generated: '2026-08-13' method: searched source: https://clevertap.com/security/ docs: - https://clevertap.com/security/ - https://developer.clevertap.com/docs/scim-user-provisioning-using-api - https://developer.clevertap.com/docs/api-encryption - https://developer.clevertap.com/docs/api-errors description: >- Industry and cross-cutting standards CleverTap conforms to, drawn from its own published security and compliance page and from the standards its API surface demonstrably implements. Compliance certifications are provider-published and independently audited; protocol conformance is asserted from the documented API behavior. standards: - id: soc2-type-ii conforms: true evidence: >- Published on https://clevertap.com/security/ — "CleverTap currently is compliant with GDPR, CCPA, SOC 2 Type II, ISO 27001, and HIPAA." Audit reports are offered through the Trust Portal at https://trust.clevertap.com/. - id: iso-27001 conforms: true evidence: Named on https://clevertap.com/security/ and in the Trust Portal. - id: iso-27017 conforms: true evidence: Extracted from the CleverTap Trust Portal by the security-programs probe. - id: hipaa conforms: true evidence: Named on https://clevertap.com/security/. - id: gdpr conforms: true evidence: >- Named on https://clevertap.com/security/. CleverTap additionally publishes GDPR-specific SDK guidance at https://developer.clevertap.com/docs/sdk-changes-for-gdpr-compliance and an EU-U.S. Data Privacy Framework Policy. - id: ccpa conforms: true evidence: Named on https://clevertap.com/security/. - id: eu-us-data-privacy-framework conforms: true evidence: EU-U.S. Data Privacy Framework Policy linked from the clevertap.com footer. - id: scim-2.0 conforms: true evidence: >- CleverTap publishes SCIM 2.0 user-provisioning endpoints at /nx/v2/scim/v2/Users with token authentication, plus IdP-driven and SSO-linked provisioning modes. https://developer.clevertap.com/docs/scim-user-provisioning-using-api - id: saml-2.0 conforms: true evidence: >- SAML-enabled SSO documented alongside SCIM provisioning. https://developer.clevertap.com/docs/scim-provisioning-with-sso-saml-enabled - id: hpke-rfc9180 conforms: true evidence: >- Optional Hybrid Public Key Encryption of API request and response payloads, with customer-held key pairs. https://developer.clevertap.com/docs/api-encryption - id: oauth2 conforms: true scope: mcp-server-only evidence: >- The MCP server at mcp.clevertap.com publishes RFC 8414 Authorization Server Metadata (authorization_code + refresh_token grants, PKCE S256, dynamic client registration). The REST API itself does NOT use OAuth — it uses static account-id/passcode headers. - id: rfc8414-oauth-authorization-server-metadata conforms: true scope: mcp-server-only evidence: >- https://mcp.clevertap.com/.well-known/oauth-authorization-server returns a valid RFC 8414 document (HTTP 200). - id: rfc9728-oauth-protected-resource-metadata conforms: true scope: mcp-server-only evidence: >- https://mcp.clevertap.com/.well-known/oauth-protected-resource returns a valid RFC 9728 document (HTTP 200), advertised via a WWW-Authenticate Bearer resource_metadata challenge. - id: rfc7591-dynamic-client-registration conforms: true scope: mcp-server-only evidence: registration_endpoint https://mcp.clevertap.com/oauth/register advertised in the RFC 8414 metadata. - id: mcp conforms: true evidence: >- Remote MCP server at mcp.clevertap.com returning MCP protocol headers (Mcp-Session-Id). See mcp/clevertap-mcp.yml. - id: openid-connect conforms: false evidence: >- openid/profile/email scopes are advertised by the MCP authorization server, but https://mcp.clevertap.com/.well-known/openid-configuration returns HTTP 500 — no OIDC discovery document is served. - id: rfc9457-problem-details conforms: false evidence: >- Errors are plain JSON with a status/message shape; no application/problem+json media type is documented or returned. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header support is documented; no deprecation policy exists. - id: rfc9116-security-txt conforms: false evidence: >- /.well-known/security.txt returns 404 on clevertap.com and developer.clevertap.com; the API hosts return a soft-200 with a zero-byte body, which is not a document. - id: asyncapi conforms: false evidence: >- Webhooks are documented but no AsyncAPI document is published anywhere. See asyncapi/clevertap-webhooks.yml. - id: openapi conforms: false evidence: >- CleverTap publishes no OpenAPI at any probed location. The specs in this repo were authored by API Evangelist from the public REST reference. - id: a2a conforms: false evidence: >- No agent card at /.well-known/agent-card.json or /.well-known/agent.json on any CleverTap host. - id: graphql conforms: false evidence: POST /graphql returns HTTP 405 on api.clevertap.com and us1.api.clevertap.com. - id: fhir conforms: false - id: fapi conforms: false - id: odata conforms: false - id: json-api conforms: false - id: idempotency conforms: false evidence: >- No idempotency key, request deduplication header or replay-safety contract is documented anywhere in the CleverTap API documentation. - id: cursor-pagination conforms: true evidence: >- Query endpoints return a `cursor` then a `next_cursor` per page; documented at https://developer.clevertap.com/docs/authentication. compliance_program: published: true url: https://clevertap.com/security/ trust_center: https://trust.clevertap.com/ certifications: - SOC 2 Type II - ISO 27001 - ISO 27017 - HIPAA - GDPR - CCPA - EU-U.S. Data Privacy Framework auditors: independent third-party auditors (named on the Trust Portal) detail: security/clevertap-trust-center.yml x-evidence: fetched: '2026-08-13' urls: - url: https://clevertap.com/security/ status: 200 - url: https://mcp.clevertap.com/.well-known/oauth-authorization-server status: 200 - url: https://mcp.clevertap.com/.well-known/oauth-protected-resource status: 200 - url: https://mcp.clevertap.com/.well-known/openid-configuration status: 500 - url: https://clevertap.com/.well-known/security.txt status: 404 - url: https://trust.clevertap.com/ status: 403 note: >- The Trust Portal answered 403 to an unauthenticated programmatic fetch on 2026-08-13, though it was reachable on 2026-07-11 and is linked from the public security page. Certifications above are carried from the earlier verified read plus the still-public clevertap.com/security/ page.