data on request, including anything held in logs, embeddings, or model context.

  • Data minimization: collecting and retaining only the personal data a task needs, meaning PII redaction and scoped access, not ingesting everything.

Lorikeet is an AI customer support platform built for complex and regulated businesses, with around 80% of its customers being US financial institutions and fintechs alongside healthtech and insurance companies. It resolves multi-step tickets end-to-end across chat, email, voice, SMS, and WhatsApp, with security and compliance posture built for buyers whose hardest stakeholder is their auditor.

The Compliance Frameworks That Matter for AI Support

Regulated buyers increasingly evaluate AI support vendors against a stack of named frameworks, not a single logo. Knowing what each covers helps you read a trust page critically.

  • SOC 2 Type II: an independent attestation against the AICPA Trust Services Criteria, covering a sustained audit period rather than a single point in time.

  • ISO 27001: the international standard for an information security management system. ISO 27701 extends it to privacy information management.

  • ISO 42001: the first international standard for AI management systems, covering bias detection, AI risk management, and transparency. It is the emerging benchmark for governing AI-specific risk.

  • AIUC-1: an AI agent security standard developed with Stanford, MIT, MITRE, and the Cloud Security Alliance, which requires quarterly adversarial testing.

  • HIPAA: US law protecting health information, requiring a signed BAA for any processing of PHI. GDPR: EU and UK law protecting personal data, requiring a signed DPA.

  • PCI DSS: the payment card industry data security standard, relevant whenever the AI touches cardholder data.

Sector-specific rules layer on top: SR 11-7 model risk management for US banks, NYDFS Part 500 for New York financial services, and DORA for EU ICT resilience. The EU AI Act adds obligations for high-risk AI systems, including some fraud detection and credit decisioning, from August 2, 2026, with penalties up to €35 million or 7% of worldwide turnover; the Colorado AI Act takes effect June 30, 2026. Under the CFPA, the CFPB has warned that financial institutions "risk violating legal obligations, eroding customer trust, and causing consumer harm when deploying chatbot technology," and that incorrect information from an AI chatbot can constitute a UDAAP violation.

At-a-Glance Comparison

Platform: Lorikeet · Best For: Fintech and healthtech where the auditor is the toughest stakeholder · Compliance Posture: SOC 2, HIPAA BAA-ready, GDPR-aligned, PII redaction, RBAC, US/AU/UK residency, contractual no-train with model providers · Pricing: ~$0.80-$0.95/chat-email-SMS resolution, ~$1.20-$1.50/voice, Coach ~$0.25-$0.30/ticket

Platform: Sierra · Best For: Large enterprises wanting outcome-only billing · Compliance Posture: Offers SOC 2 and enterprise security controls; confirm HIPAA BAA availability directly · Pricing: Custom, reportedly $50K-$200K/year

Platform: Decagon · Best For: Enterprise fintechs with large support budgets and embedded engineering · Compliance Posture: Offers SOC 2 and enterprise controls; confirm HIPAA BAA scope directly · Pricing: Custom, reportedly ~$400K median annual

Platform: Fin by Intercom · Best For: Intercom helpdesk customers wanting drop-in AI · Compliance Posture: Intercom offers SOC 2 Type II and supports HIPAA with a BAA on qualifying plans; verify per plan · Pricing: $0.99/resolution + helpdesk seat

Platform: Salesforce Agentforce · Best For: Salesforce-native enterprises · Compliance Posture: Salesforce offers SOC 2 and supports HIPAA on qualifying clouds with a BAA; confirm Agentforce scope · Pricing: Consumption-based, ~$2 per conversation plus platform

Platform: Ada · Best For: Mid-market teams with high chat volume · Compliance Posture: Offers SOC 2 and enterprise security controls; confirm HIPAA BAA availability · Pricing: Custom, reportedly ~$70K median annual

Platform: Forethought · Best For: Teams wanting resolution plus triage and QA in one stack · Compliance Posture: Offers SOC 2 and enterprise controls; confirm HIPAA BAA scope · Pricing: Custom, reportedly ~$59.5K median annual

Compliance Evaluation Comparison

The table scores the seven platforms on the eight compliance dimensions a regulated buyer gates on. "Confirm" means the posture is not publicly detailed enough to assert here, so request the SOC 2 Type II report and the BAA or DPA under NDA. Every vendor should meet the AES-256 at rest and TLS 1.2 or higher encryption baseline.

