AI Dispatch
The wirewireSep 6, 2026

Sales and voice agents cite SOC 2, HIPAA compliance; audit finds no certificate published

Two vendors name specific security standards on their sites; neither publishes a certificate, auditor or report date behind the claim.

Two AI agents reviewed by AI Dispatch this week cite compliance with major security and privacy standards, but neither publishes a certificate, auditor name or report date that would let a customer verify the claim.

Artisan's Ava, an outbound sales agent that "finds leads, enriches them, sends personalized messages, and books meetings on behalf of your reps," states on its site that it is "SOC 2 Type II GDPR" certified. The same page lists "Role-based access & audit log" as a feature and says customers "can set rules per campaign and change them anytime." Artisan counts "6,000+ sales teams, from startups to enterprise" as customers, without naming any.

MirrorFly AI Voice Agent, a voice-agent platform marketed for customer service and health care call handling, states its products are built "meeting key regulatory standards, including SOC 2, HIPAA, GDPR, and PCI DSS." MirrorFly markets agents that "autonomously make & take calls, without human intervention," including for "appointment booking, medical queries, and follow-ups" in health care.

AI Dispatch's fact-checking review, completed Sept. 6, credited both companies with partial scores on the index's compliance dimension for naming specific standards rather than making a vague claim: Artisan scored 2 of 3, MirrorFly 1 of 3. Auditors found no certificate, auditor or report date published for either, and scored MirrorFly lower because its page describes its agents as "meeting" the named standards rather than certified against them. Neither company's audit-trail claim describes what is logged, how long records are kept, or whether they are tamper-evident or reviewable by a customer. Neither publishes an insurance carrier, coverage limit or indemnity term.

Naming a standard is not the same as proving compliance against it, a distinction AI Dispatch's fact-checkers apply consistently across the index: a claim of "SOC 2" or "HIPAA" compliance, standing alone, is not a customer-reviewable audit report.

Entries in this piece 2

Published index entries backed by the same source documents this piece cites.

Sources 8

  1. Ava finds leads, enriches them, sends personalized messages, and books meetings on behalf of your reps.
    artisan.co · checked Aug 1, 2026
  2. SOC 2 Type II GDPR
    artisan.co · checked Aug 1, 2026
  3. Role-based access & audit log
    artisan.co · checked Aug 1, 2026
  4. You can set rules per campaign and change them anytime.
    artisan.co · checked Aug 1, 2026
  5. Trusted by 6,000+ sales teams, from startups to enterprise
    artisan.co · checked Aug 1, 2026
  6. MirrorFly AI Voice Agents are built with strong security and compliance measures, making them safe for business use. Their voice SDK and API let companies create custom AI voice agents while meeting key regulatory standards, including SOC 2, HIPAA, GDPR, and PCI DSS.
    www.mirrorfly.com · checked Aug 4, 2026
  7. Launch agents that can autonomously make & take calls, without human intervention.
    www.mirrorfly.com · checked Aug 4, 2026
  8. Healthcare Deliver human-like, empathetic voice assistance for appointment booking, medical queries, and follow-ups.
    www.mirrorfly.com · checked Aug 4, 2026