Rime is now fully SOC 2 compliant

rime-team
rime-team
May 9, 2025

We’re proud to announce that Rime has successfully completed our SOC 2 audit and is now fully SOC 2 Type 2 compliant.

This milestone reflects our unwavering commitment to data security, privacy, and operational excellence. SOC 2 compliance validates that our systems and processes meet the rigorous Trust Services Criteria for security, availability, processing integrity, confidentiality, and privacy.

What SOC 2 Type 2 actually covers

SOC 2 is an auditing framework developed by the American Institute of Certified Public Accountants (AICPA). A Type 1 report evaluates whether a company’s security controls are designed correctly at a single point in time. A Type 2 report goes further: an independent auditor observes those controls operating over a period of months and verifies that they work in practice.

For Rime, that means an outside auditor examined how we handle access control, change management, incident response, vendor management, and data protection across our infrastructure, then confirmed those controls held up over the full audit window.

SOC 2 Type 2 also joined a compliance program that was already underway. Rime has been HIPAA compliant since February 2024, and we treat certification as a cycle: audits recur on a set schedule so the reports your security team reviews stay current.

Why this matters for voice AI buyers

As an AI voice platform trusted by top teams, we understand the importance of protecting our customers’ data. Teams deploying text-to-speech in production often route sensitive material through their voice stack: account details in a banking IVR, appointment information in a healthcare call flow, order data in a support agent.

Security review is usually the first gate in enterprise procurement, and a current SOC 2 Type 2 report answers most of a security questionnaire before it’s even sent. If you’re evaluating Rime for an enterprise deployment, the report gives your security team independent evidence to work from.

Questions security teams ask us

Does Rime train models on customer data? No. Model training and customer traffic are fully separate, and our Privacy Policy puts that commitment in writing.

What does Rime store? Character counts for billing. We don’t retain the text you send or the audio we generate unless you ask us to, for example to enable request logging while debugging an integration.

Can conversation data stay inside our network? Yes. With a dedicated VPC or on-premises deployment, conversation text and synthesized audio never leave your environment. Several of our healthcare and financial services customers run Rime this way.

Will Rime sign a BAA or DPA? Yes. Business Associate Agreements for HIPAA workloads and data processing agreements are a standard part of our enterprise onboarding.

Part of a broader security posture

SOC 2 is one piece of how we approach security at Rime:

  • We are HIPAA compliant and will sign a Business Associate Agreement (BAA) for healthcare workloads.
  • As a general practice, we don’t collect customer data beyond character count.
  • Enterprise customers can deploy Rime in a dedicated VPC or fully on-premises, keeping audio and text inside their own network.

You can read more about these practices on our security page.

How to request Rime’s SOC 2 report

To learn more about our security practices or request a compliance report, please visit our Security page or contact us at info@rime.ai. We typically share reports under NDA, and your security team can use them to fast-track vendor review.