Security at Fluency
Last updated: September 15, 2026
We build a security operations platform, so customers reasonably expect us to hold ourselves to the standard we help them meet. This page describes how Fluency Corp, Inc. runs its own information security program, how security is enforced inside the product, and how to reach us about a vulnerability or a documentation request.
Audits and certifications
SOC 2 Type II
Fluency undergoes SOC 2 Type II examinations performed by an independent external auditor, covering the Security, Availability, and Confidentiality Trust Services Criteria. Examinations are conducted on an annual observation period. The current report is shared with customers and evaluating prospects under NDA — request it below.
GDPR
We maintain an active GDPR program. Our roles as controller and as processor, the lawful bases we rely on, and the rights available to EU, UK, and EEA residents are set out in our Privacy Policy.
ISO/IEC 42001:2023 — in progress
Because our product applies AI to security decisions, we are implementing an AI management system aligned to ISO/IEC 42001:2023 in the producer role, with AI governance and AI risk management treated as part of the security program rather than separate from it. This work is in progress and Fluency is not yet certified to ISO/IEC 42001. We will update this page when that changes.
Regulated data
Fluency is not a HIPAA covered entity, and HIPAA is not a certification anyone issues — so we do not claim to be “HIPAA certified.” Some of our customers do carry HIPAA obligations, or comparable obligations under other regimes. In those relationships the regulatory duty sits with the customer, and our role is to store and handle their data in a way that supports it: encryption in transit and at rest, role-based access, enforced tenant scope, defined retention and disposal, and audit evidence they can show their own assessors.
If you have specific regulatory or contractual requirements for how your data is stored, raise them during evaluation. We would rather tell you plainly what we do and do not support than have you discover the gap later.
Our information security program
Fluency operates a documented information security management system. Policies are owned by named roles, reviewed and re-approved on an annual cycle, and mapped to the controls our auditors test. Personnel accept the applicable policies and a confidential information agreement, and complete security training as part of onboarding.
The program includes written policies covering:
Risks are tracked in a risk register with assigned owners and treatment decisions. Vendors and subprocessors are reviewed before use and reassessed under our third-party management policy. Security incidents follow a documented incident response plan that defines severity, escalation, containment, and customer notification, and business continuity and disaster recovery planning is maintained and reviewed on the same annual cycle.
Security in the product
Fluency SIEM handles customer security telemetry, which makes access control and scope enforcement part of the product design rather than a configuration afterthought.
Authentication
Authentication supports MFA and OAuth. Headless and API access uses the same authentication level as the Fluency interface, with additional permission boundaries applied on top.
Authorization and tenant scope
Role-based access governs both capabilities and data. Tenant scope is enforced by the platform, so an MSSP analyst sees the tenants they are assigned and a tenant user sees their own environment — the same boundary applies whether the request comes from a person, an API client, an automation, or an AI agent.
Credential handling
Integration tokens and credentials are entered through a separate HTTPS channel rather than pasted into a chat or conversational surface, so secrets never become natural-language transcript content.
Bounded AI access
AI calls approved capabilities, not unrestricted backend endpoints. Each capability defines the allowed scope, the fields that are valid to query, the data source used, the output shape returned, and whether the workflow is read-only, validation-only, or permitted to change state.
Auditability
Workflows are built around evidence and deterministic outputs. The logic layer distinguishes live data, cached data, report artifacts, and locked snapshots where that distinction matters, so a team can reconstruct what an answer was based on.
Encryption and retention
Data is encrypted in transit and at rest under our cryptography policy, which also governs key lifecycle. Every Fluency package includes one year of data retention; classification, retention, and secure disposal follow our data management policy.
Secure development
Security requirements are applied across the development lifecycle under our secure development policy: change management and code review before release, separation of development and production environments, least-privilege access to production systems, and vulnerability management with remediation timelines set by severity. Infrastructure and endpoint configuration, logging, and monitoring are governed by our operations security and asset management policies.
This website
fluencysecurity.com is served over HTTPS only, with HTTP Strict Transport Security including subdomains and preload. Responses carry a Content Security Policy restricting script, style, frame, and connection sources to an explicit allowlist, with object-src 'none' and form submissions limited to approved endpoints. We also set X-Content-Type-Options: nosniff, Referrer-Policy: strict-origin-when-cross-origin, Cross-Origin-Opener-Policy: same-origin, frame-ancestor restrictions, and a Permissions Policy that denies camera, microphone, geolocation, and payment access.
Analytics on this site are privacy-preserving by default, and advertising and remarketing cookies stay off unless you accept them. The detail is in our Privacy Policy.
Reporting a vulnerability
If you believe you have found a security vulnerability in a Fluency product or in this website, please tell us at contact@fluencysecurity.com with “Security” in the subject line. Helpful reports include the affected component or URL, the steps to reproduce, the impact you believe it has, and any proof-of-concept detail. We will acknowledge your report and keep you informed while we investigate.
We ask researchers to:
- Give us a reasonable opportunity to remediate before disclosing publicly.
- Test only against your own account, tenant, or data — never another customer’s.
- Avoid testing that degrades service, such as denial of service, spam, or automated load testing.
- Avoid accessing, modifying, or retaining data that is not yours, and tell us immediately if you encounter customer data.
- Avoid social engineering, phishing, or physical attacks against our staff, customers, or facilities.
We will not pursue or support legal action against researchers who report in good faith and follow these guidelines. We do not currently operate a paid bug bounty program, but we credit reporters who want acknowledgement.
Reporting an incident or suspected compromise
Existing customers who suspect a security incident affecting their Fluency environment should contact support@fluencysecurity.com and, where the situation is urgent, use the escalation path established during onboarding so it reaches an on-call engineer rather than a queue.
Requesting documentation
For a SOC 2 report, a completed security questionnaire, a subprocessor list, a data processing agreement, or policy summaries for a vendor review, contact contact@fluencysecurity.com or your Fluency account contact. Audit reports and internal policy documents are shared under NDA.