Platform

HIPAA (BAA)

GDPR (DPA)

Data residency

SOC 2 Type II

Zero-retention LLM processing

Audit logging

Right to erasure

Lorikeet

BAA-ready

GDPR-aligned, DPA

US, AU, UK

Offers SOC 2

Contractual no-train (OpenAI, Anthropic, Gemini)

Replayable: every tool call and reasoning step

Supported

Sierra

Confirm BAA directly

Confirm DPA

Confirm

Offers SOC 2

Confirm in report

Enterprise controls; confirm

Confirm

Decagon

Confirm BAA directly

Confirm DPA

Confirm

Offers SOC 2

Confirm in report

Enterprise controls; confirm

Confirm

Fin by Intercom

BAA on qualifying plans

DPA available

US/EU hosting; confirm plan

SOC 2 Type II

Confirm per plan

Confirm per plan

Supported

Salesforce Agentforce

Qualifying clouds w/ BAA; confirm scope

DPA available

Multi-region; confirm

Offers SOC 2

Confirm scope

Enterprise governance tooling

Supported

Ada

Confirm BAA directly

Confirm DPA

Confirm

Offers SOC 2

Confirm in report

Enterprise controls; confirm

Confirm

Forethought

Confirm BAA directly

Confirm DPA

Confirm

Offers SOC 2

Confirm in report

Confirm

Confirm

The 7 Best SOC 2 and HIPAA-Compliant AI Customer Support Platforms in 2026

1. Lorikeet

Lorikeet is the AI customer support platform built for complex and regulated companies, with the largest share of its customer base in US financial services and fintech, plus healthtech and insurance. It resolves multi-step tickets end-to-end across chat, email, voice, SMS, and WhatsApp, and its security and compliance posture is designed so a compliance or security team can sign off before launch rather than after. The positioning is deliberate: most vendors call their AI compliance-friendly, Lorikeet is built so your auditor can approve the behavior up front.

Best For

Fintechs, healthtechs, insurers, and gaming or betting operators handling regulated workflows like KYC, disputes, transfers, claims, and account recovery, where every action needs an audit trail and a compliance-approvable answer. Lorikeet has passed security reviews including those of major US banks, and works with regulated operators such as a cross-border payments company and a consumer fintech that report meaningful automation and retention results on AI-handled tickets versus human-handled ones.

Key Features

  • Defence in depth across the full lifecycle: pre-launch adversarial simulations and red-teaming, inbound message checks, outbound guardrails, and 100% post-facto QA through the Coach agent. The behavior is tested before it ships, not patched after.

  • Replayable audit trail: every tool call, prompt, and reasoning step is logged in order with timestamps, which is the artifact compliance teams and regulators examine.

  • Least-privilege scoped tools and webhooks, so the agent can only reach the systems and fields it has been explicitly granted, with RBAC on the human side.

  • Deterministic Structured Workflows plus natural-language workflows, combinable in one interaction, so regulated steps that must run the same way every time stay deterministic while flexible reasoning handles the rest.

  • Omnichannel on one engine including voice with sub-1-second latency, so a customer who starts in chat does not repeat themselves on a call and every channel inherits the same guardrails and logging.

Compliance Posture

SOC 2, HIPAA BAA-ready, and GDPR-aligned, with PII redaction, role-based access control, and data residency available in the US, Australia, and the UK. Lorikeet holds contractual no-train agreements with its model providers including OpenAI, Anthropic, and Gemini, so customer data is not used to train shared models, and it has passed security reviews at major US banks. Compliance features are designed to support your obligations rather than replace your own controls, and the audit trail plus pre-go-live simulation suite let a security team validate behavior before unsupervised resolution begins. Hallucination is controlled through retrieval grounding, output validation, and confidence-based escalation rather than free-form generation, keeping regulated answers tied to source-of-truth data.

Pricing

Outcome-based and anti-deflection: approximately $0.80-$0.95 per resolved chat, email, or SMS, approximately $1.20-$1.50 per resolved voice interaction, and the Coach QA agent at approximately $0.25-$0.30 per ticket, deployable standalone. Escalations to a human are not charged, and the customer holds the veto on what counts as a resolution. For context, a human-handled ticket typically costs roughly $1.25 to $4.

Limitation

Lorikeet is purpose-built for complex and regulated workflows, which means it is deliberately not the cheapest or fastest path for a small team that only needs simple FAQ deflection on a single chat channel. Implementation involves a forward-deployed PM and engineer and reaches a sandbox in 20 to 30 minutes, but operational rollout typically takes around a month, which is more upfront investment than a drop-in widget. If your support is low-stakes and unregulated, a lighter tool may be enough.

