generated: '2026-08-12' method: probed source: >- Live response headers observed on https://media-processor-65la52ndha-uc.a.run.app/ and /health (2026-08-12), Markerly's published source at https://github.com/Markerly/media-processor-microservice, and /.well-known probes of markerly.com, api.markerly.com, and the Cloud Run host. api: markerly:media-processor notes: >- Markerly makes no public conformance or compliance claims — there is no trust center, no certification page, and no standards statement anywhere on markerly.com. Every entry below is asserted from observed behavior, not from a provider claim. No Compliance pointer is emitted because no certification is published. standards: - id: ratelimit-headers name: IETF RateLimit header fields for HTTP (draft) conforms: true evidence: >- Live 200 on https://media-processor-65la52ndha-uc.a.run.app/ returned ratelimit-policy: 100;w=900, ratelimit-limit: 100, ratelimit-remaining: 99, ratelimit-reset: 900 — the standard field names, with the legacy X-RateLimit-* variants explicitly disabled. note: Retry-After is not sent on 429; the retry hint is body-only. - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: >- Errors are returned as application/json with a flat {error, message} object, not application/problem+json, and carry no type, title, status, detail, or instance members. - id: rfc9116 name: RFC 9116 security.txt conforms: false evidence: >- /.well-known/security.txt returned 404 on markerly.com, api.markerly.com, and media-processor-65la52ndha-uc.a.run.app. - id: rfc8615 name: RFC 8615 well-known URIs / RFC 9727 api-catalog conforms: false evidence: /.well-known/api-catalog returned 404 on all three hosts. - id: oauth2 name: OAuth 2.0 authorization server conforms: false evidence: >- Markerly is an OAuth client of Meta and TikTok, not a provider. /.well-known/oauth-authorization-server and /.well-known/openid-configuration returned 404 on every host probed. - id: openapi name: OpenAPI Specification conforms: false evidence: >- No OpenAPI or Swagger document is served. /openapi.json, /openapi.yaml, /swagger.json, /api-docs, /docs, /redoc, and /v1/openapi.json all returned 404 on markerly.com, api.markerly.com, and the Cloud Run host. - id: asyncapi name: AsyncAPI conforms: false evidence: No event, streaming, or webhook surface is published. - id: hsts name: RFC 6797 HTTP Strict Transport Security conforms: partial evidence: >- The Cloud Run API host sends strict-transport-security: max-age=15552000; includeSubDomains. The marketing site markerly.com sends no HSTS header (see security/markerly-domain-security.yml). - id: cors name: W3C Cross-Origin Resource Sharing conforms: true evidence: >- access-control-allow-origin: * on the API host. Permissive by design, and notable because the endpoint behind it is unauthenticated and compute-heavy. - id: owasp-secure-headers name: OWASP secure response headers conforms: true evidence: >- helmet is applied, and the live response carries content-security-policy, x-content-type-options: nosniff, x-frame-options: SAMEORIGIN, referrer-policy: no-referrer, cross-origin-opener-policy: same-origin, cross-origin-resource-policy: same-origin, x-permitted-cross-domain-policies: none, and origin-agent-cluster: ?1. - id: fhir conforms: false - id: fapi conforms: false - id: scim conforms: false - id: odata conforms: false - id: psd2 conforms: false - id: jsonapi conforms: false compliance_certifications: published: false detail: >- No SOC 2, ISO 27001, PCI DSS, HIPAA, or FedRAMP claim appears on markerly.com. The Terms of Use page (https://markerly.com/tos, which carries the privacy policy) describes Texas privacy rights, a Do Not Track statement, and a minors policy, but names no certification or audited framework. Notable given that Markerly runs influencer campaigns for government agencies and public-health clients, a buyer segment that normally asks for one.