generated: '2026-08-13' method: searched source: https://www.adverity.com/analytics-platform/data-security standards: - id: iso-27001 conforms: true evidence: ISO/IEC 27001 certified, audited yearly by TUV Austria (data-security page). - id: soc2-type2 conforms: true evidence: SOC 2 Type 2 audited company (data-security page). - id: gdpr conforms: true evidence: Full GDPR and UK GDPR compliance; EU/US data residency options. - id: ccpa conforms: true evidence: Honors CCPA privacy rights for California residents. - id: hipaa conforms: true evidence: HIPAA compliant; Business Associate Agreement (BAA) available for PHI. - id: dora conforms: true evidence: Digital Operational Resilience Act (DORA) referenced on data-security page. - id: oauth2 conforms: true evidence: >- Two independent uses. (1) The remote MCP server at mcp.eu.adverity.com runs an OAuth 2.0 authorization-code flow with refresh tokens, verified from its own published metadata. (2) OAuth is used downstream when Adverity authorizes to connected data sources (Google Ads, Facebook Ads, LinkedIn Ads). The Management API itself is API-key only. - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: >- https://mcp.eu.adverity.com/.well-known/oauth-authorization-server returns 200 with a valid RFC 8414 document (probed 2026-08-13); saved verbatim to well-known/adverity-oauth-authorization-server.json. - id: rfc9728-oauth-protected-resource-metadata conforms: true evidence: >- https://mcp.eu.adverity.com/.well-known/oauth-protected-resource/mcp returns 200 with a valid protected-resource document, and the MCP endpoint's 401 response advertises it in the WWW-Authenticate header — the RFC 9728 discovery path done correctly. - id: rfc7591-dynamic-client-registration conforms: true evidence: registration_endpoint https://mcp.eu.adverity.com/register declared in the authorization-server metadata. - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported ["S256"] in the authorization-server metadata. - id: mcp conforms: true evidence: >- Hosted remote MCP server at https://mcp.eu.adverity.com/mcp (beta), documented for Claude and ChatGPT custom connectors; a JSON-RPC tools/list POST returned a well-formed OAuth 401 challenge rather than an error page. 12 tools published in the docs. - id: oidc conforms: false evidence: No /.well-known/openid-configuration on any Adverity host (404 on www, docs and mcp.eu). - id: rfc9457-problem-details conforms: false evidence: >- Errors use a custom { detail, errors } envelope on the legacy surface, not application/problem+json. v1/v2 and 5xx responses are excluded from even that envelope. - id: rfc9116-security-txt conforms: false evidence: No /.well-known/security.txt on www or docs (404, probed 2026-08-13). - id: rfc8594-sunset-header conforms: false evidence: >- No deprecation policy and no Sunset/Deprecation headers; release 2026.33 removed two endpoints "without deprecation" by Adverity's own description. - id: openapi conforms: false evidence: >- No OpenAPI/Swagger document published. Probed /openapi.json, /openapi.yaml, /swagger.json on www.adverity.com and docs.adverity.com — all 404/HTML shell. The contract is a hand-written endpoint table plus a public Postman collection. - id: asyncapi conforms: false evidence: >- No AsyncAPI document, though a real webhook surface with three events exists; see asyncapi/adverity-webhooks.yml. - id: a2a conforms: false evidence: No agent card at /.well-known/agent-card.json or /.well-known/agent.json on www, docs or mcp.eu (404, probed 2026-08-13). compliance: published: true certifications: [ISO/IEC 27001, SOC 2 Type 2, GDPR, UK GDPR, CCPA, HIPAA, DORA] auditor: TUV Austria (ISO 27001) page: https://www.adverity.com/analytics-platform/data-security data_residency: [EU, US]