The Unbounded SIEM

Cases, not alerts.

If your SIEM isn’t producing cases, you don’t have a SIEM. You have an alert machine.

Fluency compares every signal with the history of the person or device behind it, groups related alerts into one case per entity per day, and scores that case by how much independent evidence agrees. Analysts start with a short queue of explained cases, not a wall of alerts.


From $7 per user a month, one year of retention included →
A Fluency case for one user: risk score 14,400, Critical, built from two behavior rules scored 4,400 and 2,800
One user, one day, one case. Two behavior rules, 4,400 and 2,800, agree, so the case scores 14,400.Expo demonstration tenant · synthetic identities

Recognized by G2 · Fall 2026

High performer. Best support.

Customer satisfaction and support quality, recognized in G2's Fall 2026 reports.

G2 Best Support Fall 2026 badgeG2 High Performer Fall 2026 badge

From data to a case

Each step makes the data smaller and more meaningful.

Everything that arrives is raw data. By the time it reaches an analyst it has been enriched, matched against behavior rules, and grouped into a case that has already been scored. That is where the noise goes.

Five states of data: raw data, events, notable events, alerts and cases
Raw data → events → notable events → alerts → cases.

Events

Records are collected, enriched (a latitude and longitude becomes a country) and stored.

Notable

An event matches a behavior rule’s condition.

Alerts

The rule’s full conditions are met, including whether this is new for the entity.

Cases

Related alerts for one entity on one day are clustered and scored for review.

Behavioral analytics

A behavior is a signature plus history.

The signature says what happened: a sign-in, a group change, a data-loss match. The history says whether it is new for this person. You shouldn’t be hacked all the time, so something that has never happened before is a far stronger signal than something that happens every day.

A signature plus history produces an alert; Behavior Summary clusters and scores alerts
Fluency tracks the ISPs, countries, operating systems and actions each identity normally uses.

ML_NEW_USER

First time for this user

This rule has never fired for this person before.

ML_NEW_ALERT

First time in the organization

Nobody in the organization has ever triggered this alert.

ML_NEW_GEO_ISP

First time from here

This person has never signed in from this location and network.

Risk scoring

The score counts evidence that agrees, not alerts that repeat.

Fluency groups related alerts by entity, one day at a time. A case’s score is not the sum of its rules. It rises when separate, unique evidence points the same way, and it stays put when the same alert fires again.

The case in the screenshot

  1. 6:10 AM: the user signs in from Johannesburg on an ISP they have never used. 2,800, with two first-time flags.
  2. 6:10 AM: the same user adds a member to a group, which they have never done before. 4,400.
  3. Result: two independent pieces of evidence agree. The case scores 14,400, Critical.

Raises the score

Different behavior rules that agree. First time for this user, for the organization, or from this location and network.

Doesn’t raise it

Volume. Twenty bad logins and a thousand bad logins are the same evidence: multiple bad logins.

Triggered events on a case, each behavior rule with its score and first-time flags
Every rule shows its score, its first-time flags and the raw fields behind it.Expo demonstration tenant · synthetic identities

The score measures certainty, not damage.

A high score means Fluency is more certain a case needs a look, not that it is the most harmful. Because each new, independent piece of evidence adds to it, the score has no ceiling. The bands mark how certain we are.

BandRisk scoreWhat to do
Critical8,000 and aboveReview now
Serious2,000 – 7,999Review this shift
Moderate800 – 1,999Some supporting evidence
LowBelow 800Little supporting evidence

First time in the organization

One rule can be enough, when nobody has ever triggered it.

A user clicks a link in a Teams message. Defender allows the click, then flags the link as phishing. It is the first time that alert has fired for this user and the first time anywhere in the organization. A single rule scores 8,800, Critical, and Fluency’s AI triage recommends escalating to Tier 2.

An analyst then takes it further in Claude. The evidence shows Microsoft removed the message 14 seconds after the click, which the first triage had missed. The verdict: about 80% likely to be a real issue, and one check left to settle it.

A Defender alert flagged as first time in the organization and first time for the user, scored 8,800 Critical
First time in the organization and first time for this user: 8,800, Critical.Expo demonstration tenant · synthetic identities

Under the hood

One record, enriched once, sent everywhere it’s needed.

Fluency runs on the Ingext streaming framework. Each record is collected, enriched once before it is stored, then routed to several places at once: the data lake for search and reporting, the security modules for detection, and notification. Detection is a destination on the pipe, not a separate system.

Ingress, transformation and routing, fanning out to notification, the data lake and Event Watch
Ingress → transformation → routing. One record can go to notification, the data lake and detection at the same time.

Activity

What happened

Sign-ins, changes and alerts from identity, email, endpoint, cloud and network sources, streamed continuously and turned into cases.

Resources

What things look like

Configuration snapshots, at least daily: Office 365 users, devices, groups and apps; endpoint agents and OS versions; firewall configuration; the latest CVEs. They give every case context and drive posture reviews and compliance evidence.

Compliance evidence

Know what your evidence actually supports.

Fluency maps live evidence onto NIST SP 800-53 Rev. 5, with related views for CSF 2.0, 800-171, CMMC and ISO 27001. Each control is marked supported, partial or not observed, and a source that failed to report is shown as a collection gap, never as a failed control.

Fluency supports readiness. Certification decisions stay with your assessor, and it works alongside platforms such as Vanta and Drata.

NIST SP 800-53 Rev. 5 readiness review with evidence coverage
A NIST 800-53 readiness review built from live telemetry, with gaps named.Expo demonstration tenant · synthetic identities

Pricing and scale

Priced by the people you protect.

Fluency is priced per user, with storage included. You are not penalized for turning on another log source.

$7

per user a month (SMB)

3GB

storage included per user

$2.99

per GB only above the allowance

1 year

retention included

For MSSPs and MSPs

One customer or the whole fleet. Never both in one answer.

Access is checked two ways on every request: role decides what someone can do (Admin, Operator, CISO, Analyst), and scope decides which tenants they can reach. An MSSP sees every customer under its connectors, an MSP sees a hand-picked set, and a customer sees only itself. Analysts and AI clients inherit exactly that access.

The company behind the product

A team that helps you put security intelligence to work.

Fluency combines its SIEM with hands-on deployment and ongoing support. We help customers overcome integration obstacles, establish useful workflows, and build operational capability.

Deploy with a practical plan

Agree on the first sources, access requirements, and questions to answer. Verify data flow and usable results as onboarding progresses.

Operate across customers

For MSSPs, multi-tenant workflows support customer onboarding, health reviews, investigations, and reporting within the appropriate customer scope.

Keep improving with support

Work with a team that understands the product and the operational obstacles. Fluency was recognized for Best Support in G2’s Fall 2026 reports.

Meet the team behind Fluency

Bring your own data

See your own alerts become cases.

Start with Microsoft 365. We’ll show you the cases, the scores and the evidence behind them.