generated: '2026-08-14' method: searched source: https://mixrank.com/pricing standards: - id: standard-webhooks conforms: true evidence: >- MixRank's API documentation states webhook deliveries "follow Standard Webhooks", carrying Webhook-Id, Webhook-Timestamp and a Webhook-Signature formatted v1,.."> keyed with the caller's API key, "so any Standard Webhooks client can verify it". source: https://mixrank.com/api/documentation ref: asyncapi/mixrank-webhooks.yml - id: rfc9116-security-txt conforms: false evidence: >- /.well-known/security.txt returns 404 on both mixrank.com and api.mixrank.com. The Terms of Service additionally prohibit licensees from conducting security or vulnerability tests on the platform, so there is no coordinated-disclosure surface to record. ref: well-known/mixrank-well-known.yml - id: rfc8615-well-known conforms: false evidence: Every probed /.well-known/ path returns 404 on both hosts. ref: well-known/mixrank-well-known.yml - id: asyncapi conforms: false evidence: >- No AsyncAPI document is published (/asyncapi.yaml and /asyncapi.json 404 on both hosts) even though a real webhook surface exists. - id: gdpr conforms: true evidence: MixRank states it is "fully GDPR and CCPA compliant" on its pricing/data pages. source: https://mixrank.com/pricing - id: ccpa conforms: true evidence: MixRank states it is "fully GDPR and CCPA compliant". source: https://mixrank.com/pricing - id: oauth2 conforms: false evidence: Authentication is via an API key in the URL path; no OAuth surface. - id: rfc9457-problem-details conforms: false evidence: Errors use a custom JSON envelope with an "errors" field, not application/problem+json. - id: json-api conforms: false evidence: Responses are plain JSON, not JSON:API structured. compliance_programs: - name: GDPR published: true url: https://mixrank.com/privacy-policy/ - name: CCPA published: true url: https://mixrank.com/privacy-policy/