generated: '2026-08-01' method: searched source: DataVisor public site (footer certification badges, integration guides, privacy policy) note: >- DataVisor publishes no OpenAPI, so nothing here is derived from a spec. Every entry below is either an explicit public claim by DataVisor or a recorded absence. Marketing content about regulations (NACHA, PSD2, Regulation E, SR 11-7, OSFI) is DataVisor writing about its customers' obligations, not a conformance claim about its own API, and is excluded. standards: - id: rest-https conforms: true evidence: >- "The default integration mechanism for all APIs supports real-time, synchronous HTTPS-based RESTful calls (secured with TLS v1.2)." source: https://www.datavisor.com/datavisor-api-guide - id: tls-1.2-minimum conforms: true evidence: Stated minimum transport for all DataVisor API calls. source: https://www.datavisor.com/datavisor-api-guide - id: soc2-type-ii conforms: true evidence: >- AICPA SOC 2 Type II certification badge published site-wide in the DataVisor footer (asset aicpa-soc-2-type-ii-certified2471.svg). source: https://www.datavisor.com/ caveat: >- Badge only. DataVisor publishes no trust center, no report request flow and no audit period, so the attestation itself was not verifiable from public sources. - id: ccpa conforms: true evidence: CCPA compliance badge published site-wide in the DataVisor footer, alongside a published privacy policy. source: https://www.datavisor.com/privacy-policy - id: gdpr conforms: claimed evidence: >- "DataVisor's solution enables full compliance with GDPR. We support deploying DataVisor's detection systems in data centers located in Europe, so that your European users' data will only be processed within Europe." source: https://www.datavisor.com/integrations/datavisor-integration-guide-for-comprehensive-fraud-solution caveat: >- Self-asserted in an FAQ; no DPA, sub-processor list or Art. 28 documentation is published publicly. - id: iso-27001 conforms: false evidence: No ISO 27001 certification claim or badge found anywhere on the public site. - id: pci-dss conforms: false evidence: No PCI DSS claim found on the public site. - id: hipaa conforms: false evidence: No HIPAA claim found on the public site. - id: fedramp conforms: false evidence: No FedRAMP claim or marketplace listing found. - id: oauth2 conforms: false evidence: No OAuth 2.0 surface documented publicly; authentication is access-key based. - id: openid-connect conforms: false evidence: /.well-known/openid-configuration returns 404 on every reachable host. - id: rfc9457-problem-details conforms: false evidence: No error format published publicly. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on www.datavisor.com and the support portal. - id: rfc8594-sunset-header conforms: false evidence: No deprecation or sunset policy published. - id: openapi conforms: false evidence: >- No OpenAPI/Swagger document found on any DataVisor host after a full contract-discovery sweep; see well-known/datavisor-well-known.yml x-contract-discovery. - id: asyncapi conforms: false evidence: No AsyncAPI document and no public webhook/event catalog. - id: a2a-agent-card conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json return 404 (www) / 403 (WAF). - id: mcp conforms: false evidence: No hosted Model Context Protocol server found for DataVisor's AI agent products. certifications: - name: SOC 2 Type II issuer: AICPA published_on: https://www.datavisor.com/ form: footer badge - name: CCPA published_on: https://www.datavisor.com/privacy-policy form: footer badge