generated: '2026-09-05' method: searched source: >- https://7learnings.com/security-compliance-data-protection/, https://7learnings.com/.well-known/oauth-authorization-server, https://7learnings.com/.well-known/oauth-protected-resource, https://app-static-7l.storage.googleapis.com/latest/7Learnings_initial_data_request.pdf, https://7learnings.com/changelog/ summary: >- 7Learnings publishes two audited security certifications and, in its public data-integration specification, commits to a set of ISO data-representation standards for the fields it consumes. Its only machine-readable protocol surface (the MCP endpoint) conforms to the OAuth 2.0 discovery RFCs. There is no OpenAPI, so no spec-derived conformance is asserted. conformance: - id: soc2-type-ii conforms: true evidence: https://7learnings.com/security-compliance-data-protection/ detail: >- SOC 2 Type II certified. "Confirms our commitment to security, availability, and internal governance over time." Report access is via the Vanta trust center. - id: iso-27001-2022 conforms: true evidence: https://7learnings.com/security-compliance-data-protection/ detail: >- ISO/IEC 27001:2022 certified; certification body named on the page as Prescient Security. - id: gdpr conforms: true evidence: https://7learnings.com/security-compliance-data-protection/ detail: >- "We process all personal data in accordance with the General Data Protection Regulation (GDPR)." Data minimization stated; EU (German) establishment, Berlin HQ, VAT DE323363789. Trust center is hosted on Vanta's EU instance (app.eu.vanta.com). - id: oauth2-rfc6749 conforms: true evidence: https://7learnings.com/.well-known/oauth-authorization-server detail: >- Authorization code grant with refresh tokens; authorization, token and revocation endpoints published. - id: oauth2-authorization-server-metadata-rfc8414 conforms: true evidence: https://7learnings.com/.well-known/oauth-authorization-server detail: 200, application/json, carries issuer/authorization_endpoint/token_endpoint/scopes_supported. - id: oauth2-protected-resource-metadata-rfc9728 conforms: true evidence: https://7learnings.com/.well-known/oauth-protected-resource detail: >- 200, application/json, declares resource, authorization_servers[], bearer_methods_supported and scopes_supported - the RFC 9728 shape MCP clients read to discover the auth server. - id: oauth2-pkce-rfc7636 conforms: true evidence: https://7learnings.com/.well-known/oauth-authorization-server detail: code_challenge_methods_supported = ["S256"]. - id: oauth2-token-revocation-rfc7009 conforms: true evidence: https://7learnings.com/.well-known/oauth-authorization-server detail: revocation_endpoint = https://7learnings.com/oauth/revoke. - id: model-context-protocol conforms: true evidence: https://7learnings.com/.well-known/oauth-protected-resource detail: >- A JSON-RPC MCP endpoint is served and responds to POST with an MCP-shaped 401 (mcp_unauthorized). Protocol version could not be read - tools/list is auth-gated. - id: rfc7591-dynamic-client-registration conforms: false evidence: https://7learnings.com/.well-known/oauth-authorization-server detail: >- No registration_endpoint is advertised. The server instead sets client_id_metadata_document_supported = true. - id: openid-connect conforms: false evidence: https://7learnings.com/.well-known/openid-configuration detail: 404. The MCP authorization server is plain OAuth 2.0, not OIDC. domain_standards: note: >- Predictive pricing / retail optimization has no single dominant wire standard, and 7Learnings declares none (no GS1, no EDI/EDIFACT, no OpenRTB). What its published data contract DOES declare are the identifier and representation standards below - each is named explicitly in the Initial Data Request specification or the changelog, with the exact field or entry cited. Nothing was inferred. standards: - id: iso-3166 conforms: true evidence: https://app-static-7l.storage.googleapis.com/latest/7Learnings_initial_data_request.pdf detail: >- Section 3.1 Channels - the `market` and `upload_market` columns are specified as "Country where the product was sold using ISO 3166 format (e.g. DE for Germany)". - id: iso-4217 conforms: true evidence: https://app-static-7l.storage.googleapis.com/latest/7Learnings_initial_data_request.pdf detail: >- Section 3.1 Channels - `channel_currency` and `upload_currency` are specified as "Three letter code for local channel specific currency according to ISO 4217". - id: iso-8601 conforms: true evidence: https://app-static-7l.storage.googleapis.com/latest/7Learnings_initial_data_request.pdf detail: >- Section 3.3 Transactions - `time` is specified as "an ISO 8601 UTC timestamp (e.g. 2024-02-06 22:54:51+00:00)". - id: rfc4180 conforms: true evidence: https://7learnings.com/changelog/ detail: >- Changelog 2026-08-11, "Major CSV Engine Migration": output format changed to RFC 4180 compliant quoting, UTC timestamps and lowercase booleans. CSV is one of the two file formats (with Parquet) used across every file-based input and output transport. - id: apache-parquet conforms: true evidence: https://app-static-7l.storage.googleapis.com/latest/7Learnings_initial_data_request.pdf detail: >- Tables 1 and 16 - Parquet is an accepted format on every object-store and file transport (GCS, S3, Azure Blob, SFTP, FTPS, HTTPS) for both input and output.