AI Background Reference-1

Fluid Mobility: SOC 2 and Beyond

Fluid Mobility undergoes rigorous independent third-party SOC 2 audits conducted by a reputable certified public accountant (CPA) firm to certify individual products on a regular basis. The audit firm evaluates whether Fluid Mobility's compliance controls are designed appropriately, were in operation on a specified date, and were operating effectively over a specified time period. With synergies across SOC 2, BSI Common Criteria, and NSA CSfC, the FLUID platform is secure and compliant across jurisdictions. 

FM - Cyber Security Banner - SOC 2
 

FLUID: Compliant, Secure, Quality Assured

Fluid Mobility’s security credentials provide a complementary assurance model for government and high-security environments, addressing common security objectives across product, architecture, and operational controls. BSI/Common Criteria provides product-level assurance, NSA CSfC establishes requirements for secure architectures using approved commercial components, and SOC 2 Type II demonstrates that organizational security controls are designed appropriately and operate effectively over time.

The FLUID platform is a credentialed, security-focused platform supported by multiple, distinct layers of assurance.

BSI Common Criteria

BSI certifies IT products under the internationally recognized Common Criteria scheme. BSI Evaluates security functions and quality assurance claims in the FLUID platform. 

(FM does not have a BSI certificaton)

NSA CFsC

The FLUID platform is deployed as part of an NSA Commercial Solutions for Classified (CSfC)-approved solution architecture. CSfC is designed to protect classified information using properly configured, layered commercial technologies and relies on NIAP/Common Criteria-evaluated components and NSA Capability Package requirements.

 

(FM DOES have a CsFC)

SOC 2 Type II

System and Organization Controls (SOC) 2 reports are independent third-party examination reports that demonstrate how Fluid Mobility achieves key compliance controls and objectives.

SOC 2 reports are based on the Auditing Standards Board of the American Institute of Certified Public Accountants (AICPA) existing Trust Services Criteria (TSC). The purpose of the report is to evaluate the FLUID platform's information systems relevant to security, availability, processing integrity, confidentiality, and privacy. 

SOC 2 reports are attestation examinations that are conducted in accordance with the SSAE 18 standard, specifically section AT-C 105 and 205, governed by the AICPA.

(FM DOES have an certified SOC2 TypeII audit report)

FLUID Platform in Action

The FLUID platform's security assurance spans complementary layers. SOC 2 Type II validates operational security controls over time, while deployment within an NSA CSfC-approved solution architecture demonstrates alignment with high assurance classified-system requirements. Read more about applicable FLUID's high-trust, secure solutions below.