Security & Governance
Security can't be a separate step.
At Fluid, it's built into every flow.
Within every flow
- OAuth2 / OIDC
- JWT
- TLS
- Rate limiting
- LGPD
- Auditing
The problem
Each system with its own access rule
Each integration was built by someone different, with their own access criteria. When it's time for an audit or an incident, there isn't a single answer: there's one per system.
With AI agents acting on these flows, the question becomes bigger: besides knowing who accessed what, you need to know what the agent decided to do, and whether someone approved it beforehand or only found out later.
How Fluid helps
At Fluid, security and governance are part of every flow from the start
Authentication and access
OAuth2 and OpenID Connect standardize how each system authenticates, with JWT tokens controlling what each access is permitted to do.
Encryption
Data is protected in transit by TLS and at rest by the infrastructure's encryption mechanisms.
Abuse protection
Dynamic rate limiting and continuous traffic monitoring identify unexpected access patterns before they become an incident.
Compliance
Flows are designed considering LGPD requirements (and GDPR, where applicable), with special attention to regulated sectors: Open Finance and BACEN standards for financial institutions.
AI agent governance
Each agent inherits the same permission and authentication structure as any other system within the flow. What it can do on its own and what requires human approval is explicitly defined, and every action is recorded in the flow's history, available for later audit.
Results
What this changes in practice
A single security standard, not one per system
Auditing and incident response are faster because the access rules are the same across all flows.
Built-in regulatory compliance, not added on later
LGPD, and for the financial sector, Open Finance and BACEN, are part of the flow's design from the start.
Auditable AI agents
Every decision and action by an agent is recorded, allowing for later reconstruction of what happened and why.
Detection before the incident
Continuous monitoring and dynamic rate limiting identify non-standard behavior before it becomes a real problem.
FAQ
Frequently asked questions
How does Fluid handle sensitive data in compliance with LGPD?
LGPD is considered in the design of flows from the very beginning, not in a later review. This includes encryption of data in transit and access control with standardized authentication.
Can an AI agent access any connected system?
No. Each agent operates within an explicitly defined scope of permissions: what it can do on its own and what requires human approval is decided by the company, not by the agent.
Is this suitable for regulated sectors, like finance?
Yes. The same security and compliance foundation extends to specific industry requirements, such as the Open Finance and BACEN standards for financial institutions.