generated: '2026-08-04' method: searched source: https://movableink.com/privacy-security-and-compliance name: Movable Ink Standards and Compliance Conformance description: >- What Movable Ink asserts conformance to, and what was independently observable from its live surfaces. Certification claims come from Movable Ink's own Privacy, Security and Compliance page and Trust Center; protocol conformance comes from probing the identity tenant and the Customer Data API collector. standards: - id: iso-27001 name: ISO/IEC 27001 — Information Security Management Systems conforms: true kind: certification evidence: >- "Movable Ink is certified under ISO 27001 (Information Security Management Systems)" — https://movableink.com/privacy-security-and-compliance - id: iso-27701 name: ISO/IEC 27701 — Privacy Information Management Systems conforms: true kind: certification evidence: >- Named alongside ISO 27001 on https://movableink.com/privacy-security-and-compliance - id: iso-42001 name: ISO/IEC 42001 — AI Management System conforms: true kind: certification evidence: >- https://movableink.com/blog/movable-ink-achieves-iso-4200-certification-building-trust-in-the-age-of-ai and https://movableink.com/privacy-security-and-compliance - id: soc2-type-ii name: SOC 2 Type II conforms: true kind: audit scope: Movable Ink Studio and Da Vinci trust_criteria: [security, availability, confidentiality] cadence: annual evidence: >- "Movable Ink Studio and Da Vinci undergo an annual SOC 2 Type II audit conducted by an accredited independent auditor" — https://movableink.com/privacy-security-and-compliance report_access: Request via the Trust Center (https://trust.movableink.com/) - id: gdpr name: EU General Data Protection Regulation conforms: true kind: regulation role: data processor evidence: https://movableink.com/gdpr-commitment - id: ccpa name: California Consumer Privacy Act conforms: true kind: regulation evidence: https://movableink.com/ccpa-commitment - id: eu-us-dpf name: EU-U.S. Data Privacy Framework (incl. UK Extension and Swiss-U.S. DPF) conforms: true kind: certification evidence: https://movableink.com/privacy-security-and-compliance - id: sccs name: Standard Contractual Clauses conforms: true kind: contractual evidence: https://movableink.com/privacy-security-and-compliance - id: pen-test name: Annual independent application and network penetration testing conforms: true kind: assurance evidence: https://movableink.com/privacy-security-and-compliance - id: oidc-core name: OpenID Connect Core 1.0 conforms: true kind: protocol evidence: >- Discovery document served at https://auth.movableink.com/.well-known/openid-configuration (HTTP 200), advertising authorization, token, userinfo and JWKS endpoints. - id: oidc-discovery name: OpenID Connect Discovery 1.0 conforms: true kind: protocol evidence: https://auth.movableink.com/.well-known/openid-configuration (200) - id: rfc8414 name: RFC 8414 — OAuth 2.0 Authorization Server Metadata conforms: true kind: protocol evidence: >- https://auth.movableink.com/.well-known/oauth-authorization-server (200), byte-identical to the OIDC discovery document. - id: rfc7636 name: RFC 7636 — PKCE conforms: true kind: protocol evidence: 'code_challenge_methods_supported: ["S256", "plain"] in the discovery document' - id: rfc7009 name: RFC 7009 — OAuth 2.0 Token Revocation conforms: true kind: protocol evidence: 'revocation_endpoint: https://auth.movableink.com/oauth/revoke' - id: rfc8628 name: RFC 8628 — OAuth 2.0 Device Authorization Grant conforms: true kind: protocol evidence: 'device_authorization_endpoint: https://auth.movableink.com/oauth/device/code' - id: rfc7591 name: RFC 7591 — OAuth 2.0 Dynamic Client Registration conforms: true kind: protocol evidence: 'registration_endpoint: https://auth.movableink.com/oidc/register' - id: rfc7617 name: RFC 7617 — HTTP Basic Authentication conforms: true kind: protocol scope: Customer Data API evidence: >- Basic Authorization header documented by every downstream connector (Braze, Segment, Tealium, MetaRouter, Bloomreach). - id: rfc9457 name: RFC 9457 — Problem Details for HTTP APIs conforms: false kind: protocol evidence: >- The Customer Data API collector returns a bespoke {"message": ..., "request_id": ...} envelope with Content-Type application/json, not application/problem+json. Probed https://collector.movableink-dmz.com/behavioral/testkey → 404. - id: openapi name: OpenAPI Specification conforms: false kind: contract evidence: >- No OpenAPI/Swagger document found on any Movable Ink host. Probed /openapi.json, /openapi.yaml, /swagger.json, /docs, /api-docs on movableink.com, collector.movableink-dmz.com, sdk-mobile.movableink.com, app.movableink.com and auth.movableink.com — all 404 or an HTML shell. - id: asyncapi name: AsyncAPI Specification conforms: false kind: contract evidence: No AsyncAPI document published; no public event catalog. - id: rfc9116 name: RFC 9116 — security.txt conforms: false kind: protocol evidence: /.well-known/security.txt returns 404 on every Movable Ink host. - id: rfc9727 name: RFC 9727 — /.well-known/api-catalog conforms: false kind: protocol evidence: 404 on movableink.com and auth.movableink.com. - id: a2a name: A2A Agent Card conforms: false kind: protocol evidence: >- /.well-known/agent-card.json and /.well-known/agent.json 404 on every host probed. - id: llms-txt name: llms.txt conforms: true kind: convention evidence: https://movableink.com/llms.txt (200, text/plain) — saved verbatim to llms/ x-evidence: fetched: '2026-08-04' probes: - url: https://movableink.com/privacy-security-and-compliance status: 200 - url: https://trust.movableink.com/ status: 200 - url: https://auth.movableink.com/.well-known/openid-configuration status: 200 - url: https://movableink.com/llms.txt status: 200 - url: https://collector.movableink-dmz.com/openapi.json status: 404