Fluency has achieved SOC 2 Type II certification.
Most vendors announce this and move on. We want to be specific about what it covers, because of what Fluency actually does.
Fluency observes work at the point of execution. Not system logs, not survey responses — the work itself, across every application a team touches. That is a more sensitive position than a tool that stores documents, and it deserves a harder look than a badge on a footer.
What the Certification Actually Covers
SOC 2 Type II is defined by the AICPA and verified by an independent auditor. The distinction from Type I matters: Type I confirms your controls are designed correctly on a given day. Type II confirms they operated correctly across a sustained observation window.
Our audit covers controls for security, availability, confidentiality and privacy. In practice that means:
PII redaction. Personal data, passwords and other sensitive fields are detected and redacted automatically. Observation does not mean capturing everything indiscriminately.
End-to-end encryption. In transit and at rest.
Role-based access controls. Access is restricted by role, enforcing least privilege across the organization.
Regional data residency. Data is stored and processed in the region you choose, with Australian and US regions available, under the privacy laws that apply there.
Third-party penetration testing. External security specialists test the platform on an ongoing basis, and we audit annually rather than treating certification as a one-time event.
Why This Matters More for Work Observation
A documentation tool holds what you chose to write down. A work intelligence platform sees how the work runs — which systems a team touches, where handoffs stall, how a process actually differs from the process on paper.
That is exactly the visibility that makes AI investment decidable. It is also exactly the visibility that a regulated enterprise cannot hand to a vendor on trust alone.
So the security question is not a procurement formality here. It is the first question, and it should be. The observation that makes Fluency useful is the observation that makes the controls non-negotiable.
This is the standard our customers already hold us to. Aon and Specsavers do not run pilots with vendors who treat security as a checkbox.
The Bottom Line
Certification is not the product. What we sell is the ability to see where AI will have the biggest impact, deploy against it, and prove the return against an observed baseline.
SOC 2 Type II is what makes that safe to run inside a regulated enterprise. It is the floor, not the pitch.
If you want the detail — the trust center, our compliance monitoring, custom MSAs — it is all on our security page.



