Compliance
HIPAA-Ready, BAA Available
HIPAA safeguards are built in. Execute a BAA before using Fluent with PHI.
Subprocessor Transparency
Public list with 30+ days advance notice before changes.
View subprocessorsResources
View all- SOC 2 Type II Planned
Controls
Infrastructure Security
- Hosted on AWS
- Network segmentation & firewalls
- DDoS mitigation
- Automated patching
Access Control
- Role-based access (RBAC)
- Least-privilege by role & team
- MFA available (TOTP)
- Session timeout controls
- SSO — coming soon
Application Security
- TLS encryption in transit
- Input validation
- Secure SDLC practices
- Dependency monitoring
Data Protection
- Encryption at rest
- Encrypted backups
- Workspace data isolation
- Retention & deletion policies
Incident Response
- Documented IR plan
- Severity classification
- Breach notification per BAA
- Post-incident review
HIPAA & PHI Handling
- BAA available
- HIPAA safeguards by default
- No secondary PHI use
- Audit logging for PHI
Organizational Security
- Security awareness training
- Background checks
- Acceptable use policies
- On/offboarding procedures
AI Security & Data Use
- No AI or ML in the product
- No model training on your data
Data collected
Subprocessors
View all- Amazon Web Services (AWS) · Infrastructure Hosting Core Product US
- Google Cloud / Firebase · Authentication & Push Notifications Core Product US
- Stripe · Payment Processing Core Product US
- Twilio · SMS Verification Core Product US
- SendGrid (Twilio) · Transactional Email Delivery Core Product US
- Sentry · Error Monitoring Core Product US
- New Relic · Performance Monitoring Core Product US
- Google Maps Platform · Maps & Geocoding Core Product US
- ConfigCat · Feature Flags Core Product US
- IPify · IP Address Lookup Core Product US
FAQ
Yes. Fluent offers a BAA for customers whose workflows involve PHI. A BAA authorizes HIPAA-regulated use; Fluent applies the same controls to all customer data. Contact us or review our BAA for details.
No. Fluent doesn't use AI in the product, and customer data is never used to train any model.
Fluent's infrastructure is hosted on AWS in the United States. Data is encrypted in transit (TLS) and at rest. Backups are encrypted within the same provider.
Fluent maintains a documented incident response plan with severity levels. Breach notification follows our BAA and applicable law. Post-incident reviews identify root causes.
Yes, with a BAA in place — that’s what authorizes HIPAA-regulated use. What your team submits is yours to control under HIPAA’s minimum necessary principle; protecting whatever you do submit is ours.
Yes — multi-factor authentication (TOTP) is available to all users and required for internal staff. SAML-based SSO is on the roadmap.
Yes. PHI access is recorded in an append-only audit log with tamper-resistant storage and queryable investigation tooling.
Yes. Scoped, audited customer data exports are available, protected by step-up verification.
Updates
View allTrust Center published
We published Fluent's Trust Center to give security, compliance, and procurement reviewers a single view of our security practices, controls, subprocessors, and policies.
Security & HIPAA program
Fluent maintains a comprehensive security program spanning infrastructure, application, data protection, and access control, with built-in HIPAA safeguards and a Business Associate Agreement available for customers processing PHI.
Immutable PHI access logging
Fluent maintains an append-only, tamper-resistant audit log of PHI access, with tooling to support investigation and review.
Policies and agreements available for review.
Master Subscription Agreement (MSA)
The terms governing use of the Fluent platform.
Acceptable Use Policy (AUP)
Guidelines for acceptable use of the Fluent Service.
Privacy Policy
How Fluent collects, uses, and protects personal data.
Business Associate Agreement (BAA)
HIPAA-specific terms for customers processing PHI.
Data Processing Addendum (DPA)
Publicly available for data-protection compliance.
Cookie Policy
Details on cookies and tracking technologies used by Fluent.
Support & SLA Policy
Support tiers, response-time targets, and availability commitments.
Security Incident Response Exhibit
Severity levels, response procedures, and notification timelines.
Security artifacts for review teams. Pick what you need and we’ll share them under NDA.
Questionnaires & assessments
Security questionnaire (CAIQ / SIG Lite)
Fluent’s completed responses to the standard cloud-security questionnaires.
HIPAA security risk analysis (summary)
Summary of Fluent’s Security Rule risk analysis under 45 CFR 164.308 — scope, method, findings by severity, remediation status.
Security & architecture
Architecture overview
How Fluent is built and hosted, including environment separation and network boundaries.
Data-flow diagram
Where customer data — including PHI — enters, rests, and leaves the system.
Vulnerability-scanning summary
Latest results from continuous scanning of internet-facing systems and dependencies.
Resilience
Incident response plan
The documented plan covering detection, containment, notification, and remediation.
Business continuity & disaster recovery
Recovery approach including documented RTO and RPO targets.
Corporate
Certificate of cyber liability insurance
Current coverage and limits.
- SOC 2 Type II — On our roadmap. We follow SOC 2 security principles; no audit has been completed.
Answers to common questions from security, compliance, and procurement teams.
Yes. Fluent offers a Business Associate Agreement (BAA) for customers whose workflows involve protected health information (PHI). A BAA authorizes HIPAA-regulated use; Fluent applies the same HIPAA-oriented controls, including PHI access audit logging, to all customer data. Contact us or review our BAA for details.
Yes, with a BAA in place — that’s what authorizes HIPAA-regulated use. Fluent is built for interpreter scheduling and operations, so clinical detail beyond what those workflows need doesn’t belong in it. What your team submits is yours to control under HIPAA’s minimum necessary principle; protecting whatever you do submit is ours.
No. Fluent doesn't use AI in the product, and customer data is never used to train any model.
Fluent's primary infrastructure is hosted on Amazon Web Services (AWS) in the United States. Data is encrypted both in transit (TLS) and at rest. Backups are also encrypted and stored within the same cloud provider.
Fluent maintains a documented incident response plan with defined severity levels. In the event of a confirmed security incident involving customer data, we follow notification timelines specified in our BAA and applicable law. Post-incident reviews are conducted to identify root causes and implement preventive measures.
Customer data is retained for the duration of the subscription and a reasonable wind-down period after termination, as described in our MSA. Audit logs are retained for at least 12 months. Upon request and subject to applicable law, customer data can be deleted in accordance with our data retention and deletion policies.
Fluent maintains a public subprocessor list. We provide at least 30 days' notice before adding a new subprocessor, except in cases of urgent security, legal, or service-continuity needs. Customers can subscribe to updates to be notified of any changes.
Yes. A Data Processing Addendum (DPA) is available for customers who require one for data-protection compliance. Contact trust@fluentworks.com to request a copy.
Yes — multi-factor authentication (TOTP) is available to all users and required for internal staff. SAML-based SSO is on the roadmap.
Yes. PHI access is recorded in an append-only audit log with tamper-resistant storage and queryable investigation tooling.
Yes. Scoped, audited customer data exports are available, protected by step-up verification.