generated: '2026-09-13' method: searched source: https://integrately.com/home/privacy provider: Integrately providerId: integrately description: >- Standards and regulatory conformance Integrately actually states in public. Integrately publishes no API contract, so nothing here is derived from a spec — every entry is read from the provider's own privacy policy, terms and pricing pages, or from a live probe. Absences are recorded as conforms false with the evidence that establishes the absence, not left out. legal_entity: name: CompanyHub It Solutions Private Limited brand: Integrately source: >- schema.org Organization block (creator.legalName) embedded in https://integrately.com/pricing, fetched 2026-09-13. conformance: - id: gdpr name: EU General Data Protection Regulation (Regulation (EU) 2016/679) conforms: true grade: stated evidence: https://integrately.com/home/privacy note: >- The privacy policy (last updated 12 Sept 2024) names GDPR by its full citation in its definitions section and adopts the Article 4 meanings of Personal data, Processor and Controller. This is a stated alignment, not an audited certification. - id: tls name: HTTPS / TLS in transit conforms: true grade: verified evidence: https://integrately.com/home/privacy note: >- "The connection between Integrately and your browser is always encrypted (HTTPS)." Independently confirmed by probe: TLSv1.3 on both integrately.com and app.integrately.com, with HSTS max-age 31536000 on app.integrately.com and on embed.integrately.com (includeSubDomains; preload). See security/integrately-domain-security.yml. - id: oauth2 name: OAuth 2.0 conforms: true grade: consumer-side evidence: https://integrately.com/docs#sign-in-OAuth note: >- Integrately is an OAuth CLIENT, not an OAuth provider. It documents "Sign-In (OAuth)" as one of three ways a user connects a third-party app, and 295 of the 1,100 apps in its own catalog are flagged isOAuth true. Integrately itself exposes no authorization server — probes of /.well-known/oauth-authorization-server and /.well-known/openid-configuration on all four known hosts returned no document. - id: soc2 name: SOC 2 conforms: false evidence: https://integrately.com/home/privacy note: No SOC 2 claim appears anywhere on the site; there is no trust centre or compliance page. - id: iso27001 name: ISO/IEC 27001 conforms: false evidence: https://integrately.com/home/privacy note: No ISO 27001 claim found. - id: hipaa name: HIPAA conforms: false evidence: https://integrately.com/home/privacy note: No HIPAA claim or BAA offer found. - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: https://embed.integrately.com/apps note: >- The one live JSON surface (the embed widget's backing endpoints) uses a bespoke "{ success, message, total, data }" envelope, not application/problem+json. - id: rfc9116 name: RFC 9116 security.txt conforms: false evidence: https://integrately.com/.well-known/security.txt note: 404 on the apex; SPA HTML shells on www and app; 404 on embed. See well-known/integrately-well-known.yml. - id: openapi name: OpenAPI Specification conforms: false evidence: https://integrately.com/openapi.json note: >- No OpenAPI, Swagger, GraphQL SDL, AsyncAPI, Protobuf or WSDL contract is published on any Integrately host. See x-contract-discovery below. domain_standards: searched: true found: [] note: >- REWARD-ONLY, and nothing to reward here honestly. The iPaaS / workflow-automation market has no interoperability standard an integration platform declares in its contract — there is no SCIM, OData, OpenRTB, Sparkplug, ActivityPub, LTI, OAI-PMH, HL7, X12 or ISO 20022 analogue for "connect app A to app B". Integrately's own integration surface is proprietary (a per-app trigger/action model). No domain standard is asserted. x-contract-discovery: performed: '2026-09-13' hosts_probed: - integrately.com - www.integrately.com - app.integrately.com - embed.integrately.com paths_probed: [/openapi.json, /openapi.yaml, /swagger.json, /api-docs, /docs, /redoc, /llms.txt, /graphql] result: >- No machine-readable contract found. The apex returns real 404s; www and app return a single-page-app HTML shell with HTTP 200 for every path, which is a soft-404 and is not treated as a hit; embed.integrately.com returns bare 404s. integrately.com/docs returns HTTP 200 and is a genuine page, but it is an end-user help centre ("Welcome to the Integrately Help Center"), not an API reference. No GraphQL endpoint, no MCP server, no A2A agent card, no gRPC/proto and no WSDL were found. x-evidence: - url: https://integrately.com/home/privacy http_status: 200 fetched: '2026-09-13' - url: https://integrately.com/docs http_status: 200 fetched: '2026-09-13' - url: https://integrately.com/openapi.json http_status: 404 fetched: '2026-09-13' - url: https://embed.integrately.com/apps http_status: 200 fetched: '2026-09-13' maintainers: - FN: Kin Lane email: kin@apievangelist.com