generated: '2026-08-01' method: searched source: 'openapi/immuta-marketplace-api-openapi.yml (derived) + https://www.immuta.com/trust/ and https://documentation.immuta.com/saas/developer-guides/api-intro (searched)' standards: - id: openapi-3.0 conforms: true evidence: 'openapi/immuta-marketplace-api-openapi.yml declares openapi 3.0.0 with 61 paths / 83 operations; published by Immuta at https://openapi.gitbook.com/o/8hhKnYZrfOSd79qII2UJ/spec/immuta-marketplace-api.yaml' - id: asyncapi conforms: false evidence: no AsyncAPI document on any host; the event surface is documented as a webhook reference only (asyncapi/immuta-webhooks.yml) - id: oauth2 conforms: false evidence: 'no oauth2 securityScheme in the published spec and no OAuth authorization server for the Immuta APIs. OAuth 2.0 appears in Immuta only as an inbound option for the Alation catalog integration and as SSO/IAM configuration, not as an API authorization model.' - id: openid-connect conforms: false evidence: 'no /.well-known/openid-configuration on any Immuta host (all probed 404); OIDC is supported for end-user SSO into the Immuta app, not for API authorization' - id: rfc6750-bearer-token conforms: true evidence: 'securitySchemes.bearer is type http, scheme bearer, bearerFormat JWT; the Request app issues personal access tokens presented as Authorization: Bearer' - id: rfc9457-problem-details conforms: false evidence: errors are plain application/json with a status code and message; no application/problem+json anywhere in the spec or docs - id: rfc9116-security-txt conforms: false evidence: no /.well-known/security.txt on any host (well-known/immuta-well-known.yml) - id: rfc8594-sunset-header conforms: false evidence: deprecations are published as a documentation table with tentative EOL dates; no Sunset or Deprecation response headers are documented - id: json-schema conforms: true evidence: 89 reusable components.schemas in the published OpenAPI - id: a2a conforms: false evidence: no agent card at /.well-known/agent-card.json or /.well-known/agent.json on any Immuta host - id: mcp conforms: true evidence: a live MCP server answering tools/list over streamable HTTP at https://documentation.immuta.com/saas/~gitbook/mcp (documentation scope; see mcp/immuta-mcp.yml) - id: llms-txt conforms: true evidence: https://documentation.immuta.com/llms.txt returns a complete documentation index (redirects to /saas/llms.txt), and every docs page is retrievable as markdown by appending .md - id: scim conforms: false evidence: identity is managed through Immuta's own bim endpoints and IAM integrations; no SCIM 2.0 paths - id: odata conforms: false - id: json-api conforms: false evidence: 'pagination envelope is a bespoke { data, meta } shape, not JSON:API' compliance_program: published: true url: https://www.immuta.com/trust/ certifications: - {name: SOC 2 Type 2, body: AICPA, availability: report on request via account manager} - {name: ISO 27001} - {name: ISO 27701} - {name: PCI DSS, auditor: A-LIGN} - {name: GDPR, note: 'Immuta acts as both data processor and data controller; DPA published at https://www.immuta.com/wp-content/uploads/2024/06/Immuta-Data-Processing-Agreement-%E2%80%93-June2024.pdf'} audits: annual independent external security audit; periodic third-party penetration testing artifact: security/immuta-trust-center.yml