generated: '2026-08-13' method: searched source: https://help.passionfroot.me/en/articles/13490633-security-data-processing note: >- Assessed entirely from what Passionfroot publishes about itself — there is no OpenAPI, no GraphQL and no AsyncAPI in this repo to derive protocol conformance from. Two of the entries below are NEGATIVE and they are the most useful rows here: Passionfroot states in its own help centre that it holds neither ISO 27001 nor SOC 2, and that it supports no two-factor authentication. Recording a published "we are not certified" is data, not a gap in our research. standards: - id: gdpr conforms: true evidence: >- "Passionfroot is based in Germany (EU) and complies with the GDPR framework, as a Data Controller." — help centre, GDPR & Passionfroot. Data encrypted and stored in Germany (EU); privacy policy documents collection, retention, transfers and subject rights. source: https://help.passionfroot.me/en/articles/11570259-gdpr-passionfroot - id: iso-27001 conforms: false evidence: >- "At this time, Passionfroot does not hold formal security certifications such as ISO 27001 or SOC 2." — help centre, Security & Data Processing. source: https://help.passionfroot.me/en/articles/13490633-security-data-processing - id: soc2 conforms: false evidence: same provider statement as iso-27001 — explicitly not certified source: https://help.passionfroot.me/en/articles/13490633-security-data-processing - id: mfa-2fa conforms: false evidence: >- "Currently, Passionfroot supports authentication via username and password only. Two-factor authentication (2FA) is not available at this time." — help centre. source: https://help.passionfroot.me/en/articles/13490633-security-data-processing - id: mcp conforms: true evidence: >- First-party @passionfroot/postgres-mcp implements the Model Context Protocol on @modelcontextprotocol/sdk ^1.30.0, serving stdio and Streamable HTTP transports with tools and a resource. Scope: the operator's own Postgres, not the Passionfroot platform. source: https://github.com/Passionfroot/postgres-mcp - id: oauth2 conforms: false evidence: no public API and no documented OAuth surface - id: openid-connect conforms: false evidence: /.well-known/openid-configuration 404s on every Passionfroot host - id: rfc9457-problem-details conforms: false evidence: no public API contract to evaluate - id: rfc9116-security-txt conforms: false evidence: >- /.well-known/security.txt 404s on www and workspace; the 200 on help.passionfroot.me is Intercom's file (Canonical app.intercom.com), not Passionfroot's. source: well-known/passionfroot-well-known.yml