generated: '2026-08-14' method: searched source: https://help.coefficient.io/hc/en-us/articles/17575143684123-Data-Security name: Coefficient conformance and compliance posture notes: >- Coefficient publishes no machine-readable API description, so nothing here is derived from a spec — every entry below is either an explicit first-party claim on a Coefficient-controlled page, or a recorded absence. Third-party vendor-risk aggregators list Coefficient against a much longer certification set (ISO 27001, PCI, HIPAA, FedRAMP, CSA STAR); NONE of those are claimed by Coefficient on its own surfaces and none are recorded here. SOC 2 is the only certification Coefficient asserts for itself, and even that is gated: the audit report is not published, only made available on request through support. compliance_program: published: true url: https://coefficient.io/data-security certifications: - id: soc2 name: SOC 2 claimed: true type: null type_note: >- Coefficient's own FAQ says only "Coefficient is SOC 2 Compliant" — it does not state Type I or Type II. The DPA (§6.1 Customer Audit Rights) offers "Coefficient's SOC 2 audit results" and "a recently completed industry standard security questionnaire, such as a SIG or CAIQ" on written request. report_public: false obtain_via: support@coefficient.io source: https://help.coefficient.io/hc/en-us/articles/17575143684123-Data-Security - id: gdpr name: GDPR claimed: true evidence: Publishes a Data Processing Addendum with a Security Addendum source: https://coefficient.io/data-processing-addendum standards: - id: oauth2 conforms: true evidence: >- "Both spreadsheet platforms' authentication and authorization flows are based on the industry-standard OAuth 2.0 protocol." Coefficient authenticates users via Google Workspace OAuth and Microsoft 365 SSO and stores no Coefficient- specific password. source: https://help.coefficient.io/hc/en-us/articles/17575143684123-Data-Security - id: tls-1.2-plus conforms: true evidence: >- "All API endpoints are HTTPS-only (TLS 1.2+)" for the Google Sheets add-on and the Microsoft Excel add-in. Live probe of coefficient.io negotiated TLSv1.3. source: https://help.coefficient.io/hc/en-us/articles/17575143684123-Data-Security - id: saml-sso conforms: true evidence: >- Custom SSO (e.g. Okta) is an Enterprise-tier feature; a dedicated help article documents SSO with Microsoft Entra. source: https://help.coefficient.io/hc/en-us/articles/50094543208987-SSO-with-Entra - id: openapi conforms: false evidence: No OpenAPI/Swagger document served on any Coefficient host (see x-coverage) - id: asyncapi conforms: false evidence: No AsyncAPI document; webhook surface is inbound-trigger only - id: rfc9457-problem-details conforms: false evidence: No public error contract is documented - id: rfc9116-security-txt conforms: false evidence: https://coefficient.io/.well-known/security.txt returns 404 - id: oidc-discovery conforms: false evidence: https://coefficient.io/.well-known/openid-configuration returns 404 - id: mcp conforms: false evidence: No first-party MCP server published or registered - id: a2a conforms: false evidence: No agent card at /.well-known/agent-card.json or /.well-known/agent.json x-evidence: - url: https://help.coefficient.io/api/v2/help_center/en-us/articles/17575143684123.json http_status: 200 fetched: '2026-08-14' - url: https://coefficient.io/data-security http_status: 200 fetched: '2026-08-14' - url: https://coefficient.io/data-processing-addendum http_status: 200 fetched: '2026-08-14'