generated: '2026-08-12' method: searched source: https://compliance.salesforce.com/en/services/marketing-cloud-intelligence docs: - https://compliance.salesforce.com/en/services/marketing-cloud-intelligence - https://security.salesforce.com/responsible-disclosure-policy/ - https://developers.datorama.com/docs/manage/introduction/ note: >- Two different things are recorded here and they should not be confused. (1) TECHNICAL standards conformance for the Intelligence Platform/Query APIs, which is thin — there is no OpenAPI, no OAuth on the data APIs, no problem+json. (2) AUDIT/COMPLIANCE certifications, which are strong, published by Salesforce, and explicitly scoped to "MC Intelligence (fka Datorama)" by name on the Salesforce compliance site. standards: - id: openapi conforms: false evidence: >- No OpenAPI/Swagger served on developers.datorama.com, api.datorama.com or platform.datorama.com. /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /swagger/v1/swagger.json all probed 2026-08-12 — 404 on the docs host, HTML SPA catch-all (soft 200) on the API hosts. - id: graphql conforms: false evidence: No /graphql surface documented or discoverable. - id: asyncapi conforms: false evidence: >- No AsyncAPI document. An event surface does exist in the Apps JS SDK (DA.websocket.subscribe / subscribeWithPayload, added in SDK 0.21.0) but no channel catalog or message schema is published, and no webhook catalog exists. - id: mcp conforms: true evidence: >- First-party MCP server @datorama/mci-mcp-sdk 0.1.1 published 2026-07-21, depending on @modelcontextprotocol/sdk and proxying MCP JSON-RPC (initialize, tools/list, tools/call) to a tenant /api/mcp endpoint. - id: oauth2 conforms: partial evidence: >- The Platform and Query APIs use a static personal API token in an `Authorization` header, not OAuth2. OAuth2 appears only in the MCP path, where the mci-mcp-sdk mints a bearer from a service-account private key against an IdP discovered from the key file. - id: oidc conforms: false evidence: No /.well-known/openid-configuration served on any host (probed 2026-08-12). - id: rfc9457-problem-details conforms: false evidence: >- No application/problem+json. The Query API returns some runtime errors inside an HTTP 200 with a non-empty `errors` property. - id: rfc9116-security-txt conforms: false evidence: No /.well-known/security.txt on any Datorama host, nor on www.salesforce.com. - id: rfc8594-sunset-header conforms: false evidence: >- No Sunset or Deprecation header support documented. A dated sunset WAS executed for the old Query API (2019-05-28) via a migration guide, but through documentation, not headers. - id: rfc7807-idempotency conforms: false evidence: No idempotency key or request-replay contract documented. - id: jwt conforms: true evidence: >- POST /v1/signatures issues a signed JWT for Marketplace apps; POST /v1/signatures/verify validates it and returns {globalId, appInstanceId, env, userId}. Bearer transport is the documented preference. - id: rest conforms: true evidence: >- "The Intelligence Platform API enables you to setup, manage and administer your account by using standard REST API requests." Resource-per-entity paths under /v1, GET/POST/PUT/PATCH/DELETE, PATCH preferred for partial updates. - id: a2a conforms: false evidence: No agent card at /.well-known/agent-card.json or /.well-known/agent.json on any host. - id: llms-txt conforms: false evidence: https://developers.datorama.com/llms.txt -> 404 (probed 2026-08-12). compliance: published: true scope_name: Marketing Cloud - Intelligence url: https://compliance.salesforce.com/en/services/marketing-cloud-intelligence probed: '2026-08-12' http_status: 200 documents_total: 55 datorama_named_documents: - SOC 2 Report - MC Intelligence (fka Datorama) - SOC 3 Report - MC Intelligence (fka Datorama) - DR Summary - MC Intelligence (fka Datorama) - Vulnerability/Penetration Report Summary - MC Intelligence (fka Datorama) certifications_evidenced: - {name: SOC 2, updated: '2026-06-16', infrastructure: [AWS, Azure]} - {name: SOC 3, updated: '2026-06-16', infrastructure: [AWS, Azure]} - {name: 'SOC 2 (Marketing Cloud bundle: MCE, Intelligence, Advertising, MC Einstein, Personalization, MC Next)', updated: '2026-06-16', infrastructure: [AWS, Hyperforce]} - {name: C5 (ISAE 3000) - Marketing Cloud, updated: '2026-06-28', infrastructure: [First party, AWS, Hyperforce]} - {name: UK Cyber Essentials, updated: '2026-06-22'} - {name: UK Cyber Essentials Plus, updated: '2026-06-22'} - {name: Spain ENS High, updated: '2026-06-09'} - {name: Salesforce EU Processor Binding Corporate Rules, updated: '2026-05-06'} - {name: Salesforce Enterprise Resilience/BCP Summary, updated: '2026-07-23'} evidence_note: >- The ten rows above are the first page of 55 documents listed under the Marketing Cloud - Intelligence service; the remaining pages are client-side paginated and were not enumerated. Only certifications actually shown on this service's document list are recorded — the site-wide category index also names ISO 27001/27017/27018, HIPAA, FedRAMP, PCI DSS and others, but those are the catalog's global taxonomy and are NOT asserted for this service here. service_specific_reference_verbatim: >- "Please refer to the 'Audits and Certifications' section of the service-specific Security, Privacy and Architecture documentation for details regarding the security and privacy related audits and certifications received."