generated: '2026-08-12' method: searched source: >- https://www.viantinc.com/company/security/ (compliance claims) plus live probes of https://api.adelphic.com/ (auth scheme observation). No OpenAPI, AsyncAPI, GraphQL SDL or MCP manifest exists to derive standards from. standards: - id: http-basic-rfc7617 conforms: true evidence: >- api.adelphic.com and api.viantinc.com both answer 401 with `WWW-Authenticate: Basic realm="Adelphic"` (RFC 7617 Basic scheme). - id: soc2-ssae18 conforms: true evidence: >- Viant publishes a SOC 2 Type I assessment performed under AICPA SSAE 18; report access is via https://trust.viantinc.com/. - id: oauth2 conforms: false evidence: >- No oauth2 scheme observed; the only advertised challenge is HTTP Basic. /.well-known/oauth-authorization-server returns 404/401 on all hosts. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404/401 on all hosts. - id: openapi conforms: false evidence: >- No OpenAPI/Swagger document found. /openapi.json, /swagger.json, /v1/openapi.json, /api-docs, /docs and /redoc all return 401 on api.adelphic.com and 404 on www.adelphic.com. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface is publicly documented. - id: rfc9457-problem-details conforms: false evidence: No spec or public error reference to evaluate. - id: rfc9116-security-txt conforms: false evidence: >- /.well-known/security.txt returns 404 on adelphic.com and viantinc.com; the disclosure policy is an HTML page instead. - id: rfc8594-sunset-header conforms: false evidence: No deprecation/sunset policy is published. - id: a2a-agent-card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json return 404 on every Adelphic/Viant host except the dsp.viantinc.com SPA catch-all, whose 200 is an HTML shell and was rejected. compliance_program: published: true url: https://www.viantinc.com/company/security/ trust_center: https://trust.viantinc.com/ certifications: - SOC 2 Type I