2. Sierra

Sierra is the enterprise AI agent company founded by Bret Taylor and Clay Bavor, known for pure outcome-based pricing where customers pay only when the AI fully resolves a case. It has scaled quickly and attracts enterprise procurement attention, including from financial services brands. On compliance, Sierra positions itself for enterprise buyers and offers standard enterprise security controls, but the specifics that matter to a regulated team should be confirmed in the report rather than assumed from the website.

Best For

Large enterprises that want billing alignment, paying only for successful resolutions, and have the procurement appetite for a custom annual contract.

Key Features

  • Outcome-only pricing where escalations to humans cost nothing.

  • Voice, chat, and email channels with a branded AI persona approach.

  • High-touch implementation with embedded Sierra staff during launch.

  • Strong enterprise procurement story that resonates with CFO and IT buyers.

Compliance Posture

Sierra offers SOC 2 and enterprise-grade security controls suited to large-company procurement. Public confirmation of a HIPAA BAA is limited, so healthtech buyers should request the current SOC 2 report and confirm BAA availability and scope directly before relying on it for protected health information.

Limitation

Outcome-only pricing aligns incentives on paper, but any vendor paid only on full resolution has a structural pull toward easy tickets and away from the hard, high-stakes ones, which in regulated support are exactly the ones that matter most.

Pricing

Not published. Enterprise contracts are reportedly in the $50,000 to $200,000 per year range, with the rate per resolution negotiated case by case.

3. Decagon

Decagon is a high-end enterprise AI agent platform with named fintech and consumer customers, operating on per-conversation or per-resolution pricing with white-glove implementation. It runs large production deployments and pitches a premium, top-of-market experience. Its compliance posture is built for enterprise buyers, with the deeper specifics best confirmed in procurement.

Best For

Large fintech and financial services enterprises with sizable support budgets that can dedicate engineering resources to a months-long deployment and want a premium AI vendor.

Key Features

  • Per-conversation or per-resolution pricing, customer-selectable.

  • Voice, chat, and email channels on one platform.

  • White-glove deployment with embedded engineering during launch.

  • Production deployments processing very high interaction volumes.

Compliance Posture

Decagon offers SOC 2 and enterprise security controls aimed at large regulated buyers. For HIPAA workloads, confirm BAA availability and the exact scope of covered services directly, since published detail on healthcare-specific safeguards is limited.

Limitation

The embedded engineering that comes with a premium contract is partly a function of how much configuration the platform requires, so plan for a vendor-dependent launch period and budget the implementation as a real cost, not a free add-on.

Pricing

No published rates. Industry data suggests a median total contract value near $400,000 per year, combining a platform fee with per-conversation or per-resolution charges.

4. Fin by Intercom

Fin is the AI agent layered on top of Intercom's messenger and helpdesk, priced at $0.99 per resolved outcome, among the lowest published per-resolution rates in the category. It is a fast path to deployment for teams already on Intercom and benefits from Intercom's mature security program.

Best For

High-volume consumer teams already using Intercom, or comfortable adding it, who want the lowest published per-outcome price and a quick trial-to-deployment path.

Key Features

  • $0.99 per resolved outcome, among the lowest published rates.

  • Works with Salesforce and HubSpot helpdesks, not only Intercom.

  • Fast trial-to-deployment path on the Intercom messenger.

  • Optional copilot for human agents.

Compliance Posture

Intercom offers SOC 2 Type II and supports HIPAA with a signed BAA on qualifying plans, which makes Fin a reasonable option for some healthcare-adjacent use cases. Coverage and the availability of a BAA depend on your Intercom plan and configuration, so verify that your specific plan includes HIPAA support before processing protected health information.

Limitation

A low per-resolution sticker is not the same as low total cost or low risk. Outcome pricing still rewards a vendor for clearing easy tickets, and Fin's depth on multi-step regulated action chains is more limited than platforms built specifically for that work.

Pricing

$0.99 per resolved outcome, plus an Intercom helpdesk seat fee if you are not already a customer, plus optional copilot and analytics add-ons.

5. Salesforce Agentforce

Salesforce Agentforce is Salesforce's agentic AI layer, built to act on Salesforce data and workflows. For organizations already standardized on Salesforce, it offers the shortest path to agents that read and write CRM records, backed by Salesforce's enterprise security and compliance program.

Best For

Salesforce-native enterprises that want AI agents operating directly on their existing CRM and service cloud data without adding a separate platform.

