generated: '2026-08-12' method: searched source: >- https://covatic.com/dpa/ + https://covatic.com/about/ + https://covatic.com/privacy-policy/ + openapi/covatic-audience-builder-openapi.yml summary: >- Covatic's published compliance posture is regulatory and ethical, not technical. It names GDPR, UK GDPR/DPA 2018, ePrivacy and CCPA/CPRA in its Data Processing Agreement, is a Certified B Corporation and an IAB Tech Lab member. It publishes NO security attestation (no SOC 2, no ISO 27001, no penetration-test summary, no trust centre) and its API conforms to almost none of the cross-cutting HTTP/API standards an agent would look for. standards: - id: gdpr name: EU General Data Protection Regulation (2016/679) conforms: true evidence: >- Named as the governing regulation of the Data Processing Agreement published at https://covatic.com/dpa/, with Covatic acting as processor and a sub-processor list (AWS EMEA SARL Luxembourg, MongoDB Limited Ireland). source: https://covatic.com/dpa/ - id: uk-gdpr name: UK GDPR / Data Protection Act 2018 conforms: true evidence: Named in the DPA alongside EU GDPR; Covatic is a UK company. source: https://covatic.com/dpa/ - id: eprivacy name: Directive on Privacy and Electronic Communications (2002/58/EC) conforms: true evidence: Named in the DPA. source: https://covatic.com/dpa/ - id: ccpa-cpra name: California Consumer Privacy Act 2018 / California Privacy Rights Act 2020 conforms: true evidence: Named in the DPA. source: https://covatic.com/dpa/ - id: b-corp name: Certified B Corporation conforms: true evidence: >- "Certified B Corporation" on the About page, with a published B Corp impact report. An ethical/social certification, not a security or data-protection attestation. source: https://covatic.com/about/ - id: iab-tech-lab name: IAB Tech Lab membership conforms: partial evidence: >- Listed as an IAB Tech Lab member on the About page. Membership is not conformance — Covatic does not publish support for any specific IAB Tech Lab specification (no TCF string handling, no seller.json/ads.txt, no OpenRTB profile, no Data Transparency Standard label) in anything machine-readable. source: https://covatic.com/about/ - id: soc2 name: SOC 2 conforms: false evidence: No SOC 2 report, attestation or trust centre found on any Covatic surface. - id: iso27001 name: ISO/IEC 27001 conforms: false evidence: >- Not claimed anywhere. The DPA lists Article 32 security measures in prose (pseudonymisation, encryption, event logging, IT security governance) but names no certified ISMS. - id: oauth2 name: OAuth 2.0 conforms: partial evidence: >- The identity layer is AWS Cognito, whose OIDC discovery document advertises authorization/token/revocation endpoints and the code + token response types. But the API itself declares only a bare `http bearer` securityScheme with no oauth2 flows and no scopes, and returns 401 with no WWW-Authenticate header. source: well-known/covatic-openid-configuration.json - id: oidc name: OpenID Connect conforms: true evidence: >- Live OIDC discovery document at https://cognito-idp.eu-west-2.amazonaws.com/eu-west-2_mQWqhJueg/.well-known/openid-configuration (HTTP 200), issuer, jwks_uri, RS256, scopes openid/email/phone/profile. Served by AWS for Covatic's tenant, not by a Covatic host. source: well-known/covatic-openid-configuration.json - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: >- Errors use FastAPI's `{"detail": ...}` envelope with `application/json`, not `application/problem+json`. See errors/covatic-problem-types.yml. - id: rfc9116 name: RFC 9116 security.txt conforms: false evidence: /.well-known/security.txt returns 404 on covatic.com and on the API host. - id: rfc9727 name: RFC 9727 API Catalog conforms: false evidence: /.well-known/api-catalog returns 404 on every Covatic host. - id: rfc8594 name: RFC 8594 Sunset header / deprecation signalling conforms: false evidence: No Sunset or Deprecation header observed; no deprecation policy published. - id: idempotency name: Idempotency keys on unsafe methods conforms: false evidence: >- No Idempotency-Key parameter on any of the 28 POST operations. See conventions/covatic-conventions.yml. - id: pagination name: Consistent pagination conforms: partial evidence: >- fastapi-pagination page/size with a Page_ envelope (items/total/page/size/pages) on 13 of 71 paths; the remaining collection reads are unpaginated. - id: openapi name: OpenAPI 3.1.0 conforms: true evidence: >- A valid, complete OpenAPI 3.1.0 document is served publicly and unauthenticated at https://prodaudiencebuilderapi.covatic.io/openapi.json — 71 paths, 89 operations, 78 component schemas, every operation summarised and tagged, unique operationIds. Swagger UI at /docs and ReDoc at /redoc are also public. source: openapi/covatic-audience-builder-openapi.yml - id: asyncapi name: AsyncAPI conforms: false evidence: No event, streaming or webhook surface found. Not applicable. - id: mcp name: Model Context Protocol conforms: false evidence: >- No MCP server. Covatic does ship an in-product conversational agent (/api/v1/ai_audience_agent/chat) but exposes it as a REST operation, not as MCP tools. - id: a2a name: A2A Agent Card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json 404 on covatic.com and the API host, and return the SPA HTML shell (not an AgentCard) on platform.covatic.io. data_residency: claim: Client data is stored in EU, AU or US regions, in line with client requirements. source: https://covatic.com/technical/ corroboration: >- The Client schema in the OpenAPI carries country, bucket_name and cluster_reference fields, which is consistent with per-tenant regional storage. sub_processors: - Amazon Web Services EMEA SARL, Luxembourg - MongoDB Limited, Ireland transfer_basis: UK, the EEA, Switzerland, or another "adequate" location source_dpa: https://covatic.com/dpa/ gaps_for_the_provider: - Publish a trust centre or a security attestation; a privacy-first adtech company with no SOC 2 / ISO 27001 and no security.txt is asking buyers to take Article 32 on faith. - Name the IAB Tech Lab specifications actually implemented, rather than membership alone.