We recently completed our SOC 2 Type II examination.
Going through the process gave our team an opportunity to step back and think about a question that matters to us and, more importantly, to the organisations that trust us:
Why does this matter to our clients? Because the reality is that almost every technology company says security is a priority.
Visit enough websites and you'll see familiar phrases: Secure. Trusted. Enterprise-grade. Built with security in mind.
The challenge is that those words, on their own, don't tell you very much.
When you're evaluating a technology provider that may become part of your security, mobility, data, or operational environment, a more important question is: How do you know what is behind the claim?
That's one of the reasons Fluid Mobility chose to pursue SOC 2 Type II.
And since we've recently gone through the process ourselves, we wanted to share what SOC 2 Type II means, why we pursued it, and why we believe independent validation is becoming an increasingly important part of evaluating technology providers.
What Is SOC 2 Type II?
SOC 2 is an independent examination that evaluates an organisation's controls against applicable criteria relating to areas such as security, availability, processing integrity, confidentiality, and privacy.
The distinction between SOC 2 Type I and SOC 2 Type II is important.
A Type I examination evaluates whether relevant controls are suitably designed and implemented at a specific point in time.
A Type II examination evaluates the design and operating effectiveness of relevant controls over a defined period of time.
In simple terms:
It's one thing to say you have security controls. It's another to demonstrate that those controls are operating over time.
That distinction is an important reason organisations may consider SOC 2 Type II when evaluating a technology provider.
At Fluid Mobility, our technology helps organisations bring real-world context into mobility, security, safety and operational decisions.
That can involve supporting environments where organisations are managing mobile devices, sensitive information, security policies, people, assets, and operations.
We believe that comes with responsibility.
Our clients shouldn't simply have to take our word for how seriously we approach the processes and controls behind our platform.
They should be able to ask questions. They should expect evidence. And they should be able to evaluate us as they would any other technology provider operating within their environment.
SOC 2 Type II was one way for us to demonstrate that commitment through an independent examination.
Of course, completing a SOC 2 Type II examination isn't a substitute for every security or vendor-risk question an organisation may have.
Nor should a logo or report be treated as a shortcut for proper due diligence.
But independent validation can help move the conversation beyond: "They say they're secure." To: "How do they demonstrate it?"
We think that's a much better conversation.
One thing that became particularly clear to us is that security can be difficult to evaluate from the outside.
Technology buyers can see product features. They can watch demonstrations. They can review integrations and pricing. But the processes behind a technology provider are often less visible. For example:
Those aren't always questions answered by a product demo. And they're increasingly important as technology providers become more connected to an organisation's systems, devices, data, and operations.
That is why we believe organisations should look beyond security claims alone.
The badge may start the conversation. What is behind it matters more.
"Are you secure?" is a reasonable question. But it's also very broad, a more useful conversation may start with questions such as:
Understand what information the provider will handle and how the organisation approaches protecting it.
Ask who can access sensitive systems and information and how that access is controlled.
Security isn't static. Understanding how an organisation approaches risk management can provide important context.
Independent assessments can provide an additional layer of assurance beyond a provider's own security statements.
This may be one of the most important questions.
Because having a policy or process is one thing.
Demonstrating that it operates as intended over time is another.
When organisations evaluate technology, features understandably receive a lot of attention.
Does it solve the problem?
Will it integrate with existing systems?
Can it scale?
What will it cost?
Those questions matter but the technology itself is only part of the evaluation. The organisation behind the technology matters too.
As organisations rely on more cloud services, mobile platforms, connected systems, and specialised technology providers, understanding how a provider approaches security and risk becomes part of understanding the overall relationship.
That's why, from our perspective, security shouldn't simply be a marketing claim.
It should be something an organisation is prepared to discuss, demonstrate, and where appropriate, have independently assessed.
For us, completing a SOC 2 Type II examination represents an important milestone. But more importantly, it reinforces something we believe should apply across the technology industry:
Trust shouldn't depend entirely on what a provider says about itself.
Organisations should be able to ask questions. They should expect transparency. And when technology plays a role in protecting people, devices, information, or operations, they should look for meaningful evidence to support important security claims.
We pursued SOC 2 Type II because we believe our clients deserve that level of accountability.
And having recently gone through the process ourselves, we wanted to share the experience and the thinking behind why we chose to do it.
Because at the end of the day:
Everyone can say they're secure.
The more important question is: