generated: '2026-08-13' method: derived source: >- openapi/ (24 specs, 95 operations), live probes of mcp.braze.com / dashboard.braze.com / www.braze.com, and https://www.braze.com/docs/developer_guide/disclosures/security_qualifications standards: - id: openapi-3.0 conforms: true evidence: 24 documents declare openapi 3.0.0 in openapi/ - id: openapi-operation-ids conforms: false evidence: 0 of 95 operations declare an operationId; overlays/ proposes them as an API Evangelist enhancement - id: oauth2 conforms: true evidence: MCP server authorizationCode + PKCE S256; https://dashboard.braze.com/.well-known/oauth-authorization-server (HTTP 200) scope: mcp-only - id: oidc conforms: false evidence: /.well-known/openid-configuration on dashboard.braze.com returns an HTML login page, not a discovery document - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: https://dashboard.braze.com/.well-known/oauth-authorization-server (HTTP 200, valid JSON) - id: rfc9728-oauth-protected-resource-metadata conforms: true evidence: https://mcp.braze.com/.well-known/oauth-protected-resource (HTTP 200) and the WWW-Authenticate resource_metadata challenge on 401 - id: rfc7591-dynamic-client-registration conforms: true evidence: registration_endpoint https://rest.iad-01.braze.com/oauth/register advertised in the authorization server metadata - id: mcp conforms: true evidence: first-party remote MCP server at https://mcp.braze.com/mcp (JSON-RPC 2.0, 401 challenge observed 2026-08-13) - id: a2a conforms: false evidence: no agent card at /.well-known/agent-card.json or /.well-known/agent.json on any Braze host - id: scim-2.0 conforms: true evidence: '/scim/v2/Users and /scim/v2/Users/{id} in openapi/braze-scim-api-openapi.yml; docs https://www.braze.com/docs/api/endpoints/scim/' - id: rfc9457-problem-details conforms: false evidence: errors are application/json {message, errors[]} strings with no type/code/instance — see errors/braze-problem-types.yml - id: rfc9116-security-txt conforms: true evidence: https://www.braze.com/.well-known/security.txt (HTTP 200) with Contact, Expires, Policy, Canonical, Preferred-Languages - id: rfc8594-sunset-header conforms: false evidence: no Sunset or Deprecation header documented; deprecations are announced on a docs page and in release notes only - id: rate-limit-headers conforms: partial evidence: >- Returns X-RateLimit-Limit / X-RateLimit-Remaining / X-RateLimit-Reset (the legacy X- convention), not the RFC 9331 draft RateLimit-* fields. Retry-After is not documented. - id: idempotency conforms: false evidence: no idempotency key header or parameter is documented or present in any spec - id: fhir-r4 conforms: false - id: odata conforms: false - id: json-api conforms: false - id: psd2 conforms: false - id: fapi conforms: false compliance_program: published: true url: https://www.braze.com/docs/developer_guide/disclosures/security_qualifications certifications: - {name: ISO 27001, auditor: Schellman, first_certified: '2018-12-18', renewed: '2025-08-29', expires: '2027-12-15'} - {name: SOC 2 Type 2, auditor: Schellman & Company LLC, scope: Security and Availability, period: '2024-07-01 to 2025-06-30'} - {name: TISAX, level: AL3, assessment_id: AMH9TZ-1, scope_id: SNCM4K, verification: ENX Association portal} - {name: HIPAA, note: Braze operates a dedicated HIPAA cluster compliant with the Security and Privacy rules} - {name: GDPR Article 28, note: covered within the TISAX AL3 scope} note: >- Named, dated, third-party-verifiable certifications published on Braze's own docs — this is what earns the Compliance pointer, not the derived standards list above.