AI Voice for Business
Published September 2, 2026 · Every claim below was read from the vendor’s own compliance, trust or terms pages on September 2, 2026. This page is about what a procurement review actually asks, not a ranking — for that, see the flagship comparison. This is not legal advice.
The short answer
Four vendors publish a SOC 2 Type II. One publishes “SOC2” with no report type stated anywhere we could read. Type I and Type II are different assurances, and a procurement questionnaire will ask which.
The sharpest split is what happens to your text. Amazon reserves the right to use and store customer content for service improvement including model training. Azure states that for prebuilt neural voice, neither input text nor output audio is stored. Those are opposite defaults.
Only one vendor publishes an SLA number for speech. Google commits to “Text-to-Speech >= 99.9%” monthly uptime. Nobody else we read publishes a figure for this service.
And four providers never state that you own the audio at all. If your contract requires you to warrant ownership of delivered work, that is the question to settle first — it is set out in our commercial use guide.
Basis: vendor compliance and legal pages only, checked September 2, 2026 — no accounts, no sales calls, no questionnaires answered (how we verify).
On this page
Certifications, and the type question
A SOC 2 Type I reports that controls are designed appropriately at a point in time. A Type II reports that they operated effectively over a period. Vendors that hold a Type II generally say so.
| Provider | What the vendor publishes |
|---|---|
| Cartesia | “Cartesia is GDPR, SOC 2 Type II, PCI-DSS service provider, and HIPAA compliant” |
| ElevenLabs | “We’re certified SOC2 and GDPR compliant” — no report type stated; a search of the page text returns zero occurrences of “type” |
| Murf AI | “We are ISO 42001, ISO 27001, SOC 2 Type II, CCPA and GDPR compliant”, and separately that it “completed a SOC 2 Type II audit with no exceptions, receiving a ‘clean’ report” |
| OpenAI | ISO/IEC 27001:2022 “for OpenAI’s API, ChatGPT Enterprise, and ChatGPT Edu services”; SOC 2 report covering “July 1, 2025 to June 30, 2026” |
| Speechify | “SOC 2 Type II”, alongside “Encryption in transit and at rest” and “No training on customer data” |
Murf publishes the most specific position of any vendor here, and it is worth noting because Murf is otherwise the least transparent vendor in this comparison on pricing. A named ISO 42001 — the AI management systems standard — alongside a clean Type II with no exceptions is a stronger disclosure than several larger competitors offer.
OpenAI is the only vendor that dates its report period, which is exactly what a reviewer needs: a certification without a period is not assessable. Note its ISO scope names the API specifically.
ElevenLabs is the one to query. Its enterprise page says “We’re certified SOC2 and GDPR compliant” and its documentation repeats “ElevenLabs maintains SOC2 certification”, but no report type appears on either. Its trust centre, where a subprocessor list and certification detail would normally live, served only a JavaScript shell when we fetched it, so we could not read it. That is a question for a call, not a defect — but it is a question.
For the cloud platforms, check scope rather than existence. Amazon, Google and Microsoft hold extensive certifications; what matters for procurement is whether the specific speech service is in scope, and that is published per service in each platform’s compliance documentation rather than as a company-level claim.
Will they train on your content?
This is the question that most often stops a deployment, and the vendors are further apart here than anywhere else on this page.
Amazon reserves the right by default. Verbatim: “AWS AI services may use and store customer content for service improvement, such as fixing operational issues, evaluating service performance, debugging, or model training.” An opt-out mechanism exists at the organisation level in AWS, and any buyer relying on it should confirm it is applied before use rather than after.
Azure states the opposite for prebuilt voices. Verbatim: “Neither input text nor output audio content is stored” in the synthesis path for prebuilt neural voice. And on custom voices: “A customer’s training data is used only to develop that customer’s custom voice models and isn’t used by Microsoft to train or improve any Microsoft text to speech voice models.” That is the clearest no-training statement in this comparison.
Speechify states it plainly: “We never train models on your data”, alongside “No training on customer data” in its security summary.
ElevenLabs offers a mode rather than a default: “our optional Zero Retention Mode ensures none of your content or data are retained on our servers”. Optional is the operative word — it is something you must enable, and it is also the precondition for its HIPAA position.
Google describes its service as stateless for this purpose. A buyer should read the current Cloud terms for the service rather than the general statement, since Google distinguishes its consumer and cloud data practices.
Data residency, and what it actually covers
Residency is usually sold as a location guarantee. Read what it guarantees.
ElevenLabs is admirably precise, and the precision is the warning. Data residency “is an Enterprise feature”, and: “While storage will take place in the selected location, processing may nevertheless occur outside of the selected location, including by ElevenLabs’ international affiliates and subprocessors, for support purposes, and for content moderation purposes.” Storage residency and processing residency are different products, and most buyers assume they have bought both. A narrower carve-out exists: “with respect to EU residency, users may restrict processing to the EU by using Zero Retention Mode and the API.”
Its company-level disclosure is separate: “We maintain hosting and/or server locations in the United States, the Netherlands, and Singapore.”
Azure ties residency to the resource’s region and enforces region by credential scoping rather than by hostname, which is a stronger guarantee than an endpoint choice. Google publishes regional and multi-regional endpoints framed explicitly as a data-location control, stating that nothing else about the API changes. MiniMax discloses that personal data “are stored in the data center located in the United States”, with its international entity being Nanonoble Pte. Ltd.
The same distinction appears in our real-time comparison: OpenAI publishes ten regional hostnames, but for the audio group containing text-to-speech most regions provide storage residency only, with processing in the United States and Europe.
