Security & Governance

Security can't be a separate step.

At Fluid, it's built into every flow.

Within every flow

  • OAuth2 / OIDC
  • JWT
  • TLS
  • Rate limiting
  • LGPD
  • Auditing

The problem

Each system with its own access rule

Each integration was built by someone different, with their own access criteria. When it's time for an audit or an incident, there isn't a single answer: there's one per system.

With AI agents acting on these flows, the question becomes bigger: besides knowing who accessed what, you need to know what the agent decided to do, and whether someone approved it beforehand or only found out later.

How Fluid helps

At Fluid, security and governance are part of every flow from the start

  • Authentication and access

    OAuth2 and OpenID Connect standardize how each system authenticates, with JWT tokens controlling what each access is permitted to do.

  • Encryption

    Data is protected in transit by TLS and at rest by the infrastructure's encryption mechanisms.

  • Abuse protection

    Dynamic rate limiting and continuous traffic monitoring identify unexpected access patterns before they become an incident.

  • Compliance

    Flows are designed considering LGPD requirements (and GDPR, where applicable), with special attention to regulated sectors: Open Finance and BACEN standards for financial institutions.

  • AI agent governance

    Each agent inherits the same permission and authentication structure as any other system within the flow. What it can do on its own and what requires human approval is explicitly defined, and every action is recorded in the flow's history, available for later audit.

    See AI Agents →

Understand how Fluid orchestrates →

Results

What this changes in practice

  • A single security standard, not one per system

    Auditing and incident response are faster because the access rules are the same across all flows.

  • Built-in regulatory compliance, not added on later

    LGPD, and for the financial sector, Open Finance and BACEN, are part of the flow's design from the start.

  • Auditable AI agents

    Every decision and action by an agent is recorded, allowing for later reconstruction of what happened and why.

  • Detection before the incident

    Continuous monitoring and dynamic rate limiting identify non-standard behavior before it becomes a real problem.

FAQ

Frequently asked questions

How does Fluid handle sensitive data in compliance with LGPD?

LGPD is considered in the design of flows from the very beginning, not in a later review. This includes encryption of data in transit and access control with standardized authentication.

Can an AI agent access any connected system?

No. Each agent operates within an explicitly defined scope of permissions: what it can do on its own and what requires human approval is decided by the company, not by the agent.

Is this suitable for regulated sectors, like finance?

Yes. The same security and compliance foundation extends to specific industry requirements, such as the Open Finance and BACEN standards for financial institutions.

Does your audit still need to check system by system to know who has access to what? With Fluid, that answer is in one place.