generated: '2026-08-22' method: probed source: >- Live probes of https://mcp.glaciergrid.com/ metadata endpoints, plus https://www.glaciergrid.com/privacy, /dpa, /subprocessors summary: >- GlacierGrid asserts no security certification publicly (no SOC 2, ISO 27001, PCI, HIPAA or FedRAMP claim appears anywhere on its site, and there is no trust center). What it does publish is a privacy compliance program — a privacy policy naming CCPA, a Data Processing Addendum, a maintained sub-processor list with a change-notification commitment, and a privacy-request intake. On the technical side, the MCP server is genuinely conformant with the modern OAuth discovery stack. standards: - id: oauth2 name: OAuth 2.0 Authorization Framework (RFC 6749) conforms: true evidence: url: https://mcp.glaciergrid.com/.well-known/oauth-authorization-server detail: authorization_endpoint, token_endpoint, revocation_endpoint, grant_types authorization_code + refresh_token. - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata conforms: true evidence: url: https://mcp.glaciergrid.com/.well-known/oauth-authorization-server status: 200 - id: rfc9728 name: OAuth 2.0 Protected Resource Metadata conforms: true evidence: url: https://mcp.glaciergrid.com/.well-known/oauth-protected-resource/mcp status: 200 detail: >- Advertised from the 401 via WWW-Authenticate: Bearer resource_metadata="https://mcp.glaciergrid.com/.well-known/oauth-protected-resource/mcp" - id: rfc7636 name: PKCE conforms: true evidence: detail: 'code_challenge_methods_supported: ["S256"]' - id: rfc7591 name: OAuth 2.0 Dynamic Client Registration conforms: true evidence: url: https://mcp.glaciergrid.com/register detail: Advertised as registration_endpoint; POST with an empty body returns 400 (endpoint present and validating). - id: rfc7009 name: OAuth 2.0 Token Revocation conforms: true evidence: detail: 'revocation_endpoint: https://mcp.glaciergrid.com/revoke' - id: mcp name: Model Context Protocol (streamable HTTP transport) conforms: true evidence: url: https://mcp.glaciergrid.com/health detail: '{"status":"ok","transport":"streamable-http","auth":"oauth"}; /mcp answers JSON-RPC 2.0 error objects.' - id: json-rpc-2.0 name: JSON-RPC 2.0 conforms: true evidence: detail: 'Observed envelope {"jsonrpc":"2.0","error":{"code":-32001,...},"id":null}' - id: ratelimit-headers name: IETF RateLimit header fields (draft-ietf-httpapi-ratelimit-headers) conforms: true evidence: detail: 'ratelimit-policy: 2000;w=900 and ratelimit: limit=2000, remaining=1999, reset=900 on a live response.' - id: oidc name: OpenID Connect Discovery conforms: false evidence: url: https://mcp.glaciergrid.com/.well-known/openid-configuration status: 404 - id: rfc9457 name: Problem Details for HTTP APIs conforms: false evidence: detail: Errors are JSON-RPC objects, not application/problem+json. - id: rfc9116 name: security.txt conforms: false evidence: url: https://www.glaciergrid.com/.well-known/security.txt status: 404 - id: rfc8594 name: Sunset HTTP header conforms: false evidence: detail: No Sunset or Deprecation header and no deprecation policy published. - id: a2a name: A2A Agent Card conforms: false evidence: detail: /.well-known/agent-card.json and /.well-known/agent.json return 404 on mcp.glaciergrid.com and www.glaciergrid.com. domain_standards: - id: haccp name: HACCP (Hazard Analysis and Critical Control Points) market: food safety / cold chain conforms: false claimed_in_marketing: true evidence: detail: >- GlacierGrid's llms.txt and product pages describe "HACCP-ready compliance reporting" and an "IoT Temperature Logging and HACCP Compliance Guide", but this is a prose claim on marketing pages. There is no contract, schema, message type or export format published that declares a HACCP structure, so the domain-standard signature is NOT present in any machine-readable artifact. urls: - https://www.glaciergrid.com/en/llms.txt - https://www.glaciergrid.com/resources/research-and-impact/iot-temperature-logging-haccp-compliance-guide - id: lorawan name: LoRaWAN (LoRa Alliance) market: IoT device connectivity conforms: true layer: device/radio, not API evidence: url: https://www.glaciergrid.com/resources/technical-guides/lorawan detail: >- GlacierGrid's sensors and hubs are LoRaWAN-based and the company publishes a technical guide and hardware specifications. This is a hardware-layer standard, not an API contract, so it does not carry a machine-readable signature in any artifact here. - id: bacnet-modbus-lonworks name: BACnet / Modbus / LonWorks (building automation) market: building automation systems conforms: claimed evidence: url: https://www.glaciergrid.com/technology/integrations-and-controls detail: >- GlacierGrid's own llms.txt describes the Integrations and Controls page as "BAS integration (BACnet, Modbus, LonWorks) and cloud-based controls platform". The public page itself lists named third-party integrations (Ecobee, Emporia, Shelly, UtilityAPI, Visual Crossing, Arcadia) but publishes no protocol conformance detail, point list or object mapping — so this is a stated capability, not a verifiable contract signature. note: >- These are inbound integrations GlacierGrid consumes, not a standard it exposes to integrators. compliance_program: certifications_published: [] note: >- No SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP claim was found on any GlacierGrid page. /security, /trust and /compliance all return 404 and there is no trust center. privacy_program: published: true regimes: - id: ccpa evidence: url: https://www.glaciergrid.com/privacy status: 200 - id: gdpr evidence: url: https://www.glaciergrid.com/helpcenter/what-is-glaciergrid status: 200 detail: GDPR referenced; the DPA at /dpa is the contractual instrument. artifacts: - name: Privacy Policy & Cookies url: https://www.glaciergrid.com/privacy status: 200 - name: Data Processing Addendum url: https://www.glaciergrid.com/dpa status: 200 - name: Sub-processors url: https://www.glaciergrid.com/subprocessors status: 200 last_updated_by_provider: '2026-08-01' commitment: >- "We update this page when we add or replace a sub-processor and give affected business customers advance notice and an opportunity to object." subprocessors: - name: Amazon Web Services purpose: Compute, database, content delivery, and load balancing location: United States - name: AWS ElastiCache (Valkey) purpose: Authorization state only; no facility data location: United States - name: InfluxData (InfluxCloud) purpose: Time-series sensor telemetry location: United States - name: Google (Firebase) purpose: Identity and sign-in location: United States - name: Elastic Cloud purpose: Operational logs and performance monitoring location: United States - name: Anthropic, PBC purpose: >- Operates Claude. Where a customer connects the GlacierGrid Connector for Claude, Anthropic receives the facility data returned by the connector. location: United States - name: Privacy Request url: https://www.glaciergrid.com/privacy-request status: 200 - name: Master Services Agreement url: https://www.glaciergrid.com/msa status: 200 contact: privacy@glaciergrid.com