// TRUST CENTER

Security, privacy, and HIPAA made clear.

Everything your security and procurement teams need to evaluate Fluent—our controls, HIPAA approach, subprocessors, and policies, in one place.

Contact us

Have a security or procurement question? Reach us directly at trust@fluentworks.com

Compliance

HIPAA-Ready, BAA Available

HIPAA safeguards are built in. Execute a BAA before using Fluent with PHI.

Data Processing Addendum (DPA)

Publicly available for data-protection compliance.

View DPA

Subprocessor Transparency

Public list with 30+ days advance notice before changes.

View subprocessors

Incident Response Program

Defined severity levels and notification timelines.

View details

Support & Availability

Dedicated support with defined response-time targets.

View SLA details

Resources

View all
Security artifacts — on request
On our roadmap
  • SOC 2 Type II Planned

Data collected

Account & user data
Operational scheduling data
Interpreter profile data
Customer organization data
Billing & usage metadata
Security & audit logs
PHI note: A BAA authorizes HIPAA-regulated use of Fluent; it doesn’t change what you can enter. You control what’s submitted and apply the minimum necessary principle — Fluent protects all data with the same controls either way.

FAQ

Yes. Fluent offers a BAA for customers whose workflows involve PHI. A BAA authorizes HIPAA-regulated use; Fluent applies the same controls to all customer data. Contact us or review our BAA for details.

No. Fluent doesn't use AI in the product, and customer data is never used to train any model.

Fluent's infrastructure is hosted on AWS in the United States. Data is encrypted in transit (TLS) and at rest. Backups are encrypted within the same provider.

Fluent maintains a documented incident response plan with severity levels. Breach notification follows our BAA and applicable law. Post-incident reviews identify root causes.

Yes, with a BAA in place — that’s what authorizes HIPAA-regulated use. What your team submits is yours to control under HIPAA’s minimum necessary principle; protecting whatever you do submit is ours.

Yes — multi-factor authentication (TOTP) is available to all users and required for internal staff. SAML-based SSO is on the roadmap.

Yes. PHI access is recorded in an append-only audit log with tamper-resistant storage and queryable investigation tooling.

Yes. Scoped, audited customer data exports are available, protected by step-up verification.

Updates

View all
Compliance June 2026

Trust Center published

We published Fluent's Trust Center to give security, compliance, and procurement reviewers a single view of our security practices, controls, subprocessors, and policies.

Security April 2026

Security & HIPAA program

Fluent maintains a comprehensive security program spanning infrastructure, application, data protection, and access control, with built-in HIPAA safeguards and a Business Associate Agreement available for customers processing PHI.

Compliance March 2026

Immutable PHI access logging

Fluent maintains an append-only, tamper-resistant audit log of PHI access, with tooling to support investigation and review.

Available under NDA

Security artifacts for review teams. Pick what you need and we’ll share them under NDA.

Questionnaires & assessments

Security questionnaire (CAIQ / SIG Lite)

Fluent’s completed responses to the standard cloud-security questionnaires.

HIPAA security risk analysis (summary)

Summary of Fluent’s Security Rule risk analysis under 45 CFR 164.308 — scope, method, findings by severity, remediation status.

As of Jun 2026

Security & architecture

Architecture overview

How Fluent is built and hosted, including environment separation and network boundaries.

Data-flow diagram

Where customer data — including PHI — enters, rests, and leaves the system.

Vulnerability-scanning summary

Latest results from continuous scanning of internet-facing systems and dependencies.

As of Aug 2026

Resilience

Incident response plan

The documented plan covering detection, containment, notification, and remediation.

Business continuity & disaster recovery

Recovery approach including documented RTO and RPO targets.

Corporate

Certificate of cyber liability insurance

Current coverage and limits.

Valid through Mar 2027
Not yet available
  • SOC 2 Type II — On our roadmap. We follow SOC 2 security principles; no audit has been completed.
Frequently asked questions

Answers to common questions from security, compliance, and procurement teams.

Yes. Fluent offers a Business Associate Agreement (BAA) for customers whose workflows involve protected health information (PHI). A BAA authorizes HIPAA-regulated use; Fluent applies the same HIPAA-oriented controls, including PHI access audit logging, to all customer data. Contact us or review our BAA for details.

Yes, with a BAA in place — that’s what authorizes HIPAA-regulated use. Fluent is built for interpreter scheduling and operations, so clinical detail beyond what those workflows need doesn’t belong in it. What your team submits is yours to control under HIPAA’s minimum necessary principle; protecting whatever you do submit is ours.

No. Fluent doesn't use AI in the product, and customer data is never used to train any model.

Fluent's primary infrastructure is hosted on Amazon Web Services (AWS) in the United States. Data is encrypted both in transit (TLS) and at rest. Backups are also encrypted and stored within the same cloud provider.

Fluent maintains a documented incident response plan with defined severity levels. In the event of a confirmed security incident involving customer data, we follow notification timelines specified in our BAA and applicable law. Post-incident reviews are conducted to identify root causes and implement preventive measures.

Customer data is retained for the duration of the subscription and a reasonable wind-down period after termination, as described in our MSA. Audit logs are retained for at least 12 months. Upon request and subject to applicable law, customer data can be deleted in accordance with our data retention and deletion policies.

Fluent maintains a public subprocessor list. We provide at least 30 days' notice before adding a new subprocessor, except in cases of urgent security, legal, or service-continuity needs. Customers can subscribe to updates to be notified of any changes.

Yes. A Data Processing Addendum (DPA) is available for customers who require one for data-protection compliance. Contact trust@fluentworks.com to request a copy.

Yes — multi-factor authentication (TOTP) is available to all users and required for internal staff. SAML-based SSO is on the roadmap.

Yes. PHI access is recorded in an append-only audit log with tamper-resistant storage and queryable investigation tooling.

Yes. Scoped, audited customer data exports are available, protected by step-up verification.