generated: '2026-08-12' method: derived source: https://support.marinsoftware.com/en_US/bulk-actions/marin-api note: >- Derived from Marin's live help-center API reference and legal pages; there is no OpenAPI to read securitySchemes or media types out of. Every "conforms: false" below is an observed absence in the published documentation, not an assumption. standards: - id: openapi conforms: false evidence: No OpenAPI/Swagger document is published on any Marin host; /openapi.json, /openapi.yaml, /swagger.json and /api-docs 404 on www and support, and 301 on one. - id: asyncapi conforms: false evidence: No event, streaming, or webhook surface is documented. - id: graphql conforms: false evidence: No /graphql surface is documented or reachable. - id: rest conforms: partial evidence: >- Self-described as a "post-only REST API", but it exposes only POST across five endpoints with no resource retrieval, no HTTP verb semantics beyond POST, and no hypermedia — RPC-over-HTTP in practice. - id: http-basic-auth conforms: true evidence: '"All endpoints require basic authorization using a Marin username and password."' - id: oauth2 conforms: false evidence: No OAuth 2.0 flows, authorization server, or token endpoint documented. - id: oidc conforms: false evidence: /.well-known/openid-configuration 404s on every Marin host. - id: rfc9457-problem-details conforms: false evidence: 'No application/problem+json; the published error contract is two HTTP status codes (200, 500) with no response body schema.' - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns "Invalid .well-known request" (404) on www and 301 on one.marinsoftware.com. - id: rfc8594-sunset-header conforms: false evidence: No deprecation or sunset policy is published. - id: rfc8615-well-known conforms: false evidence: Every probed /.well-known/* path 404s; the origin returns a generic "Invalid .well-known request" page. - id: a2a-agent-card conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json both 404 on www and 301 on one.marinsoftware.com. - id: mcp conforms: false evidence: No hosted or published Model Context Protocol server. - id: llms-txt conforms: false evidence: /llms.txt 404s on www and support. - id: idempotency conforms: false evidence: No idempotency key or replay contract documented. - id: pagination conforms: false evidence: Write-only surface; nothing to paginate. - id: rate-limit-headers conforms: false evidence: 'The "Errors and Limits" section publishes no limits and no RateLimit-* or Retry-After headers.' - id: tls-https-only conforms: true evidence: '"Only HTTPS requests are supported. Plain HTTP will fail."' - id: gdpr conforms: true evidence: >- Marin publishes a GDPR Data Processing Addendum as a linked PDF, incorporated by reference into the Terms of Use ("The parties agree that the Marin Software Data Processing Addendum ... is incorporated"), with the agreement governed by Irish law and Dublin jurisdiction for the EU contracting entity. url: https://www.marinsoftware.com/legal/data-processing-addendum - id: ccpa conforms: true evidence: A "Do Not Sell My Personal Information" notice and cookie-management page are published in the legal footer. url: https://www.marinsoftware.com/privacy/cookie-saas certifications_published: [] certifications_note: >- No SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP or CSA STAR claim appears on any live Marin page. There is no trust center: trust.marinsoftware.com and security.marinsoftware.com return 200 only because marinsoftware.com serves a wildcard subdomain catch-all that lands on the marketing homepage, and /security, /trust and /compliance all 404 on www. The published compliance posture is privacy/data-protection only (GDPR DPA + CCPA notice). x-evidence: - url: https://www.marinsoftware.com/legal/terms-of-use status: 200 fetched: '2026-08-12' - url: https://www.marinsoftware.com/legal/data-processing-addendum status: 200 note: redirects to the signed Data Processing Addendum PDF on the Webflow asset host fetched: '2026-08-12' - url: https://www.marinsoftware.com/trust status: 404 fetched: '2026-08-12' - url: https://www.marinsoftware.com/security status: 404 fetched: '2026-08-12' - url: https://www.marinsoftware.com/.well-known/security.txt status: 404 fetched: '2026-08-12'