generated: '2026-08-12' method: searched source: >- https://support.liveintent.com/programmatic-bidding-api/, https://privacy.liadm.com/api-guide, https://www.liveintent.com/privacy-policy/, plus the two harvested OpenAPI documents. Probed 2026-08-12. standards: - id: openapi-3.0 conforms: true evidence: >- Both harvested documents declare openapi 3.0.0 (openapi/liveintent-audiences-openapi.yml, openapi/liveintent-privacy-openapi.yml). - id: openrtb-2.5 conforms: true evidence: >- "The LiveIntent Programmatic Bidding API incorporates a subset of the IAB OpenRTB specification v2.5"; requests carry the header x-openrtb-version: 2.5 and a no-bid is signalled with HTTP 204 and an empty body. Implicit tmax=150ms. docs: https://support.liveintent.com/programmatic-bidding-api/ - id: openrtb-native-1.1 conforms: true evidence: LiveIntent Programmatic Bidding API supports IAB OpenRTB Native Ads 1.1 markup. docs: https://support.liveintent.com/programmatic-bidding-api/ - id: openrtb-native-1.2 conforms: true evidence: LiveIntent Programmatic Bidding API supports IAB OpenRTB Native Ads 1.2 markup. docs: https://support.liveintent.com/programmatic-bidding-api/ - id: gdpr conforms: true evidence: >- The Privacy Management API exists specifically to accept GDPR data subject requests (RESTRICT / ERASURE / ACCESS) programmatically, and LiveIntent publishes a GDPR Data Processing Addendum in its knowledge base. docs: https://privacy.liadm.com/api-guide - id: ccpa conforms: true evidence: >- The Privacy Management API accepts CCPA opt-out-of-sale and deletion requests; LiveIntent publishes a CCPA notice. docs: https://privacy.liadm.com/api-guide - id: global-privacy-control conforms: true evidence: >- LiveIntent's privacy policy states it recognizes and processes Global Privacy Control signals and opts users out of sale/sharing when a GPC signal is detected. docs: https://www.liveintent.com/privacy-policy/ - id: iab-tcf conforms: true evidence: >- LiveIntent maintains a public attestation of compliance in the IAB Europe Global Vendor List. docs: https://www.liveintent.com/privacy-policy/ - id: oauth2 conforms: false evidence: >- No RFC 6749 authorization server. All APIs use an opaque bearer token in the Authorization header, declared in OpenAPI as an apiKey scheme. The Reporting API's documentation calls its username/password login endpoint "OAuth2" but it publishes no authorize endpoint, client_id or scopes. - id: oidc conforms: false evidence: >- /.well-known/openid-configuration returned 404 on www.liveintent.com, audiences.liveintent.com and privacy.liadm.com, and 401 on connect.liveintent.com (probed 2026-08-12). - id: rfc9457-problem-details conforms: false evidence: >- Errors use a proprietary ApplicationError array under `errors` with media type application/json — no `type` URI, no `title`, not application/problem+json. - id: rfc8594-sunset-header conforms: false evidence: >- No Sunset or Deprecation headers are documented; Legacy Privacy API endpoints are deprecated in prose only and carry no `deprecated: true` flag in the spec. - id: rfc9116-security-txt conforms: false evidence: >- /.well-known/security.txt returned 404 on www.liveintent.com, audiences.liveintent.com and privacy.liadm.com (probed 2026-08-12). - id: rfc8615-well-known conforms: false evidence: >- No /.well-known/ document of any kind is served on any LiveIntent host. See well-known/liveintent-well-known.yml. - id: asyncapi conforms: false evidence: >- No event, streaming or webhook surface is published. See asyncapi/liveintent-events.yml. - id: json-api conforms: false evidence: Plain JSON payloads; no JSON:API media type or document structure. - id: fhir-r4 conforms: false - id: scim2 conforms: false - id: odata conforms: false - id: psd2 conforms: false - id: fapi conforms: false certifications: published: false named: [] note: >- No trust center, compliance page or named certification (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP) could be found. trust.liveintent.com and security.liveintent.com do not resolve; https://www.liveintent.com/security/ and /trust/ returned 404. LiveIntent's regulatory posture is real but it is privacy-regime conformance (GDPR/CCPA/GPC/TCF), not an audited security certification. Because no certification program is published, NO `Compliance` pointer is wired into apis.yml. probed: - {url: 'https://www.liveintent.com/security/', status: 404} - {url: 'https://www.liveintent.com/trust/', status: 404} - {url: 'https://trust.liveintent.com', status: NXDOMAIN}