generated: '2026-08-13' method: searched source: https://help.animoto.com/hc/en-us/articles/360004421634-General-Data-Protection-Regulation-GDPR-and-Animoto note: >- There is no OpenAPI, AsyncAPI, GraphQL SDL or vocabulary in this repo to derive technical conformance from, and Animoto publishes no API reference. Everything asserted below was read from Animoto's own published pages on 2026-08-13. Animoto names GDPR explicitly and describes a data-protection program, but publishes NO named third-party certification — no SOC 2, no ISO 27001, no PCI DSS, no HIPAA, no FedRAMP is claimed anywhere on its site or help center, and no trust center exists. Absence of those is recorded as `conforms: false` rather than omitted. standards: - id: gdpr conforms: true evidence: >- Animoto publishes a dedicated GDPR page describing its compliance work — updates to Terms and Privacy Policy, records of data-collection processes, vendor/partner GDPR review, and an internal team for privacy requests including deletion. url: https://help.animoto.com/hc/en-us/articles/360004421634-General-Data-Protection-Regulation-GDPR-and-Animoto - id: data-encryption-at-rest-and-in-transit conforms: true evidence: >- "We encrypt data in transit and at rest using keys managed by AWS, and maintain internal security best-practices." Animoto also names JAMF, AWS and DataGrail as the vendors used for safeguarding and processing user and employee data. url: https://help.animoto.com/hc/en-us/articles/30294070375827-How-Animoto-Protects-Your-Data-Privacy - id: data-subject-access-and-deletion conforms: true evidence: >- Published data deletion request form and privacy request route; Animoto states users may request access, rectification and deletion at any time. url: https://help.animoto.com/hc/en-us/articles/30084701038867-Animoto-Data-Deletion-Request-Form - id: breach-notification conforms: true evidence: >- Animoto published a standing breach-notification page for the July 2018 unauthorized-access incident, describing what happened, what data was involved, and remediation. Still maintained (last updated 2025-10-12). url: https://help.animoto.com/hc/en-us/articles/360008114514-Important-Security-Announcement - id: soc2 conforms: false evidence: No SOC 2 report or attestation referenced on any Animoto property. - id: iso27001 conforms: false evidence: No ISO/IEC 27001 certification referenced on any Animoto property. - id: pci-dss conforms: false evidence: >- Not claimed. Animoto states complete payment card data is stored in a separate system, but publishes no PCI DSS attestation. - id: hipaa conforms: false evidence: Not applicable and not claimed — consumer/SMB video creation product. - id: fedramp conforms: false evidence: Not claimed. - id: oauth2 conforms: false evidence: >- Live probe of api.animoto.com returns `WWW-Authenticate: Basic realm="Application"` on every path. No OAuth 2.0 authorization server, no /.well-known/oauth-authorization-server, no /.well-known/openid-configuration. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on animoto.com and 401 on api.animoto.com. - id: rfc9457-problem-details conforms: unknown evidence: >- Cannot be established — error bodies are behind HTTP Basic and no error reference is published. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on animoto.com (see well-known/animoto-well-known.yml).