generated: '2026-08-12' method: searched source: https://mapp.com/trust/, https://docs.mapp.com/apidocs/, live probes of api.mapp.com and mapp.com standards: - id: oauth2 conforms: true evidence: openapi/mapp-intelligence-analytics-openapi.yml declares an oauth2 clientCredentials scheme with tokenUrl https://auth.mapp.com/oauth2/token; openapi/mapp-fashion-openapi.yml documents an authorization_code + PKCE flow. - id: rfc7636-pkce conforms: true evidence: 'Mapp Fashion /oauth/authorize mandates PKCE with the S256 challenge method; mapp.com /.well-known/oauth-authorization-server advertises code_challenge_methods_supported: [S256].' - id: rfc8414-authorization-server-metadata conforms: true evidence: https://mapp.com/.well-known/oauth-authorization-server returns 200 application/json with issuer, authorization_endpoint, token_endpoint, revocation_endpoint. - id: rfc9728-protected-resource-metadata conforms: true evidence: https://mapp.com/.well-known/oauth-protected-resource returns 200; the MCP endpoint answers 401 with a WWW-Authenticate Bearer challenge carrying resource_metadata. - id: rfc9457-problem-details conforms: true evidence: GET https://api.mapp.com/api/analytics/segments returns 401 application/problem+json with type/title/status/detail/instance; the Analytics OpenAPI defines a Problem schema. - id: rfc7617-http-basic conforms: true evidence: The Mapp Engage REST API authenticates with HTTP Basic using an API-type system user (docs.mapp.com/apidocs/getting-started-with-engage-api). - id: mcp conforms: true evidence: A live MCP endpoint is served at https://mapp.com/wp-json/mcp/mcp-oauth-server with RFC 8414/9728 discovery. tools/list is OAuth-gated. - id: openapi conforms: true evidence: Mapp publishes OpenAPI 3.0.1/3.0.3 documents for the Product Catalog and Analytics APIs and Swagger 2.0 fragments for Engage and Mapp Fashion, embedded per endpoint on docs.mapp.com/apidocs. - id: llmstxt conforms: true evidence: https://docs.mapp.com/llms.txt (3,895 lines) and https://mapp.com/llms.txt both return real llms.txt documents. - id: apache-kafka conforms: true evidence: Mapp Intelligence Data Streams is a standard Apache Kafka setup with SASL/JAAS auth and JSON or Avro payloads (docs.mapp.com/docs/data-streams). - id: iso-27001 conforms: true evidence: Named on https://mapp.com/trust/ with a downloadable certificate. - id: iso-27017 conforms: true evidence: Named on https://mapp.com/trust/ as an ISO 27001 add-on (cloud security). - id: iso-27018 conforms: true evidence: Named on https://mapp.com/trust/ as an ISO 27001 add-on (cloud privacy). - id: iso-27701 conforms: true evidence: Named on https://mapp.com/trust/ (privacy information management). - id: iso-22301 conforms: true evidence: Named on https://mapp.com/trust/ (business continuity). - id: gdpr conforms: true evidence: https://mapp.com/trust/ publishes a DPA, TOMs, SOA and sub-processor list; the Engage API exposes GDPR contact export and anonymize operations. - id: ccpa conforms: true evidence: Named on https://mapp.com/trust/. - id: nis2 conforms: true evidence: Named on https://mapp.com/trust/. - id: dora conforms: true evidence: Named on https://mapp.com/trust/. - id: csa-caiq conforms: true evidence: A CAIQ security questionnaire is offered for download on https://mapp.com/trust/. - id: soc2 conforms: false evidence: No SOC 2 attestation is named on https://mapp.com/trust/; the program is ISO-based. - id: pci-dss conforms: false evidence: Not claimed; Mapp is not a payments provider. - id: hipaa conforms: false evidence: Not claimed. - id: fedramp conforms: false evidence: Not claimed; hosting is in ISO 27001 certified data centres in Germany and AWS EU regions. - id: openidconnect conforms: false evidence: No /.well-known/openid-configuration is served on any Mapp host (404 on mapp.com and docs.mapp.com; soft-404 HTML on api.mapp.com and auth.mapp.com). - id: rfc9116-security-txt conforms: false evidence: No /.well-known/security.txt on any host probed 2026-08-12. - id: asyncapi conforms: false evidence: The Data Streams event surface is documented as raw Kafka; no AsyncAPI document is published. - id: a2a conforms: false evidence: No agent card at /.well-known/agent-card.json or /.well-known/agent.json on any host. - id: idempotency conforms: false evidence: No idempotency key header, parameter, or retry-safety contract appears anywhere in the four OpenAPI surfaces or the docs; the published retry guidance is time-based (30s, then 15 minutes) with no deduplication guarantee. - id: json-api conforms: false evidence: Responses are plain JSON, not JSON:API media types. - id: scim conforms: false evidence: System-user management is proprietary (/system/user*), not SCIM 2.0.