generated: '2026-07-31' method: searched source: https://www.axtria.com/privacy-statement/ summary: | Axtria has no public machine-readable API contract, so every API-shaped standard below is recorded as not-applicable rather than not-conformant. The only standards Axtria explicitly names on its public surface are data-protection and healthcare privacy regimes, in its privacy statement. No certification report (SOC 2 Type II, ISO 27001, HITRUST) is published on the public site and no trust center exists, so no `Compliance` pointer is claimed — a customer would have to request the security package under NDA. standards: - id: gdpr conforms: true evidence: 'Privacy statement names the EU GDPR and UK GDPR / Data Protection Act 2018 as frameworks Axtria operates under; a Data Protection Officer contact is published (data_privacy@axtria.com, Berkeley Heights NJ and Gurgaon addresses).' source: https://www.axtria.com/privacy-statement/ - id: ccpa conforms: true evidence: Privacy statement enumerates California Consumer Privacy Act rights and the request channel. source: https://www.axtria.com/privacy-statement/ - id: hipaa conforms: unverified evidence: HIPAA is named in the privacy statement in the context of protected health information handling. No BAA terms, HIPAA attestation or audit report is published publicly. source: https://www.axtria.com/privacy-statement/ - id: fcra conforms: unverified evidence: Fair Credit Reporting Act is named in the privacy statement (employment screening context). source: https://www.axtria.com/privacy-statement/ - id: soc2 conforms: unverified evidence: No SOC 2 report, attestation letter or trust center published on the public site. - id: iso-27001 conforms: unverified evidence: No ISO 27001 certificate or scope statement published on the public site. - id: hitrust conforms: unverified evidence: No HITRUST CSF certification published on the public site. - id: oauth2 conforms: not-applicable evidence: No public API or authorization server; /.well-known/oauth-authorization-server 404s on every host. - id: oidc conforms: not-applicable evidence: /.well-known/openid-configuration 404s on every host. - id: openapi conforms: not-applicable evidence: No OpenAPI/Swagger document found at any probed path on any Axtria host. - id: asyncapi conforms: not-applicable evidence: No public event, streaming or webhook surface documented. - id: rfc9457-problem-details conforms: not-applicable evidence: No public API contract to evaluate error media types against. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on www.axtria.com and axtria.com. - id: a2a conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json return 404 (www/apex) or 401 (docs) on every host. - id: mcp conforms: false evidence: No hosted or remote MCP server found in Axtria docs, press releases or public MCP registries, despite the InsightsMAx.ai "Agents, Apps and APIs" framing. x-evidence: fetched: '2026-07-31' note: | `conforms: unverified` means Axtria almost certainly holds or claims the posture contractually (a vendor to 16+ of the top 20 pharma enterprises is audited), but nothing is published on the public surface this pipeline can cite. It is recorded as unverified rather than false so a later pass with a trust-center hit can upgrade it honestly.