Key Features

  • Native action-taking on Salesforce records and service workflows.

  • Consumption-based pricing aligned to conversations handled.

  • Deep integration with the broader Salesforce platform and data model.

  • Enterprise governance tooling familiar to existing Salesforce admins.

Compliance Posture

Salesforce offers SOC 2 and supports HIPAA on qualifying clouds with a signed BAA, and it maintains a broad enterprise compliance program. The specific question for agentic AI is whether your Agentforce configuration falls inside the HIPAA-covered scope, so confirm BAA coverage for the exact Agentforce services and data flows you plan to use.

Limitation

Agentforce is at its strongest inside the Salesforce ecosystem. If your support data, telephony, or systems of record sit largely outside Salesforce, the integration overhead and consumption costs can climb, and you inherit the complexity of the wider platform.

Pricing

Consumption-based, reported around $2 per conversation, layered on top of the relevant Salesforce platform licensing.

6. Ada

Ada is one of the most established AI customer service vendors, with a long track record and public customers across consumer brands and fintech. It has expanded from chat into voice and email and pitches a high autonomous resolution rate. For compliance, Ada offers an enterprise security program suited to mid-market and larger buyers.

Best For

Mid-market and enterprise teams with high inbound chat volume that prefer a vendor with a long operating history over a newer entrant.

Key Features

  • High claimed autonomous resolution rate on supported workflows.

  • Multi-channel coverage across chat, voice, and email.

  • Mature integrations with Salesforce, Zendesk, and major helpdesks.

  • Established deployment playbooks for large enterprise rollouts.

Compliance Posture

Ada offers SOC 2 and an enterprise security program. Public confirmation of HIPAA BAA availability is limited, so healthcare buyers should request the current report and confirm BAA terms and scope before processing protected health information.

Limitation

Ada's roots are in chatbot deflection, and vendors that retrofit into the agent category tend to do breadth well and depth less so. On multi-step regulated action chains and replayable audit detail, expect to probe how deep the capability actually runs.

Pricing

Not published. Marketplace data shows median annual contracts around $70,000, with a wide range based on company size and volume.

7. Forethought

Forethought offers a multi-agent platform covering resolution, triage, agent assist, discovery, and quality scoring, using natural-language business logic rather than rigid decision trees. It suits teams that want more than resolution alone in a single stack. Its compliance posture is built for enterprise procurement.

Best For

Mid-market and enterprise teams that want a unified AI stack spanning resolution, triage, and QA rather than a single-purpose resolver.

Key Features

  • Multi-agent stack covering resolution, routing, assist, discovery, and QA.

  • Natural-language workflow logic instead of decision trees.

  • Multi-channel coverage across chat, email, voice, and messaging.

  • Broad library of system integrations.

Compliance Posture

Forethought offers SOC 2 and enterprise security controls. For HIPAA workloads, confirm BAA availability and the precise scope of covered services directly, since healthcare-specific detail is not heavily published.

Limitation

Following its acquisition by a larger helpdesk vendor, Forethought's roadmap is increasingly tied to its acquirer's direction. Signing now means signing into that roadmap, so weigh long-term product direction alongside current capability.

Pricing

Not published. Median reported annual contract is around $59,500, with voice add-ons priced separately for higher call volumes.

Compliance posture is the gate, not the garnish: in regulated support the platform that survives the security review wins the deal. See how Lorikeet clears SOC 2, HIPAA BAA, and audit-trail requirements end-to-end.

How to Verify SOC 2 and HIPAA for an AI Support Platform

A logo on a website is the start of due diligence, not the end. The steps below are what a regulated buyer should run before letting any AI agent touch customer or patient data. Most of the real answers live in the report and the contract, not the marketing page.

Read the SOC 2 Report, Not the Badge

Request the current SOC 2 Type II report under NDA and read three things: the scope, the trust service criteria covered, and the exceptions. Type II matters more than Type I because it tests whether controls operated effectively over time, rather than only whether they were designed. A report that covers only Security but not Confidentiality, or that excludes the AI service you are buying, does not cover what you think it covers. Check the report period too, because a report that ended a year ago tells you less than a current one.

Get the HIPAA BAA in Writing

HIPAA has no certification, so the only thing that makes a vendor HIPAA-compliant for your data is a signed Business Associate Agreement plus the safeguards behind it. Ask whether the vendor will sign a BAA, on which plan or tier, and which exact services the BAA covers. A vendor that says it is "HIPAA-ready" but will not sign a BAA, or only signs one on a tier you are not on, is not covering your protected health information. Confirm the BAA scope matches the channels and integrations you will actually use.

