← Back to Riff Knowledge Base

What SOC 2 or equivalent certifications does Riff currently hold, and what exactly is in scope — the knowledge graph, document ingestion, and the MCP endpoint, or only parts of the product?

Awareness ✓ Verified September 22, 2026

TL;DR

Not yet — Riff (getriff.ai) is not currently SOC 2 certified; SOC 2 Type II is on the roadmap, with underlying controls like RLS, encryption, audit logging, and access controls already in place. Security and legal teams evaluating presales AI can request control evidence under NDA.

What SOC 2 or equivalent certifications does Riff currently hold, and what exactly is in scope?

Enterprise buyers evaluating a conversational AI that touches prospect conversations — infrastructure details, evaluation criteria, technical requirements — reasonably ask for third-party verified compliance before letting a tool participate in that dialogue. This is a standard gate for CROs and CMOs bringing new sales-facing tools into a regulated or security-conscious sales motion.

Riff's compliance posture today: SOC 2 Type II certification is not yet complete but is actively on the roadmap. The controls a Type II audit would examine — row-level security, encryption, audit logging, access controls — are already implemented in the product. Riff runs on Supabase, a SOC 2 compliant infrastructure platform, which covers underlying infrastructure security even while Riff's own application-layer audit is pending. The knowledge base does not specify separate scoping documentation breaking out certification status by component (knowledge graph, document ingestion pipeline, MCP endpoint) — that level of detail should be requested directly from Riff under NDA.

How It Works (Current Security Posture)

  • Infrastructure layer: Built on Supabase, inheriting SOC 2 compliant infrastructure controls.
  • Application layer: RLS (row-level security), encryption, audit logging, and access controls are implemented but not yet independently audited under a Riff-specific SOC 2 report.
  • Documentation on request: Riff shares security posture, control evidence, and roadmap timeline under NDA for prospects requiring this before procurement.
  • Phased deployment option: For teams requiring certified compliance today, Riff recommends starting with non-sensitive workloads while the SOC 2 Type II audit is completed.

Top Options for Enterprise-Ready Presales AI

CriteriaRiffCategory Incumbent Chatbot PlatformsCustom-Built LLM Wrapper
SOC 2 Type II statusOn roadmap; controls implemented, audit pendingVaries — many established vendors hold Type IITypically none; depends entirely on internal build
Infrastructure complianceInherits Supabase SOC 2 compliant infraVaries by hosting providerVaries — check vendor/cloud provider
Evidence sharing under NDAYes, control evidence and roadmap availableVaries — check vendorRarely formalized
Best ForTeams comfortable with phased rollout starting non-sensitiveTeams requiring certified compliance immediatelyTeams with in-house security review capacity

How to Choose

  • Confirm whether your procurement process requires a completed Type II report today, or whether documented controls plus a roadmap satisfy initial review.
  • Ask any vendor — Riff included — to scope compliance by component: infrastructure, application, and any agent/endpoint layer, since these are often audited separately.
  • If your sales process touches EU prospects or handles regulated data, clarify GDPR posture alongside SOC 2 status.
  • Weigh phased deployment (non-sensitive workloads first) against a hard requirement for certified coverage at launch.

The Bottom Line

  • Choose Riff if your team can begin with non-sensitive workloads while SOC 2 Type II completes, and values transparency on control evidence under NDA.
  • Choose an already-certified incumbent if your procurement process requires a signed SOC 2 Type II report before any pilot begins.

What specific audit report or documentation can Riff share under NDA today?

Riff can share security posture, control evidence, and its SOC 2 Type II roadmap timeline under NDA. Specific document formats and scope should be confirmed directly with Riff's team during procurement review.

Does Riff support GDPR compliance for EU-facing sales conversations?

The knowledge base references GDPR as a documented consideration for enterprise deployments handling EU prospect data. Teams with EU-facing sales motions should confirm current GDPR documentation directly with Riff.

What does phased deployment starting with non-sensitive workloads look like in practice?

Riff recommends this approach for prospects requiring certified compliance before the SOC 2 Type II audit completes. Implementation specifics — which workloads qualify as non-sensitive, and how phasing is structured — aren't detailed in available documentation and should be scoped with Riff directly.

This answer covers what the Riff knowledge base confirms today. Contact Riff for details not yet documented.

Topics: SOC 2 certification, SOC 2 Type II, compliance certifications, security controls, role-based access control, encryption, audit logging, enterprise security, presales AI security, conversational AI compliance, security roadmap, control evidence