generated: '2026-08-14' method: searched source: https://www.matik.io/security standards: - id: oauth2 conforms: true evidence: >- OAuth 2.0 authorizationCode + refresh_token flow with producer/consumer scopes (https://developer.matik.io/guides/oauth). Confirmed independently by the first-party Postman collection, which carries authUrl https://app.matik.io/oauth/authorize and accessTokenUrl https://app.matik.io/api/v1/oauth/token/. - id: rfc8414-oauth-authorization-server-metadata conforms: false evidence: >- /.well-known/oauth-authorization-server returns 404 on www.matik.io, app.matik.io and developer.matik.io. The authorize/token endpoints are discoverable only from prose. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on every Matik host. - id: openapi conforms: false evidence: >- No OpenAPI is served. Probed and 404: developer.matik.io /openapi.json, /openapi.yaml, /matik.yaml; app.matik.io /api/1.0/openapi.json, /api/1.0/swagger, /api/1.0/swagger.json, /api/swagger, /api/v1/swagger. app.matik.io/swagger returns 200 but is the SPA shell (body "Matik"), not a spec. The reference at developer.matik.io IS generated by docusaurus-plugin-openapi-docs — the rendered pages carry `openapi__heading` and `openapi-tabs__*` classes — so the source document exists but is not published. - id: soc2 conforms: true evidence: 'SOC 2 Type I and Type II certified (https://www.matik.io/security)' - id: gdpr conforms: true evidence: GDPR compliant (https://www.matik.io/security) - id: rfc9457-problem-details conforms: false evidence: >- No application/problem+json error format documented on any of the 91 operations. See errors/matik-problem-types.yml. - id: rfc9116-security-txt conforms: false evidence: >- No /.well-known/security.txt on any Matik-controlled host. status.matik.io serves Atlassian's, which belongs to the Statuspage vendor, not Matik. - id: rfc8594-sunset-header conforms: false evidence: No deprecation or sunset policy published. See lifecycle/matik-lifecycle.yml. - id: rest conforms: true evidence: >- REST API served under https://app.matik.io/api/1.0/ with 91 documented operations across 15 resource areas (https://developer.matik.io/docs/matik/matik-external-api). - id: mcp conforms: true partial: true evidence: >- A [BETA] hosted MCP server with 8 tools and OAuth 2.0 dynamic client registration (https://help.matik.io/hc/en-us/articles/48790661770267--BETA-Matik-MCP-Server). The endpoint URL is not public — it is issued by a Technical Account Manager — so the server cannot be reached or introspected from public information. - id: a2a conforms: false evidence: >- No agent card. /.well-known/agent-card.json and /.well-known/agent.json both 404 on www.matik.io, app.matik.io and developer.matik.io. compliance_program: certifications: [SOC 2 Type I, SOC 2 Type II, GDPR] page: https://www.matik.io/security see: security/matik-trust-center.yml vulnerability_disclosure: published: false note: >- Re-probed 2026-08-14. https://www.matik.io/security (HTTP 200, ~20k chars) contains no occurrence of "disclosure", "vulnerability", "bug bounty", "security@", "penetration" or "report a" — it is a security-posture page, not a disclosure policy. No security.txt, no HackerOne/Bugcrowd/Intigriti program. The `type: Security` pointer that the 2026-07-20 pass wired at this URL has been REMOVED from apis.yml: the check it feeds (`security_disclosure`) asserts the provider publishes a way to report a vulnerability, and Matik does not. The `Compliance` and `TrustCenter` pointers at the same URL are correct and remain.