generated: '2026-08-13' method: searched source: https://www.emotive.io/security docs: - https://www.emotive.io/security - https://help.emotive.io/docs/compliance/tcpa-compliance - https://help.emotive.io/docs/compliance/ccpa-privacy-policy - https://www.emotive.io/compliance derived_from: - openapi/emotive-open-api-openapi.yml - openapi/emotive-auth-openapi.yml - openapi/emotive-helpdesk-openapi.yml - conventions/emotive-conventions.yml - errors/emotive-problem-types.yml summary: >- Emotive's compliance posture is regulatory, not technical. It runs a documented SMS compliance program against TCPA, CCPA and CTIA — the regime that actually governs its product — and ships a product feature (the Emotive Litigator Filter) built on it. It conforms to almost none of the cross-cutting API standards: no RFC 9457, no idempotency, no rate-limit signaling, no OpenID Connect, no declared OAuth 2.0 security scheme, no RFC 9727 API catalog. Its security page names ISO 27001, SOC 1/SSAE 16, PCI Level 1, FISMA and SOX — but every one of those accreditations belongs to Amazon Web Services (its hosting provider) or Stripe (its payment processor), not to Emotive. Emotive names no certification of its own. standards: - id: tcpa name: Telephone Consumer Protection Act conforms: true evidence: >- Emotive publishes a TCPA compliance program with a checklist, prior-express-written-consent requirements, mandatory opt-out handling, and a required TCPA-compliant follow-up message on every SMS opt-in enforced by the Lists API integration flow. url: https://help.emotive.io/docs/compliance/tcpa-compliance - id: ccpa name: California Consumer Privacy Act conforms: true evidence: Published CCPA privacy policy overview describing Emotive's role as a service provider processing customer-controlled personal data. url: https://help.emotive.io/docs/compliance/ccpa-privacy-policy - id: ctia name: CTIA Messaging Principles and Short Code Monitoring Handbook conforms: true evidence: Emotive's compliance documentation requires familiarity with and adherence to the current CTIA Short Code Monitoring Handbook and Messaging Principles and Best Practices Guide. url: https://help.emotive.io/docs/compliance/tcpa-compliance - id: 10dlc name: 10DLC registered long-code messaging conforms: true evidence: Emotive documents 10DLC as its long-code messaging upgrade in the SMS fundamentals section of the knowledge base. url: https://help.emotive.io/llms.txt - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: No operation in any of the seven published OpenAPI documents declares application/problem+json. Four different ad-hoc error envelopes are in use. See errors/emotive-problem-types.yml. - id: idempotency name: Idempotency keys for unsafe requests conforms: false evidence: No idempotency header, no retry semantics and no dedup guidance is published, despite every public operation being a state-creating POST. See conventions/emotive-conventions.yml. - id: rate-limit-headers name: RateLimit header fields for HTTP conforms: false evidence: No RateLimit-*, X-RateLimit-* or Retry-After header appears in any spec or doc page; 429 appears in zero response objects. - id: oauth2 name: OAuth 2.0 conforms: partial evidence: >- The Auth Server API exposes POST /oauth/token and POST /v2/oauth/token plus Auth0, Google and Shopify authorization legs, but declares no oauth2 securityScheme, publishes no scope vocabulary, and serves no /.well-known/oauth-authorization-server. The tokens issued are Emotive session JWTs, not scoped third-party API credentials. url: https://api-gw.emotiveapp.co/auth/openapi.json - id: oidc name: OpenID Connect Discovery conforms: false evidence: /.well-known/openid-configuration returns 404 or a soft-404 HTML shell on every Emotive host. See well-known/emotive-well-known.yml. - id: rfc9727 name: RFC 9727 api-catalog well-known URI conforms: false evidence: /.well-known/api-catalog is not served on any Emotive host. - id: rfc9116 name: RFC 9116 security.txt conforms: false evidence: /.well-known/security.txt is not served on any Emotive host; no vulnerability disclosure policy or contact was found. - id: rfc8594 name: RFC 8594 Sunset header conforms: false evidence: No Sunset or Deprecation header is declared or documented, and no operation in any spec is marked deprecated, despite v1 and v2 of the Auth Server running side by side. - id: openapi name: OpenAPI Specification conforms: true evidence: >- Six OpenAPI documents are published by Emotive itself — five served live from the API gateway at api-gw.emotiveapp.co (OpenAPI 3.0.2) and one embedded verbatim in the GitBook Lists developer reference. A seventh was generated by API Evangelist from Emotive's prose docs. url: https://api-gw.emotiveapp.co/helpdesk/openapi.json - id: asyncapi name: AsyncAPI conforms: false evidence: No AsyncAPI document is published, though a real two-directional webhook surface exists. See asyncapi/emotive-webhooks.yml. - id: a2a name: A2A Agent Card conforms: true evidence: A conformant A2A agent card is served at https://help.emotive.io/.well-known/agent-card.json (protocolVersion 0.3). See a2a/emotive-a2a.yml. - id: mcp name: Model Context Protocol conforms: true evidence: An anonymous remote MCP server answers tools/list at https://help.emotive.io/mcp with three documentation tools. See mcp/emotive-mcp.yml. certifications_claimed_by_emotive: [] certifications_named_but_belonging_to_third_parties: - certification: ISO 27001 held_by: Amazon Web Services context: Emotive's physical infrastructure is hosted in AWS data centers. - certification: SOC 1 / SSAE 16 / ISAE 3402 held_by: Amazon Web Services - certification: PCI DSS Level 1 held_by: Amazon Web Services and Stripe context: Stripe processes Emotive's credit card payments. - certification: FISMA Moderate held_by: Amazon Web Services - certification: Sarbanes-Oxley (SOX) held_by: Amazon Web Services security_program: published: true url: https://www.emotive.io/security covers: [data centers, physical security, system authentication, vulnerability management, encryption, patching] vulnerability_disclosure_contact: null bug_bounty: null note: >- The page describes an internal vulnerability MANAGEMENT process (assessments, patch monitoring, third-party mailing lists, risk ranking, remediation). It provides no external DISCLOSURE channel — no security@ address, no policy page, no bounty program, no security.txt. A researcher has nowhere published to report to.