Security & Privacy
Security at Fluid
At Fluid, security, privacy, and the protection of customer data are fundamental to how we design, operate, and continuously improve our platform.Our information security, privacy, and quality controls are independently assessed against recognised industry standards. Fluid is ISO 27001:2022 certified, ISO 9001 certified, and SOC 2 Type II certified, and we operate in accordance with UK and EU GDPR requirements.Our security framework applies multiple layers of protection across the application, infrastructure, people, and operational processes. This includes encryption, least-privilege access controls, secure software development practices, continuous monitoring, vulnerability management, incident response, and business continuity measures.Security and Compliance
ISO 27001:2022 Certified
Fluid operates an Information Security Management System certified to ISO 27001:2022, providing a structured framework for managing information security risks, controls, governance, and continuous improvement. Certification is maintained through independent external audits.
SOC 2 Type II Certified
Fluid has successfully completed a SOC 2 Type II audit, providing independent assurance that our controls relating to security, availability, confidentiality, processing integrity, and privacy are suitably designed and operating effectively over the audit period.
ISO 9001 Certified
Fluid is certified to ISO 9001, demonstrating our commitment to a structured quality management system, consistent service delivery, process governance, customer focus, and continuous improvement.
UK and EU GDPR Compliance
Fluid processes personal data in accordance with applicable UK and EU data protection requirements. Our privacy and information security controls include data minimisation, access controls, defined retention and disposal processes, and mechanisms for supporting data subject rights.
Cyber Essentials Certified
Fluid maintains Cyber Essentials certification, demonstrating the implementation of recognised baseline controls designed to protect against common cyber threats.Data Protection
Encryption in Transit and at Rest
Customer data is protected using industry-standard encryption. Data transmitted between users and the Fluid platform is encrypted using TLS 1.2 or higher, while data stored within the platform, including databases and backups, is encrypted at rest.
Authentication and Access Control
Fluid applies role-based access control and the principle of least privilege to ensure that users and administrators only have access to the information and functionality required for their responsibilities. Multi-factor authentication and Single Sign-On are supported, including integration with Microsoft Entra ID.
Security Monitoring and Audit Logging
Fluid maintains security logging and monitoring across key application and infrastructure components. Audit records are used to support security monitoring, investigation, accountability, and incident response activities.
Vulnerability Management and Penetration Testing
Fluid performs ongoing vulnerability monitoring and regular security assessments. Penetration testing is conducted at least annually, with identified vulnerabilities assessed, prioritised, tracked, and remediated according to risk.
Secure Software Development
Security is incorporated throughout Fluid's software development lifecycle. Changes are subject to documented development, review, testing, approval, and controlled deployment processes before being promoted into production.
Security Updates and Patch Management
Fluid monitors infrastructure and application components for vulnerabilities and applies security updates and remediation measures based on assessed risk and severity.Business Continuity and Incident Management
Data Backup and Recovery
Fluid maintains structured backup and recovery processes using Microsoft Azure. Backup, replication, point-in-time recovery, and geographically resilient infrastructure help support service continuity and recovery in the event of disruption.
Business Continuity and Disaster Recovery
Documented business continuity and disaster recovery arrangements are maintained and periodically reviewed and tested. These processes are designed to support the continued availability of critical services and the timely recovery of systems and data.
Incident Response
Fluid maintains documented incident response and incident management procedures covering preparation, detection, investigation, containment, remediation, recovery, communication, and post-incident review.
Security Awareness
Employees receive security guidance and training appropriate to their responsibilities. Security policies and standards are communicated across the organisation and reviewed as part of Fluid's broader information security management framework.
Customer Support
Customers have access to Fluid's support team for security-related questions, incidents, and service enquiries, with defined escalation procedures available for service-impacting issues.
Cloud Hosting
Fluid is hosted on Microsoft Azure, providing a secure, resilient, and globally established cloud infrastructure for the delivery of the Fluid platform.
Secure Data Centres
Microsoft Azure data centres use multiple layers of physical and operational security, including controlled physical access, monitoring, environmental safeguards, and resilient infrastructure. These controls support the protection and availability of the systems used to host Fluid.
Fluid's application architecture also uses Azure security capabilities to provide logical isolation, network segmentation, monitoring, access control, and resilience.ISO and Cloud Security StandardsMicrosoft Azure maintains a broad range of internationally recognised security and privacy certifications, including ISO 27001 and cloud-specific standards such as ISO 27017 and ISO 27018.
These certifications complement Fluid's own ISO 27001:2022, ISO 9001, and SOC 2 Type II certifications, providing assurance across both the Fluid application environment and the underlying Microsoft Azure infrastructure.
SOC Assurance
Microsoft Azure undergoes independent Service Organization Control assessments covering security and operational controls within its cloud environment.Fluid's own SOC 2 Type II certification provides additional independent assurance over the controls operated directly by Fluid.
Together with Azure's infrastructure controls, this creates a layered security model spanning application, operational, and cloud infrastructure security.By combining Fluid's independently certified security and quality management framework with Microsoft Azure's cloud infrastructure, customers benefit from multiple layers of technical, organisational, and operational protection across the storage, transmission, and processing of their data.





