DeepL's SOC 2 Type II report: what it means for your data security and confidentiality

Key Takeaways

  • DeepL's SOC 2 Type II report independently verifies its information systems against security, availability, processing integrity, confidentiality, and privacy standards.
  • The audit confirmed DeepL never stores DeepL Pro translation data, reinforcing full confidentiality for users.
  • Unlike a Type I report, Type II requires an independent auditor to verify that controls were followed consistently over a 12-month period.
  • Each SOC 2 Type II report is unique, reflecting an organization's specific controls, business objectives, and risk profile.
  • Passing this audit signals to partners, suppliers, and clients that a company prioritizes data security and has proof to back it up.
  • DeepL's full SOC 2 Type II report and Security & Data Residency white paper are available on request.

Does your company have specific security requirements for all the tools and vendors it works with? If you answered yes, good—you should. From GDPR to ISO 27001, you need to consider many important data security and privacy measures.

On that note, we have great news. DeepL now has another qualification to add to our growing list: the SOC 2 Type II report. This extensive auditing procedure provides the proof that security-conscious organizations need when choosing which tools and service providers to work with.

Read on to learn what this is, why it’s important, and how you can access DeepL’s report.

Visit the DeepL Data Security page to see how we protect and secure your data.

What is a SOC 2 Type II report?

an illustration of the Soc 2 type 2 five trust service principles

The American Institute of Certified Public Accountants (AICPA) developed the System and Organization Controls (SOC) 2 Type II report. It’s based on the Trust Services Criteria (TSC) and acts as a way to define proper customer data management. 

The purpose of the SOC 2 report is to evaluate a company’s or organization's information systems based on these five “trust service principles.”

1. Security

Security is a critical principle for all companies or organizations that deal with sensitive or confidential information. For DeepL, this means we put controls in place to protect against theft, unauthorized access, or destruction of our systems and data.

2. Availability

The availability principle is vital for companies that rely on their systems and data to conduct their day-to-day business operations. At DeepL, this means we use controls to maintain the consistent availability of all our systems and data. 

3. Processing integrity

Processing integrity is critical for organizations that rely on accurate data to make business decisions. Meeting this principle requires that controls be put in place to ensure the accuracy and completeness of data processing.

4. Confidentiality

The principle of confidentiality is necessary for organizations that handle sensitive data and information. At DeepL, it means we introduce controls to safeguard the confidentiality of our systems and data. 

For example, the SOC 2 Type II audit verified that we never store any DeepL Pro translation data—effectively maintaining the full confidentiality of users’ data.

5. Privacy

The privacy principle is crucial for organizations that collect, process, or store personal information. At DeepL, it refers to controls put in place to protect the privacy of personal data.

What makes each SOC 2 Type II report unique

According to Maximilian Ehrlich, DeepL’s head of Information Security, it’s important to note that “each SOC 2 Type II report is unique to the organization and, therefore, reflects its own designed controls in accordance with its business objectives, risks, and adherence to the trust service criteria.” 

Because the SOC 2 Type II report provides critical information on how we manage customer data, an outside auditor must issue it. It’s this auditor’s job to assess how well the company or organization in question complies with those five trust principles.

Learn how DeepL helps you safeguard data per HIPAA guidelines.

How is a SOC 2 Type II report different from a Type I report?

If there’s a SOC 2 Type II report, there has to be a SOC Type I, right? Yes, there is—and important distinctions lie between the two. 

The main difference between the Type I and the Type II report is that the Type I describes a company’s existing controls. The Type II requires that an independent auditor check the described controls.

According to Ehrlich, the Type II report proves that “the predefined policies and procedures have been successfully followed for a reporting period of 12 months." A third party verifies this fact. 

As a result, the Type II report is a much stronger testament to existing security controls than a Type I report.

Why are SOC 2 Type II reports important?

Not every company requires their partners and service providers to have passed their SOC 2 Type II report, but the most security-minded organizations do.

Successfully completing the SOC 2 Type II audit is a rigorous, extensive undertaking. Having this report is a clear sign to all potential partners, suppliers, and clients that your company prioritizes data security and privacy. And it’s proof that you’ve put in the work to prove it. 

At DeepL, data security, privacy, and data protection are of the utmost importance. That’s why we’re so pleased to share that DeepL has passed our independent SOC 2 Type II audit of our Pro service, conducted by a Certified Public Accountant (CPA).

Ehrlich perfectly captured DeepL’s shared sentiment, stating: “We are proud to announce our SOC 2 Type II report as further evidence of DeepL’s commitment to security and validation of our security measures."

Explore how DeepL API strengthens security with multiple API keys.

Read DeepL’s SOC 2 Type II report

DeepL's SOC 2 type 2 (service organization controls) report cover

We're happy to share DeepL’s audit verdict and the final report:

200,000+ global enterprises trust DeepL with their data: Read their stories.

Build on a foundation your security team can verify

SOC 2 Type II isn't a checkbox: It's independently verified proof that DeepL's controls hold up under scrutiny. That same commitment to security runs through every DeepL specialized Language AI tool your teams use: 

  • Translator for confidential document translation
  • Write for secure communication drafting
  • Voice for real-time multilingual conversations
  • API for embedding verified, enterprise-grade translation into your own systems

Contact Sales to request DeepL's full SOC 2 Type II report or discuss our Language AI suite. Your global teams move fast—our AI solutions keep their data as secure as it is fluent.

Share