generated: '2026-07-19' method: searched source: https://entytle.com/compliance/ # Entytle publishes no public OpenAPI, so cross-cutting API standards cannot be # derived from a spec. These entries capture the compliance/security posture the # provider publishes on its compliance page (searched). standards: - id: soc2-type-ii conforms: true evidence: 'compliance page: SOC 2 Type II, validated through regular external audits against AICPA Trust Services Criteria' source: https://entytle.com/compliance/ - id: gdpr conforms: true evidence: 'compliance page: adheres to EU General Data Protection Regulation; publishes GDPR Guidelines' source: https://entytle.com/compliance/ - id: penetration-testing conforms: true evidence: 'compliance page: regular external penetration tests (automated scans + manual expert testing)' source: https://entytle.com/compliance/ - id: iso-27001 conforms: false evidence: not referenced on the compliance page - id: hipaa conforms: false evidence: not referenced on the compliance page