We integrate AI, automated tools, and pentesters to continuously help your development team build secure software without delays.
Summary from the company’s website.
Publicly advertised compliance posture
As observed on September 8, 2026 on the organization’s public trust center.
-
SOC 2
Independent CPA audit of controls for security, availability, and confidentiality.
-
SOC 3
Public summary of a SOC 2 audit, intended for general distribution.
-
ISO 27001
International standard for an information security management system, certified by accredited bodies.
-
ISO 27701
Publicly advertised on the organization’s trust center.
-
ISO 27017
Publicly advertised on the organization’s trust center.
-
ISO 27018
Publicly advertised on the organization’s trust center.
-
PCI DSS
Payment card industry standard for handling cardholder data securely.
-
GDPR
Public claim of alignment with the EU General Data Protection Regulation.
Compliance timeline
-
September 8, 2026
Posture last observed by Trust Index
Subprocessors
Third parties Fluidattacks discloses on its trust center. Linked entries have their own profile in the Trust Index.
68% chain trust: 15 of 22 disclosed subprocessors are themselves in the Trust Index.
- Amazon Web Services Cloud provider
- Cloudflare Cloud monitoring
- Google Workspace Identity provider
- OpenAI Engineering
- Zoho IT
- Vanta Security
- Auth0 Identity provider
- Okta Identity provider
- Datadog Cloud monitoring
- dbt Labs Data analytics
- Voyage
- Snowflake Database for analytical purposes
- Zoho Desk
- GitLab Version control
- Zoho People
- Google Drive Document management
- Anthropic Engineering
- Kiflo Partner Relationship Management (PRM)
- rudol Rudol.ai is an end-to-end, AI-driven data quality and governance platform designed to help organizations discover, monitor, and trust their data.
- Kandji Endpoint Secure Management
- Refiner Customer feedback and survey platform
- Deepinfra Other
About this data
The Trust Index reports only what organizations publicly advertise. A missing framework here means no public claim was observed as of September 8, 2026; it never means an organization is non-compliant. HIPAA entries reflect a public claim of compliance; no HIPAA certification exists. Corrections are welcome and verified against public evidence. Read the full methodology.