Everyone says they're secure. How do you know?
We recently completed our SOC 2 Type II examination.
Going through the process gave our team an opportunity to step back and think about a question that matters to us and, more importantly, to the organisations that trust us:
Why does this matter to our clients? Because the reality is that almost every technology company says security is a priority.
Visit enough websites and you'll see familiar phrases: Secure. Trusted. Enterprise-grade. Built with security in mind.
The challenge is that those words, on their own, don't tell you very much.
When you're evaluating a technology provider that may become part of your security, mobility, data, or operational environment, a more important question is: How do you know what is behind the claim?
That's one of the reasons Fluid Mobility chose to pursue SOC 2 Type II.
And since we've recently gone through the process ourselves, we wanted to share what SOC 2 Type II means, why we pursued it, and why we believe independent validation is becoming an increasingly important part of evaluating technology providers.
What Is SOC 2 Type II?
SOC 2 is an independent examination that evaluates an organisation's controls against applicable criteria relating to areas such as security, availability, processing integrity, confidentiality, and privacy.
The distinction between SOC 2 Type I and SOC 2 Type II is important.
SOC 2 Type I
A Type I examination evaluates whether relevant controls are suitably designed and implemented at a specific point in time.
SOC 2 Type II
A Type II examination evaluates the design and operating effectiveness of relevant controls over a defined period of time.
In simple terms:
It's one thing to say you have security controls. It's another to demonstrate that those controls are operating over time.
That distinction is an important reason organisations may consider SOC 2 Type II when evaluating a technology provider.
Why Did Fluid Mobility Pursue SOC 2 Type II?
At Fluid Mobility, our technology helps organisations bring real-world context into mobility, security, safety and operational decisions.
That can involve supporting environments where organisations are managing mobile devices, sensitive information, security policies, people, assets, and operations.
We believe that comes with responsibility.
Our clients shouldn't simply have to take our word for how seriously we approach the processes and controls behind our platform.
They should be able to ask questions. They should expect evidence. And they should be able to evaluate us as they would any other technology provider operating within their environment.
SOC 2 Type II was one way for us to demonstrate that commitment through an independent examination.
Of course, completing a SOC 2 Type II examination isn't a substitute for every security or vendor-risk question an organisation may have.
Nor should a logo or report be treated as a shortcut for proper due diligence.
But independent validation can help move the conversation beyond: "They say they're secure." To: "How do they demonstrate it?"
We think that's a much better conversation.
A Security Badge Doesn't Tell the Whole Story
One thing that became particularly clear to us is that security can be difficult to evaluate from the outside.
Technology buyers can see product features. They can watch demonstrations. They can review integrations and pricing. But the processes behind a technology provider are often less visible. For example:
- How is access managed?
- How are risks identified and addressed?
- How are important controls monitored?
- How does the organisation protect sensitive information?
- How does the organisation demonstrate that its processes are operating as intended?
Those aren't always questions answered by a product demo. And they're increasingly important as technology providers become more connected to an organisation's systems, devices, data, and operations.
That is why we believe organisations should look beyond security claims alone.
The badge may start the conversation. What is behind it matters more.
What Should You Ask When Evaluating a Technology Provider?
"Are you secure?" is a reasonable question. But it's also very broad, a more useful conversation may start with questions such as:
1. How Do You Protect Our Information?
Understand what information the provider will handle and how the organisation approaches protecting it.
2. How Is Access Managed?
Ask who can access sensitive systems and information and how that access is controlled.
3. How Do You Identify and Manage Risk?
Security isn't static. Understanding how an organisation approaches risk management can provide important context.
4. Are Relevant Controls Independently Assessed?
Independent assessments can provide an additional layer of assurance beyond a provider's own security statements.
5. How Do You Demonstrate That Your Controls Are Working?
This may be one of the most important questions.
Because having a policy or process is one thing.
Demonstrating that it operates as intended over time is another.
Security Is About More Than Product Features
When organisations evaluate technology, features understandably receive a lot of attention.
-
Does it solve the problem?
-
Will it integrate with existing systems?
-
Can it scale?
-
What will it cost?
Those questions matter but the technology itself is only part of the evaluation. The organisation behind the technology matters too.
As organisations rely on more cloud services, mobile platforms, connected systems, and specialised technology providers, understanding how a provider approaches security and risk becomes part of understanding the overall relationship.
That's why, from our perspective, security shouldn't simply be a marketing claim.
It should be something an organisation is prepared to discuss, demonstrate, and where appropriate, have independently assessed.
What Does SOC 2 Type II Mean for Fluid Mobility?
For us, completing a SOC 2 Type II examination represents an important milestone. But more importantly, it reinforces something we believe should apply across the technology industry:
Trust shouldn't depend entirely on what a provider says about itself.
Organisations should be able to ask questions. They should expect transparency. And when technology plays a role in protecting people, devices, information, or operations, they should look for meaningful evidence to support important security claims.
We pursued SOC 2 Type II because we believe our clients deserve that level of accountability.
And having recently gone through the process ourselves, we wanted to share the experience and the thinking behind why we chose to do it.
Because at the end of the day:
Everyone can say they're secure.
The more important question is:
How do you show it?
Frequently Asked Questions
What is SOC 2 Type II?
SOC 2 Type II is an independent examination that evaluates the design and operating effectiveness of relevant controls over a defined period of time.
What is the difference between SOC 2 Type I and Type II?
A Type I examination evaluates the design and implementation of relevant controls at a specific point in time. A Type II examination evaluates relevant controls over a defined period, including their operating effectiveness.
Does SOC 2 Type II mean a company is completely secure?
No. SOC 2 Type II is not a guarantee that an organisation will never experience a security incident. It should be considered as one part of a broader technology-provider and vendor-risk evaluation.
Why should organisations consider SOC 2 Type II when evaluating a technology provider?
SOC 2 Type II can provide independent evidence about controls within the scope of the examination. Organisations may consider it alongside their own security, privacy, operational, and vendor-risk requirements.
How should you evaluate a technology provider's security?
Look beyond product features and broad security claims. Ask how the provider manages access, risk, sensitive information, and relevant controls and what evidence they can provide to support their approach.
