Skip to main content
Request evaluation

Home

Trust Center

Last updated: August 20, 2026

FluencyRank is a production-ready B2B workplace AI fluency training and readiness platform. This Trust Center summarizes how we approach security, privacy, AI governance, and employee data use in approved company workspaces — written for IT and Legal reviewers in a buying committee.

FluencyRank is built with security, privacy and AI governance readiness in mind. We do not claim ISO, SOC, or similar certifications. What you read here matches how the product works today.

European Artificial Intelligence Office logo

EU AI governance commitment

European Union AI Pact Signatory

FluencyRank is publicly listed as a signatory to the EU AI Pact on the European Commission’s official AI Pact page — an initiative of the European Commission and the European AI Office supporting organisations in preparing for implementation of the EU AI Act. As a signatory, FluencyRank has committed to best efforts across the Pact’s three core areas: AI governance strategy, mapping of potentially high-risk AI systems, and AI literacy.

The EU AI Pact is a voluntary framework. Signatory status is not an AI Act certification, regulatory approval, third-party audit, or determination of regulatory compliance.

Cloud Security Alliance AI Trustworthy Pledge 2026 badge

External assurance

AI Trustworthy Pledge — Cloud Security Alliance

FluencyRank has signed the Cloud Security Alliance AI Trustworthy Pledge, committing to principles for secure, transparent, accountable and privacy-conscious AI.

This is a voluntary public pledge and official participant badge — not a certification, third-party audit, or determination of regulatory compliance.

Cloud Security Alliance STAR Level 1 badge

Public security transparency

Cloud Security Alliance STAR Level 1

FluencyRank has completed a CSA STAR Level 1 Security Self-Assessment and is publicly listed in the official CSA STAR Registry. Our published CAIQ v4.1 documents FluencyRank's cloud security controls against the CSA Cloud Controls Matrix.

STAR Level 1 is a self-assessment. Independent certification and third-party attestation are available at STAR Level 2.

Cloud Security Alliance STAR for AI Level 1 badge

Public AI security transparency

Cloud Security Alliance STAR for AI Level 1

FluencyRank has completed a CSA STAR for AI Level 1 AI CAIQ Self-assessment (v1.1.0) and published it on the official CSA STAR Registry. The questionnaire documents FluencyRank's responses and current AI security and governance control posture against the CSA Artificial Intelligence Controls Matrix (AICM).

STAR for AI Level 1 is a self-assessment. It is not STAR for AI Level 2, not a CSA certification, and not a third-party audit or determination of regulatory compliance.

internet.nl 100% website test badge

Modern internet standards

internet.nl Website Test — 100%

FluencyRank’s public website (www.fluencyrank.com) scores 100% on the internet.nl website test for modern internet standards, including IPv6, DNSSEC and HTTPS. The domain is listed in the internet.nl Hall of Fame for websites.

This is an automated standards test score for the public website — not a security certification, third-party audit, SOC 2/ISO claim, or AI Act compliance determination. A 100% score means the site fully meets internet.nl’s current test norm; internet.nl notes that not every mandatory internet standard is necessarily tested or weighted in the score. Scores can change; retest to verify. Badge use requires maintaining a 100% score.

Security overview

The product runs on Vercel with data and authentication on Supabase. Employees sign in with email one-time codes by default; Google Workspace SSO is supported for approved B2B workspaces, and Microsoft Entra SSO is available on request after enterprise technical review. Access is organization-scoped: members see their own progress; champions (admins) manage their organization. We use encryption in transit and provider-managed encryption at rest. Privileged server access uses least-privilege staff practices and environment-based secrets — never in the client.

Hosting analytics and product analytics are documented under Privacy. Formal certifications are not claimed. For authentication detail and tenant isolation, see Authentication and access below.

Authentication and access

Company workspaces use email one-time codes (OTP) via Supabase Auth by default. Google Workspace SSO is supported for approved B2B workspaces and is enabled per organization by the champion. Microsoft Entra SSO is available on request after enterprise technical review and also needs your Azure tenant. Sign-in is invite- and membership-gated: new accounts are not created for arbitrary emails. Sessions use secure cookies refreshed on the server. Unauthenticated visitors are redirected away from employee and admin workspaces.

Members access their own progress in the employee workspace. Champions (organization admins) manage invites, members, settings, and readiness reports for their organization only — after server-side admin checks, not client-trusted roles.

Tenant data is scoped by organization ID. Row Level Security (RLS) is enabled on tenant and personal-data tables. Sensitive organization reads and writes on the server use a service-role client only after session and membership checks. Optional email-domain allowlists can further restrict who may join.

Google Workspace SSO is supported for approved B2B workspaces (OTP remains the default). Microsoft Entra SSO and SCIM 2.0 Users provisioning are available on request after enterprise technical review. Custom data residency pickers, published VPAT, and full HRIS/Workday sync are not in the product — we do not invent roadmap dates for those.

Privacy & data protection

We process work email, profile details, organization membership, and training activity (challenge attempts, XP, readiness signals) to operate the service. Marketing updates-list and evaluation request forms collect prospect contact details. We do not sell personal data. A Data Processing Agreement (DPA) is available for B2B customers upon request and legal review.

Optional product analytics (PostHog, EU) and hosting analytics (Vercel Web Analytics / Speed Insights) load only after you accept analytics cookies. Full cookie and processor details are in the Privacy Policy.

Read the Privacy Policy

Data we process

Plain-language categories for procurement and privacy review. Details and lawful bases live in the Privacy Policy.