Pressure-Test Data Isolation and No-Train Commitments

Ask how one tenant's data, prompts, and model interactions are kept separate from another's, and get the model-training answer in writing. Many AI platforms rely on third-party model providers, so the question is whether the vendor has contractual no-train agreements with those providers that prevent your data from being used to train shared models. Lorikeet, for example, holds contractual no-train agreements with OpenAI, Anthropic, and Gemini. Also confirm where data is stored and processed, since data residency in the US, AU, or UK can be a hard requirement for your own compliance obligations. Confirm encryption baselines too: AES-256 at rest and TLS 1.2 or higher in transit.

Demand a Replayable Audit Trail

For an agentic platform, the audit trail is the control that lets you prove what the AI did. The right standard is a replayable record of every tool call, prompt, and reasoning step, in order, with timestamps, not a sampled log or a chat transcript. Ask the vendor to replay a real decision its AI made last week, end to end. If they can only show you the customer-facing messages, the system cannot support a regulator examination or an internal investigation when something goes wrong.

Validate Behavior Before Go-Live

A compliance team cannot approve a system whose behavior is "trust us, it usually works." Ask whether you can test guardrails, no PII leaks, scripted disclosures, dollar-threshold blocks, and jurisdiction-specific responses, before launch and read the results. Platforms built for regulated use let you run adversarial simulations and a guardrail test suite pre-go-live and review the pass and fail report. Lorikeet's defence-in-depth model layers pre-launch simulation, inbound message checks, outbound guardrails, and 100% post-facto QA, so behavior is provable before unsupervised resolution starts. If a vendor only offers guardrails as a runtime feature with no pre-launch report, your compliance team is being asked to approve faith, not behavior.

Questions to Ask Your Vendor

  • Can I read your current SOC 2 Type II report under NDA, including scope, criteria, and exceptions, and what period does it cover?

  • Will you sign a HIPAA BAA, on which plan, and which exact services and channels does it cover?

  • How is my tenant's data isolated, and do you have contractual no-train agreements with your model providers?

  • Where is my data stored and processed, and can you guarantee US, AU, or UK residency?

  • Show me a replayable audit trail for a decision your AI made last week, with every tool call and the reasoning between them.

  • Can my compliance team run your guardrail and simulation suite before go-live and read the pass and fail report?

  • What are your encryption baselines at rest and in transit, and do you meet AES-256 and TLS 1.2 or higher?

  • Can you honor a right-to-erasure request across logs, embeddings, and model context, within GDPR timelines?

  • What hallucination controls are in place: retrieval grounding, output validation, and confidence-based escalation?

  • When did you last complete third-party penetration testing, and can I read the summary?

Lorikeet's Take on Compliant AI Support

Most AI vendors lead with a resolution rate and a SOC 2 logo. Neither tells a regulated buyer what they need to know, which is the failure mode. A platform can report 80% resolution by attempting every ticket, succeeding on the easy majority, and mishandling protected data on the rest. In a regulated business that is not an 80% win, it is a 20% audit finding wearing a deflection metric.

The platforms that win procurement at the regulated companies Lorikeet works with are the ones whose behavior is provable before launch and replayable after. The test is simple: can your compliance team read the SOC 2 report, sign the BAA, confirm data isolation and residency, and replay the audit trail, and is the agent correct on the tickets that actually carry regulatory weight. If that is your bar, see how Lorikeet handles end-to-end resolution with defence in depth.

Key Takeaways

  • SOC 2 and HIPAA are different regimes. SOC 2 is an auditor's attestation you should read in full; HIPAA compliance for your data requires a signed BAA, not a badge.

  • For agentic AI, data isolation, contractual no-train commitments, and data residency increasingly decide whether a regulated buyer can deploy at all.

  • The replayable audit trail, every tool call and reasoning step in order, is the control that lets you prove what the AI did to an auditor or regulator.

  • Behavior should be validated before go-live through simulation and a guardrail test suite, not approved on faith and patched after an incident.

  • Lorikeet leads this list for regulated buyers on SOC 2, HIPAA BAA-readiness, isolation, residency, and audit depth; Sierra, Decagon, Fin by Intercom, Salesforce Agentforce, Ada, and Forethought are credible depending on existing stack, budget, and how much you can confirm in procurement.

