Is this your company?Buyers are checking Suki AI here. Claim suki.ai free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Suki, a leading provider of AI voice technology, is transforming the healthcare industry by reducing administrative burdens for clinicians. Its mission is to reimagine healthcare technology, making it both invisible and supportive. Suki is further expanding its impact through strategic collaborations, integrating its AI solutions into major electronic health record (EHR) systems and telehealth platforms.
SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Documents
List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Suki AI SOC 2 compliant?
Suki AI is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Suki AI HIPAA compliant?
According to Suki AI's public trust center, Suki AI is HIPAA compliant. On SOC2C this listing is Listed.
Is Suki AI CCPA compliant?
According to Suki AI's public trust center, Suki AI is CCPA compliant. On SOC2C this listing is Listed.
Is Suki AI NIST CSF compliant?
According to Suki AI's public trust center, Suki AI is NIST CSF compliant. On SOC2C this listing is Listed.
Is Suki AI SOC 2 Type I or Type II?
Suki AI is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Suki AI's SOC 2 for a vendor risk assessment?
Yes. Suki AI's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Suki AI penetration tested?
Suki AI hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Suki AI secure?
Security isn't a single yes/no, but Suki AI is SOC 2 Type II compliant and holds HIPAA, CCPA, SOC 2 Type II, NIST CSF. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Suki AI have a bug bounty or vulnerability disclosure program?
Suki AI hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@suki.ai or via a /security page (Suki AI lists a security contact).
Who are Suki AI's subprocessors?
Suki AI lists 9 subprocessors on its trust center, including Google Cloud Platform, OKTA, GitHub, Wiz, ThreatLocker. Buyers use this for fourth-party risk review.
Where does Suki AI host or store data?
Suki AI hosts on GCP. Data residency details are on its trust center.
Where is Suki AI's trust center or security page?
Suki AI's trust center is at https://trust.suki.ai. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
What level of control do our clinicians have over the AI-generated notes?
Clinicians have full control. All Suki AI-generated content is presented as editable suggestions that clinicians must review and explicitly accept or reject before finalization in the EHR. The clinician is always in control of the final note content.
How does Suki ensure the accuracy of the clinical notes it generates?
To ensure accuracy, Suki uses a multi-layered approach. Our medically-tuned ASR accurately transcribes conversations. We use grounding techniques to tie AI outputs to factual data from the EMR and encounter transcripts. Most importantly, every AI-generated note is reviewed and approved by the clinician, who has the final say.
What measures are in place for transparency and explainability of your AI?
Suki prioritizes transparency. We provide end-to-end traceability of clinical note content back to sections of the audio recording. While we don't currently provide specific local interpretability measures to end-users , we can provide audio transcripts for user review.
How does Suki support different languages and accents?
Suki's ASR model is trained on a wide variety of user accents to ensure robust and reliable transcription. Suki supports 81 languages. Clinicians can conduct visits in a patient's preferred language, and Suki will create suggested note content in English.
How does Suki AI use Artificial Intelligence?
Suki’s AI combines a proprietary, medically-tuned Automatic Speech Recognition (ASR) model with third-party Large Language Models (LLMs) for advanced note summarization and organization, all deeply integrated within existing EHR workflows.
Does Suki train its own Large Language Models (LLMs)?
No, Suki AI does not train foundational LLMs. We utilize LLMs from third-party providers, such as OpenAI, for tasks like note summarization. Our AI training is limited to our proprietary cognitive AI model, the Automatic Speech Recognition (ASR) module.
Does Suki AI use our data to train AI models?
Our process is to use customer data to train the internal Automatic Speech Recognition Model after identifying information is removed. We do not use your data to train any third-party Large Language Models (LLMs). Our contractual agreements with third-party AI vendors, like OpenAI, explicitly prohibit them from using any data transmitted by Suki for their own model training.
What third-party AI tools do you use, and how do you manage the risks?
Suki integrates LLMs from third-party providers, such as OpenAI, for note summarization. We have a comprehensive third-party risk management policy and program. This includes performing due diligence and risk assessments before engaging any provider, establishing documented agreements with information security requirements, and verifying vendor compliance with frameworks like HIPAA and SOC 2.
How do you protect your AI models from malicious attacks?
Suki proactively mitigates risks such as indirect prompt injection, memory poisoning, and theft by incorporating specific guardrails within our prompting infrastructure. Our prompting mechanisms are not directly exposed to end-users or external entities, which significantly reduces the potential attack surface.
What are "hallucinations" in AI and how does Suki prevent them?
AI hallucinations are instances where the AI generates inaccurate or fabricated information. Suki minimizes the occurrence of hallucinations by employing a meticulously designed prompt structure and robust grounding techniques. These techniques tie AI-generated content to factual information from the EHR and the encounter transcript, enhancing accuracy and reliability. Clinician review of all AI-generated suggestions serves as a primary safeguard.
How do you address potential bias and ensure fairness in your AI?
User trust and safety are top priorities at Suki, and we continuously work to address potential bias and fairness. We identify potential bias sources in our ASR training data and work to mitigate them through targeted data augmentation and model retraining. For our ASR model, we incorporate a wide variety of user accents in our training data. We do not label or use sensitive PII like race or ethnicity in the training of our models or in clinical audits of output quality.
How do you monitor the performance of your AI models?
Suki's model performance is continuously evaluated through automated monitoring of key accuracy metrics, system analytics, and internal quality assurance processes. We use our Patient Documentation Quality Instrument (PDQI) framework to measure note quality, which includes accuracy and checks for hallucinations. We also conduct automated regression tests, manual reviews by clinical experts, and have feedback loops with trusted testers.