generated: '2026-08-13' method: derived source: >- openapi/*.yml, well-known/mediamath-well-known.yml, mcp/mediamath-mcp.yml, grpc/mediamath-winnotice.proto, https://apidocs.mediamath.com/guides/authentication, https://apidocs.mediamath.com/guides/api-rate-limiting, https://apidocs.mediamath.com/guides/security-best-practices note: >- Assertions about cross-cutting standards. Each entry records whether MediaMath conforms and the evidence for the call. No compliance certification (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP) was found published on any MediaMath or Infillion host, so no Compliance pointer is emitted — see `certifications` below for the probes that came up empty. standards: - id: oauth2 name: OAuth 2.0 (RFC 6749) conforms: true evidence: >- Auth0-backed OAuth2 at https://auth.mediamath.com/. Authorization Code and Resource Owner Password grants are documented end to end with authorize/token endpoints, audience, client_id/client_secret and refresh_token exchange. Declared as oauth2 securitySchemes in the specs. source: https://apidocs.mediamath.com/guides/authentication - id: oauth2-refresh name: OAuth 2.0 refresh tokens conforms: true evidence: offline_access scope documented; grant_type=refresh_token exchange documented with response shape. source: https://apidocs.mediamath.com/guides/authentication - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata conforms: partial evidence: >- A conformant metadata document is served at https://apidocs.mediamath.com/.well-known/oauth-authorization-server (HTTP 200) — but it describes the documentation MCP server's authorization server (issuer https://auth.cloud.redocly.com), not the platform APIs. The platform's own Auth0 tenant publishes no metadata document at any probed mediamath.com path. - id: oidc name: OpenID Connect Discovery conforms: false evidence: >- /.well-known/openid-configuration returned 404 on apidocs.mediamath.com, api.mediamath.com and infillion.com. The refresh-token docs mention an id_token when `openid` scope is requested, so OIDC is implemented by the Auth0 tenant but no discovery document is exposed on a MediaMath host. - id: rfc9116 name: security.txt conforms: false evidence: 404 on every probed host. A disclosure contact (security@mediamath.com) is published in prose only. see: security/mediamath-vulnerability-disclosure.yml - id: rfc9457 name: Problem Details for HTTP APIs conforms: false evidence: Errors use a vendor {meta, errors[]} envelope with application/json, not application/problem+json. see: errors/mediamath-problem-types.yml - id: rfc8594 name: Sunset HTTP header / deprecation signalling conforms: false evidence: >- Two APIs carry dated deprecation notices in prose, but no Sunset or Deprecation response headers are documented and no operation in any spec carries deprecated: true. see: lifecycle/mediamath-lifecycle.yml - id: idempotency name: Idempotent write semantics conforms: false evidence: >- No Idempotency-Key header, no client-supplied request key, and updates use POST rather than PUT/PATCH. Documented retry guidance applies backoff to writes with no de-duplication mechanism. see: conventions/mediamath-conventions.yml - id: pagination name: Documented pagination conforms: true evidence: >- Offset pagination via page_limit / page_offset with sort_by and q, and meta.count / meta.total_count / meta.offset in every collection response. source: https://apidocs.mediamath.com/guides/postman-collections - id: rate-limit-headers name: Rate-limit response headers conforms: partial evidence: >- X-RateLimit-Limit / -Remaining / -Reset plus X-Concurrency-Limit / -Remaining and Retry-After are published and returned on all responses. These are the X- draft-era header names, not the IETF RateLimit / RateLimit-Policy fields; and the values are per-pod while the documented limits are cluster-wide, so a client that trusts the header under-uses its quota by 4x. source: https://apidocs.mediamath.com/guides/api-rate-limiting - id: openapi name: OpenAPI 3.0 conforms: true evidence: 44 OpenAPI 3.0.0 documents covering 353 operations across nine published APIs. - id: mcp name: Model Context Protocol conforms: true evidence: >- A live MCP server at https://apidocs.mediamath.com/mcp answered initialize with protocolVersion 2025-06-18 and tools/list with six tools carrying JSON Schema inputSchema and MCP tool annotations (readOnlyHint / destructiveHint / idempotentHint / openWorldHint). A second MCP server, the Infillion Agent Connector, is in closed beta with 69 documented tools and MCP App UI resources. see: mcp/mediamath-mcp.yml - id: a2a name: A2A Agent Card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json probed on apidocs.mediamath.com, api.mediamath.com, www.mediamath.com, platform.mediamath.com and infillion.com. All either 404 or returned an HTML SPA shell. No agent card is served. - id: asyncapi name: AsyncAPI conforms: false evidence: >- No AsyncAPI document is published. An event surface DOES exist — Custom Bid Router win notifications are delivered as HTTPS callbacks with a published protobuf schema — but it is described in prose and a .proto file only. see: asyncapi/mediamath-webhooks.yml - id: protobuf name: Protocol Buffers conforms: true evidence: >- proto2 WinNotification message published in MediaMath/bid-valuator-endpoint-java alongside a vendored google/openrtb/openrtb.proto. Custom Bid Router accepts Content-Type application/protobuf for bid requests and win notices. see: grpc/mediamath-winnotice.proto - id: openrtb name: IAB OpenRTB conforms: true evidence: >- Custom Bid Router bid requests follow OpenRTB; the reference endpoint implementation vendors google/openrtb/openrtb.proto. source: https://apidocs.mediamath.com/guides/byoa/custom-bid-router/about - id: iab-taxonomy name: IAB content taxonomy / attributes conforms: true evidence: >- Video Creatives API exposes /static_data/v1.0/iab_attributes and /static_data/v1.0/iab_verticals reference collections. source: openapi/mediamath-video-creatives-api-openapi.yml - id: vast name: IAB VAST conforms: true evidence: >- Video Creatives API exposes POST /video/v2.0/creatives/validateVAST and a Get-Video-creative-VAST-XML operation. source: openapi/mediamath-video-creatives-api-openapi.yml - id: mfa name: Multi-factor authentication conforms: true evidence: >- SMS and TOTP MFA supported on platform accounts; MFA posture is an entity-level attribute exposed through the API (agency and advertiser objects carry MFA inheritance settings, and mfa_fee_cpm appears on contracts). source: https://apidocs.mediamath.com/guides/security-best-practices - id: nist-password name: NIST SP 800-63B password guidance conforms: claimed evidence: >- Provider states its password policy follows NIST guidance. Self-asserted; not independently verifiable from the public surface. source: https://apidocs.mediamath.com/guides/security-best-practices - id: tls name: TLS transport security conforms: true evidence: >- HTTPS enforced on all API and docs hosts. TLS 1.3 on apidocs.mediamath.com, TLS 1.2 on api.mediamath.com. HSTS is NOT set on either. see: security/mediamath-domain-security.yml - id: gdpr name: GDPR / data-protection program conforms: unknown evidence: >- Infillion publishes a privacy policy at https://infillion.com/privacy-policy/ (HTTP 200) and MediaMath publishes an audience-data policy referenced from the Audience Segments docs. Neither was parsed for specific regulatory commitments during this pass. certifications: published: false probed: - url: https://trust.mediamath.com/ status: 000 - url: https://trust.infillion.com/ status: 000 - url: https://infillion.com/trust/ status: 404 - url: https://infillion.com/security/ status: 404 - url: https://infillion.com/compliance/ status: 404 note: >- No trust center and no named certification (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP) was found on any MediaMath or Infillion host. For an enterprise ad-tech platform handling audience data and processing spend on behalf of agencies, this is a conspicuous absence rather than evidence of absence — such attestations commonly exist but are shared only under NDA. Nothing is asserted here that was not observed.