Conclusion

The question in 2026 is not whether to deploy AI customer support, it is which platform survives a security and compliance review and still resolves the regulated tickets that matter. SOC 2 scope, a signed HIPAA BAA, tenant isolation, data residency, and a replayable audit trail are the gates a regulated buyer has to clear before resolution rate even enters the conversation.

The seven platforms above each fit a different profile, and the honest move is to verify each one's posture in the report and the contract rather than the marketing page. Lorikeet is the answer for fintechs, healthtechs, and other regulated operators whose toughest stakeholder is their auditor, who need provable behavior before go-live, and who want a per-resolution model that does not penalize escalating the hard cases. The other six are credible alternatives depending on your existing helpdesk, budget, and how much of their compliance posture you can confirm for your exact use case.

If you are evaluating SOC 2 and HIPAA-compliant AI customer support, book a Lorikeet demo and bring your security questionnaire and your hardest regulated tickets. We will run them against your guardrails before you sign.

Frequently asked questions

What is the difference between SOC 2 and HIPAA for AI customer support?

They are different things and a vendor can have one without the other. SOC 2 is an independent auditor's attestation that a platform's security controls meet AICPA trust service criteria, and the report comes in Type I (design at a point in time) or Type II (operating effectiveness over a period). HIPAA is a US law protecting health information, with no certification body. A platform is HIPAA-compliant for your data only when it signs a Business Associate Agreement and maintains the safeguards behind it. Treat "SOC 2 certified" and "HIPAA-ready" as claims to verify, not coverage to assume.

Which AI customer support platform is best for regulated industries in 2026?

Lorikeet leads for regulated buyers because it is built for complex and regulated companies, with around 80% of its customers in US financial services and fintech plus healthtech and insurance. It offers SOC 2, is HIPAA BAA-ready, is GDPR-aligned, supports US, AU, and UK data residency, holds contractual no-train agreements with its model providers, and gives compliance teams a replayable audit trail plus pre-go-live simulation. Sierra, Decagon, Fin by Intercom, Salesforce Agentforce, Ada, and Forethought are credible depending on your existing stack and how much of their HIPAA and isolation posture you can confirm for your exact use case.

Does the platform sign a HIPAA Business Associate Agreement?

This is the question that decides HIPAA coverage, because there is no HIPAA certification. Lorikeet is HIPAA BAA-ready for regulated healthcare and healthtech workloads. Intercom supports HIPAA with a signed BAA on qualifying plans for Fin, and Salesforce supports HIPAA on qualifying clouds with a BAA, which can extend to Agentforce within scope. For Sierra, Decagon, Ada, and Forethought, public confirmation is more limited, so request a BAA in writing and confirm which plan, services, and channels it covers before processing any protected health information.

How do I verify a vendor's SOC 2 report is real and relevant?

Request the current SOC 2 Type II report under NDA and read three things: scope, the trust service criteria covered, and the exceptions noted. Confirm the report period is recent, since an attestation that ended a year ago tells you less than a current one. Check that the AI service you are buying is actually inside the scope and that the criteria go beyond Security alone if Confidentiality or Privacy matter to you. A logo on a website is a starting signal; the report is the evidence.

How does Lorikeet keep customer data isolated and out of model training?

Lorikeet is built for regulated buyers, so isolation and data handling are core to the design rather than an add-on. It applies PII redaction, role-based access control, and least-privilege scoped tools so the agent only reaches the systems and fields it has been granted. It supports data residency in the US, Australia, and the UK, and holds contractual no-train agreements with its model providers including OpenAI, Anthropic, and Gemini, which means customer data is not used to train shared models. Lorikeet has also passed security reviews including those of major US banks. As always, request the current documentation under NDA to match it to your own obligations.

How do GDPR and HIPAA breach notification timelines differ?

The clocks are very different. HIPAA requires breach notification without unreasonable delay and no later than 60 days after discovery. GDPR is far tighter, requiring notification to the supervisory authority within 72 hours of becoming aware of a personal data breach. The stakes are real: GDPR authorities have imposed €5.88 billion in cumulative fines since May 2018, and breach notifications in Europe reached 443 per day in 2025, up 22% year over year (DLA Piper, 2026). For an AI support platform, that makes fast, replayable audit trails and tight data isolation practical necessities, because you cannot report what you cannot reconstruct inside 72 hours.

SEE IT ON YOUR TICKETS

Watch Lorikeet resolve your hardest ticket, live

End-to-end resolution

Not deflection — the ticket actually gets fixed.

Full audit trail

Every backend action, logged and reviewable.

Live in weeks

Not quarters. Forward-deployed setup.