generated: '2026-08-13' method: searched source: openapi/, https://trust.liveramp.com/, https://liveramp.com/security/, https://developers.liveramp.com/.well-known/api-catalog standards: - id: openapi-3.0 conforms: true evidence: >- Three published documents — Activation API (3.0.1, generated by LiveRamp's own open-source Reslang tool), Clean Room API (3.0.0), Privacy API (3.0.1). - id: openapi-3.1 conforms: false evidence: No published document uses OpenAPI 3.1. - id: oauth2 conforms: true evidence: >- Clean Room API declares an oauth2 clientCredentials scheme; the LiveRamp Service Account token service implements the OAuth 2.0 resource-owner password grant. - id: oidc conforms: partial evidence: >- The Service Account token request uses scope=openid and the token response includes an id_token, but LiveRamp publishes no /.well-known/openid-configuration discovery document (probed 404 on liveramp.com, developers.liveramp.com, api.liveramp.com). - id: rfc8414-oauth-authorization-server-metadata conforms: false evidence: /.well-known/oauth-authorization-server returned 404 on every host probed. - id: rfc9727-api-catalog conforms: true evidence: >- https://developers.liveramp.com/.well-known/api-catalog returns an application/linkset+json document naming all ten developer-portal API surfaces, each with a nested per-API catalog and a service-doc link. - id: rfc9116-security-txt conforms: false evidence: >- No /.well-known/security.txt on any host. developers.liveramp.com answers 200 with the Webflow SPA HTML shell, which is not a security.txt document. - id: rfc9457-problem-details conforms: false evidence: >- Errors use a proprietary { error: { message, code, requestId } } envelope with LiveRamp's own 600-nnnn code registry; no application/problem+json media type appears in any spec. - id: rfc8594-sunset-header conforms: false evidence: >- Deprecations are announced in the changelog with dated sunsets (ATS Mobile SDK, 2026-09-30) but no Sunset or Deprecation response header is documented. - id: idempotency conforms: partial evidence: >- Privacy API POST /v1/requests deduplicates natively (is_duplicate + stable request_uuid). No Idempotency-Key header anywhere in the portfolio. - id: rate-limit-headers conforms: false evidence: >- Numeric limits are published for AbiliTec but no X-RateLimit-* / RateLimit-* response headers are documented on any API. - id: llmstxt conforms: true evidence: >- https://developers.liveramp.com/llms.txt returns a 75,679-byte index covering ten APIs, plus a per-API llms.txt for each. Every documentation page is also retrievable as .md. - id: mcp conforms: partial evidence: >- LiveRamp publishes an MCP server (LiveRamp/logscale-mcp) but it fronts CrowdStrike LogScale, not LiveRamp's own APIs, and it is local-stdio with no hosted endpoint. - id: a2a conforms: false evidence: No agent card at /.well-known/agent-card.json or /.well-known/agent.json on any host. - id: json-api conforms: false - id: odata conforms: false - id: scim conforms: false - id: fhir conforms: false - id: iab-tcf conforms: true evidence: >- LiveRamp publishes and maintains an open-source Go implementation of the IAB Consent String specs v1.1 and v2 (github.com/LiveRamp/iabconsent). - id: iab-ccpa-us-privacy conforms: true evidence: >- LiveRamp publishes an open-source Go implementation of the IAB U.S. Privacy String / CCPA Opt-Out Storage Format (github.com/LiveRamp/ccpa). - id: tls-1.2-minimum conforms: true evidence: >- TLS 1.2 or higher required since 2022-11-01; earlier versions rejected. Live probes observed TLSv1.3 on liveramp.com and developers.liveramp.com. compliance_program: published: true url: https://trust.liveramp.com/ certifications: - SOC 2 - ISO 27001 - GDPR additional: - name: Data Protection Addendum url: https://www.liveramp.com/legal/dpa/ - name: Subprocessors url: https://liveramp.com/legal/subprocessors/ - name: RampID Data Protection Attestation url: https://storage.googleapis.com/lr-tech-docs-resources/Files/LiveRamp%20RampID%20Data%20Protection%20Attestation.pdf - name: Overview of State Privacy Laws url: https://storage.googleapis.com/lr-tech-docs-resources/Files/LiveRamp%20Overview%20of%20State%20Privacy%20Laws.pdf source: security/liveramp-trust-center.yml