Service levels
Google is the only provider publishing an SLA figure for speech synthesis that we found: “Covered Service Monthly Uptime Percentage Text-to-Speech >= 99.9%”.
ElevenLabs gates SLA terms to its Enterprise tier — the plan card reads “Custom terms & assurance around DPA/SLAs” — without publishing a number. Murf states “We typically offer 99% uptime”, which is a statement of typical behaviour rather than a commitment. For the other providers we found no published speech-specific SLA.
If uptime is a contractual requirement for you, that narrows the field considerably before any other consideration.
What sits behind the Enterprise plan
Several controls a security review will require are not available on self-serve plans at all. ElevenLabs is explicit, listing under Enterprise: “Custom terms & assurance around DPA/SLAs”, “BAAs for HIPAA customers”, “Custom SSO”, “More seats and voices” and “Elevated concurrency limits”. Its HIPAA position is conditioned three ways: “HIPAA support is available when Zero Retention Mode is enabled and a Business Associate Agreement (BAA) is in place” — and the vendor’s wording is “HIPAA-eligible configurations”, not HIPAA compliant, which is a distinction a reviewer will care about.
One scope note worth carrying: ElevenLabs’ published BAA page is written for its Agents product — “ElevenLabs Agents is one of ElevenLabs’ HIPAA-eligible services” — and does not state that the standalone text-to-speech API is among them, nor enumerate which services are. If you need PHI handling on text-to-speech specifically, ask for that in writing.
Not everything is gated. ElevenLabs publishes its DPA publicly and applies it to self-serve customers through its terms, with EEA Standard Contractual Clauses incorporated and “deemed executed upon this DPA taking effect”. A DPA you do not have to negotiate is a genuine procurement saving.
Who owns the output
The question a legal review asks last and should ask first. Four of the ten never state, in any numbered clause, that you own the audio you generate — Murf, Speechify, Cartesia and Resemble AI. Amazon states it plainly in its service terms, and OpenAI assigns output rights outright.
If your customer contracts require you to warrant ownership of delivered audio, that determines your shortlist before certifications do. The clause-by-clause position for all ten is in our guide to can you use AI voices commercially.
Questions to put to a vendor in writing
- Is your SOC 2 a Type I or a Type II, and what period does the report cover? One vendor here publishes neither.
- Is the speech service in scope of that certification, or is the certification company-level?
- Do you train on our inputs or outputs by default, and if so how do we opt out? Get the answer scoped to the specific service.
- Does residency cover processing, or only storage? At least one vendor documents that it covers storage only.
- What is the SLA figure, and is it contractual? Only one vendor publishes a number for speech.
- Do we own the output? Four vendors’ terms do not say.
- Which plan is each of these on? DPA terms, SSO, BAAs and residency are frequently Enterprise-only.
Frequently asked questions
Which AI voice providers are SOC 2 Type II?
Cartesia, Murf AI and Speechify state Type II explicitly, and OpenAI publishes a dated SOC 2 report period alongside ISO/IEC 27001:2022 scoped to its API. ElevenLabs states “SOC2” without a report type on any page we read.
Will these vendors train on our data?
It varies by default, not just by contract. Amazon states AWS AI services “may use and store customer content for service improvement… or model training”. Azure states neither input text nor output audio is stored for prebuilt neural voice. Speechify states it never trains on customer data. ElevenLabs offers Zero Retention Mode as an option you enable.
Does anyone publish an SLA?
Google publishes “Text-to-Speech >= 99.9%” monthly uptime. ElevenLabs gates SLA terms to Enterprise without a public number, and Murf states it “typically” offers 99% uptime, which is not a commitment.
Can we get a BAA for HIPAA?
ElevenLabs offers BAAs to enterprise customers with Zero Retention Mode engaged, describing the result as “HIPAA-eligible configurations” rather than HIPAA compliance — and its published BAA page is scoped to its Agents product. Cartesia states it is HIPAA compliant. The cloud platforms handle this through their standard agreements.
Is data residency enough for our EU requirements?
Read what it covers. ElevenLabs documents that storage occurs in the selected location while “processing may nevertheless occur outside” it, with a narrower EU-only path available through Zero Retention Mode and the API.
Which is best for enterprise?
We do not rank that, because the answer depends on which of these gates binds you. If it is ownership, three providers answer clearly and four do not. If it is an SLA, one publishes a figure. If it is no-training-by-default, Azure’s statement is the most explicit.
Sources and what we could not verify
Every claim was read from the vendor’s own enterprise, compliance, trust or legal pages on September 2, 2026. Ownership positions are set out clause by clause in our guide to can you use AI voices commercially; the method is on the methodology page. This page reports what vendors publish and is not legal advice.
What we could not verify
- Any certification itself. We read vendor claims about their certifications; we did not obtain or review a single report.
- ElevenLabs’ SOC 2 report type. Not stated on any page we read, and its trust centre served a JavaScript shell we could not parse.
- Whether company-level certifications cover the speech service specifically for several vendors.
- Which ElevenLabs services besides Agents are HIPAA-eligible. The published page names one and does not enumerate the rest.
- Whether opt-outs from training are applied by default or must be configured, for the platforms that permit them.
- Subprocessor lists where they live behind JavaScript-only trust centres.
- Anything about audio quality. No listening test has been run.
Change log
September 2, 2026 — First publication. All claims read from official vendor pages on September 2, 2026 and dated accordingly.
Published September 2, 2026 · Compliance postures change and certifications lapse; every statement here carries its check date for that reason. Corrections are recorded with their date on the corrections page. Independence note: this page contains no affiliate links, and no vendor paid for placement or influenced the order — see how we make money and our editorial policy.