generated: '2026-08-27' method: searched source: https://www.aftership.com/security + https://accounts.aftership.com/auth/realms/business/.well-known/openid-configuration + the ten harvested OpenAPI documents standards: - id: openapi conforms: true version: 3.1.0 evidence: 'All ten harvested specs declare openapi: 3.1.0 and are downloadable from the provider docs via the Stoplight export URL each spec names in info.description.' - id: oauth2 conforms: true evidence: OAuth 2.0 authorization-code flow for Partner Dashboard public apps, documented at /docs/tracking/quickstart/authentication/oauth/overview; live authorization server at https://accounts.aftership.com/auth/realms/business advertises authorization_code, client_credentials, refresh_token, device_code and token-exchange grants. - id: oidc conforms: true evidence: OpenID Connect Discovery 1.0 document served at https://accounts.aftership.com/auth/realms/business/.well-known/openid-configuration (HTTP 200), issuer https://accounts.aftership.com/auth/realms/business. - id: pkce conforms: true evidence: 'code_challenge_methods_supported: ["plain","S256"] in the OIDC discovery document.' - id: rfc9728 conforms: true evidence: OAuth 2.0 Protected Resource Metadata served at https://mcp.aftership.com/.well-known/oauth-protected-resource (HTTP 200), naming the AfterShip business realm as authorization server. - id: mcp conforms: true version: '2025-03-26' evidence: AfterShip publishes a Streamable HTTP MCP server at https://mcp.aftership.com/tracking/public and states MCP spec 2025-03-26 in its own README. - id: rfc9457 conforms: false evidence: No application/problem+json media type appears in any harvested spec; AfterShip uses a proprietary meta/data envelope (see errors/aftership-problem-types.yml). - id: idempotency conforms: false evidence: No Idempotency-Key header, idempotency parameter or idempotency documentation was found in the ten harvested specs or the quickstart docs. - id: pagination conforms: true evidence: Cursor and page/limit pagination objects appear in the harvested specs (e.g. CourierConnectionResponseForGetCourierConnectionsDataPagination in the Tracking spec). - id: scim conforms: false evidence: No SCIM schema URN appears in any spec; the Members API is a proprietary membership/role surface. - id: odata conforms: false evidence: No $metadata surface or OData annotations found. - id: fhir conforms: false evidence: Not applicable — AfterShip is an ecommerce logistics provider, not healthcare. - id: saml conforms: true evidence: SAML / OIDC SSO with customer IdPs (Okta, Azure AD) is listed as an Enterprise plan entitlement on the pricing page, and SSO is named in the Trust Centre product-security highlights. domain_standards: market: Ecommerce post-purchase / multi-carrier shipping searched: - EDIFACT - X12 - GS1 EPCIS - UPU S10 - ISO 20022 - OAGIS - schema.org ParcelDelivery - OpenTravel found: [] note: 'No domain standard is declared by any AfterShip contract. The market itself is carrier-federated rather than standardised: AfterShip normalises 1,400+ proprietary carrier formats behind a proprietary "slug" vocabulary (openapi/aftership-tracking-api-openapi.yml, Slug Groups enum) and a proprietary delivery-status and sub-status enum (Delivered_005, Exception_016, InTransit_011, ...). This is a reward-only check with no penalty: the enum IS the de-facto interchange vocabulary a large part of the ecommerce tracking market integrates against, but it is AfterShip''s, not a standards body''s.' compliance: certifications: - SOC 2 Type II - ISO 27001 regulations: - GDPR frameworks: - CIS Benchmarks - OWASP Top 10 practices: - annual third-party penetration testing - automated production vulnerability scanning - HackerOne bug bounty programme - 24/7 security monitoring and incident response - security awareness training documents: terms_of_service: https://www.aftership.com/legal/terms-of-service privacy_policy: https://www.aftership.com/legal/privacy dpa: https://www.aftership.com/legal/dpa subprocessors: https://www.aftership.com/legal/subprocessors sla: https://www.aftership.com/enterprise-sla hosting: Google Cloud Platform and Amazon Web Services, United States. Cloudflare WAF in front of production. source: https://www.aftership.com/security