Typically processed in a company workspace

  • Work email and display name for accounts and invites
  • Organization membership, role path, and optional department labels
  • Challenge attempts, scores, XP, badges, and practice timestamps
  • Champion-facing engagement and readiness signals (platform engagement — not employment scores)
  • Org AI policy text you configure, plus updates-list / evaluation request contact fields
  • Optional challenge-feedback flags and notes (useful / not useful / unrealistic) for catalog quality — not HR or performance records

What we do not do today

  • Sell personal data or share it for advertising networks
  • Send employee challenge answers to a production LLM for model training
  • Offer FluencyRank scores as the sole basis for hiring, promotion, or discipline
  • Claim SOC 2, ISO, AI Act Art. 4 compliance, or certification theater

AI governance

FluencyRank trains workplace AI fluency and safe adoption habits through authored challenges and champion tools. Champions can export literacy practice evidence (who practiced, when, skill areas) as decision-support documentation — a measure of engagement, not proof of AI Act Art. 4, DOL, ISO, or other regulatory compliance. Readiness scores reflect platform engagement — not a comprehensive capability assessment or professional certification. Challenge content is reviewed through our release process. We do not currently run a production LLM on employee challenge answers; if AI feedback is added later, it will remain advisory with human oversight.

Organizations remain responsible for their AI usage policies, literacy programs, and legal review. FluencyRank practice evidence and readiness metrics do not guarantee regulatory compliance or employment outcomes.

Employee data use

FluencyRank is designed for AI fluency training and workforce readiness insights. Scores, XP, badges and reports are intended to support learning and identify training needs. They should not be used as the sole basis for employment, promotion, compensation, disciplinary, or termination decisions.

Champions may see individual engagement in their organization and can export engagement CSV that includes work email. Those exports are logged (admin, export type, row count, time). Organization admins can also review an org-scoped audit log of admin and ops actions (roles, offboard, SSO, policy, invites, billing) — metadata only, not emails or tokens, and not a SOC 2 or “audit-ready” claim. Prefer aggregate views for leadership conversations. Employers should tell employees how FluencyRank data will be used.

Subprocessors

Active vendors that help us operate the product:

VendorPurpose
VercelApplication hosting; optional Web Analytics / Speed Insights (cookie consent)
SupabaseDatabase and authentication
PostHog (EU)Optional product analytics (cookie consent)
Sentry (EU)Error monitoring
ResendTransactional and notification email

Confirm cloud region details with your FluencyRank contact when required for procurement. Optional rate limiting may use Upstash when configured.

Data retention & deletion

We retain account, organization, and training activity data to operate the service and readiness reports. Removing a member from the roster only blocks their access — it is not erasure. Ending a pilot typically pauses the workspace while practice history stays. Full erasure is a written request to FluencyRank, is not self-serve, and may be limited by provider backups. We do not publish fixed deletion SLAs without a reviewed DPA.

Privacy or deletion requests: [email protected].

Security questionnaires and reviews

For vendor security questionnaires, architecture walkthroughs, or DPA kickoff during a guided B2B evaluation, email [email protected]. We answer from how the product works today — not from marketing claims.

We will not invent SOC 2, ISO, pen-test PDFs, or SSO timelines to win a form. If a control is not shipped, we say so.

FAQ for B2B customers

Are you SOC 2 or ISO certified?
No. We document controls and readiness honestly and do not claim certifications we have not earned. FluencyRank is publicly listed as a signatory to the EU AI Pact on the European Commission’s official AI Pact page (a voluntary European Commission / European AI Office framework — not an AI Act certification or regulatory approval). FluencyRank also publishes CSA STAR Level 1 (CAIQ v4.1.0) and STAR for AI Level 1 (AI CAIQ v1.1.0) self-assessments on the official STAR Registry — those are self-assessments, not STAR Level 2 and not a CSA certification. The public website scores 100% on the internet.nl website test (modern internet standards such as IPv6, DNSSEC and HTTPS) — an automated test score, not a security certification. SOC 2 / ISO audits are available for discussion on request — not included in a standard subscription.
How do employees sign in?
Email one-time codes via Supabase Auth by default. Workspace access is invite- and membership-gated. Google Workspace SSO is supported for approved B2B workspaces and is enabled per organization. Microsoft Entra SSO is available on request after enterprise technical review (it also needs your Azure tenant).
How is customer data isolated?
By organization ID with Row Level Security on tenant tables. Admins only manage their org after server-side checks. Members see their own progress, not other organizations.
Is FluencyRank for performance management?
No. It is a training and readiness platform. Scores should not be the sole basis for employment decisions.
Do you use employee data to train public AI models?
We do not send employee challenge answers to a production LLM today. Authored challenges are scored in our application. If AI feedback is enabled later, we will document providers and keep outputs advisory.
Can we get a DPA?
Yes — available for B2B customers upon request and legal review.
What happens to employee data when someone leaves or a pilot ends?
Three different controls: an admin can soft-remove one member (access only; history stays); FluencyRank ops can suspend the whole workspace (data retained); full erasure is a written request, not an in-app button, and provider backups may still hold copies. We do not publish a fixed deletion SLA without a reviewed DPA.
Where is data hosted?
Application on Vercel; database and auth on Supabase. There is no in-product data residency picker. Confirm the current database region with your FluencyRank contact if your procurement requires a named region.
Do you offer SSO, SCIM, or a published VPAT?
Google Workspace SSO is supported for approved B2B workspaces. Microsoft Entra SSO and SCIM 2.0 Users provisioning (not full HRIS) are available on request after enterprise technical review. A published VPAT and third-party accessibility certification are not shipped — available for discussion on request. We do not publish fake “coming soon” dates.
Do you have an admin audit log?
Yes — organization admins can review an org-scoped audit log of admin and ops actions (for example roles, offboard, SSO, policy, invites, and billing). The log stores allowlisted metadata only — not emails, tokens, or payment details. Managers and members cannot see it. This is workspace accountability, not a SOC 2, ISO, or “audit-ready” certification.