generated: '2026-08-13' method: searched source: >- https://ortto.com/security-privacy/, https://ortto.com/gdpr/, https://ortto.com/dpf/, https://help.ortto.com/a-57-privacy-security-and-gdpr, https://help.ortto.com/a-714-api-error-responses, https://help.ortto.com/a-235-rate-limits, https://help.ortto.com/a-258-retrieve-one-or-more-people-get, https://ortto.com/.well-known/security.txt, derived against openapi/*.yml description: >- What Ortto conforms to, checked one standard at a time. The compliance story is stronger than the protocol story: Ortto states it is GDPR, CCPA, ISO 27001 and SOC 2 compliant, is an M3AAWG member, serves a real security.txt with a published bug-bounty rate table, and offers multi-region data residency. The HTTP surface, by contrast, adopts almost no cross-cutting web standards — no OAuth, no OpenID Connect, no RFC 9457 problem details, no RFC 9331 rate-limit headers, no RFC 8594 sunset headers, no conditional requests. The one modern agent standard it does implement is MCP, shipped as a hosted remote server in release 1.27. conformance: - id: oauth2 conforms: false evidence: >- Authentication is a single account-scoped API key in the X-Api-Key header. No authorization endpoint, no token endpoint, no scopes. Probed /.well-known/oauth-authorization-server on ortto.com (404) and on mcp-api-us.ortto.app (403). - id: oidc conforms: false evidence: >- /.well-known/openid-configuration returns 404 on ortto.com. Ortto supports SSO and Okta for app login, but publishes no OIDC discovery document for API consumers. - id: mcp conforms: true evidence: >- First-party hosted MCP server released in version 1.27 (2025-12-19) with three regional endpoints and 20 documented tools; help-center category c-332. Hosts probed live 2026-08-13 (403 unauthenticated, awselb). Protocol version could not be confirmed anonymously. partial: true see_also: mcp/ortto-mcp.yml - id: a2a conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json return 404 on ortto.com and help.ortto.com and 403 on the API and MCP hosts. No agent card is served. - id: rfc9457 conforms: false evidence: >- Errors are returned as vendor JSON (request_id/code/error observed live; the documented rate-limit body uses error code + message + try-in-seconds). No application/problem+json media type appears in the docs or the spec. see_also: errors/ortto-problem-types.yml - id: rfc9331-ratelimit-headers conforms: false evidence: >- The rate-limit reference documents no RateLimit-* or X-RateLimit-* response headers and no Retry-After; retry timing is carried in the 429 JSON body as try-in-seconds. see_also: rate-limits/ortto-rate-limits.yml - id: rfc8594-sunset conforms: false evidence: >- No deprecation policy, Sunset header or Deprecation header is published; no operation in openapi/*.yml is marked deprecated. see_also: lifecycle/ortto-lifecycle.yml - id: idempotency conforms: false evidence: >- No Idempotency-Key header is documented. Merge operations are idempotent on the configured merge_by key by design, but activity creation and transactional sends are not, and Ortto instructs webhook consumers to de-duplicate on campaign_id + contact_id + run_id. partial: true see_also: conventions/ortto-conventions.yml - id: pagination conforms: true evidence: >- Offset pagination with limit (default 50, max 500), offset, and an optional cursor_id, plus has_more / next_offset / meta totals in the response envelope. Documented at help.ortto.com/a-258. partial: true note: Consistent and documented, but a vendor convention rather than a standard. - id: openapi conforms: false evidence: >- Ortto publishes no machine-readable OpenAPI. Probed /openapi.json, /openapi.yaml, /swagger.json, /api-docs, /docs and /redoc on api.ap3api.com (403 from the gateway), ortto.com (404 SPA shell) and help.ortto.com (404). The specs in openapi/ are scaffolded by API Evangelist from the published help-center reference. - id: asyncapi conforms: false evidence: >- No AsyncAPI document. The event surface is outbound webhooks configured in-product, unsigned and undocumented as a machine-readable catalog. see_also: asyncapi/ortto-webhooks.yml - id: graphql conforms: false evidence: No GraphQL endpoint is published or documented. - id: soc2 conforms: true evidence: >- "We are GDPR, CCPA, ISO27001^ and SOC2 compliant" — https://ortto.com/security-privacy/. Ortto states audit reports are available on request; no report or trust portal is published for self-service download. self_asserted: true - id: iso27001 conforms: true evidence: >- Named in the same compliance statement at https://ortto.com/security-privacy/, carrying a footnote marker. self_asserted: true - id: gdpr conforms: true evidence: >- Dedicated GDPR page at https://ortto.com/gdpr/, cookie-tracking opt-in in the tracking code (gdpr.hasConsentGiven option), EU data residency and an EU API endpoint. - id: ccpa conforms: true evidence: Named at https://ortto.com/security-privacy/. self_asserted: true - id: eu-us-data-privacy-framework conforms: true evidence: Ortto publishes a Data Privacy Framework page at https://ortto.com/dpf/. - id: hipaa conforms: false evidence: >- Not claimed. Ortto markets a healthcare solutions page but names no HIPAA program or BAA on its security page. - id: pci-dss conforms: false evidence: Not claimed; Ortto does not process cardholder data through its API. - id: fedramp conforms: false evidence: Not claimed. - id: security-txt conforms: true evidence: >- https://ortto.com/.well-known/security.txt returns 200 text/plain with Contact, Expires, Preferred-Languages, Canonical and three Policy entries, plus a commented bug-bounty rate table (2024-03-15). see_also: well-known/ortto-well-known.yml - id: m3aawg conforms: true evidence: >- "a member of anti-abuse organization M3AAWG" — https://ortto.com/security-privacy/; also announced 2024-12-20 on the Ortto blog. - id: data-residency conforms: true evidence: >- Multi-region hosting (EU, USA, Australia, Asia) with matching API endpoints api.eu.ap3api.com and api.au.ap3api.com and matching MCP endpoints. summary: checked: 23 conforms: 10 partial: 3 does_not_conform: 13 compliance_certifications_named: - SOC 2 - ISO 27001 - GDPR - CCPA - EU-US Data Privacy Framework