generated: '2026-08-02' method: searched source: https://www.pingcap.com/trust-hub/ + published OpenAPI/Swagger documents standards: - id: openapi-2.0 conforms: true evidence: Six TiDB Cloud specs are Swagger 2.0 documents published at docs-download.pingcap.com. - id: openapi-3.0 conforms: true evidence: TiDB DM ships OpenAPI 3.0.0; OSS Insight ships OpenAPI 3.0.3; TiDB Cloud Data Service generates OpenAPI 3.0 per Data App. - id: rest conforms: true evidence: Resource-oriented JSON over HTTPS. - id: rfc7616-http-digest conforms: true evidence: All TiDB Cloud API requests authenticate with HTTP Digest Authentication (RFC 7616). - id: google-aip conforms: true evidence: 'v1beta1 services are gRPC-transcoded Google API style: relative resource names, pageSize/pageToken, updateMask field masks, colon-suffixed custom methods, google.rpc.Status errors.' - id: oauth2 conforms: false evidence: No oauth2 securityScheme in any spec; OAuth 2.0 is offered for console sign-in only, not for API calls. - id: oidc conforms: false evidence: No /.well-known/openid-configuration on any host. - id: rfc9457-problem-details conforms: false evidence: Errors use google.rpc.Status ({code,message,details}) with application/json, not application/problem+json. - id: rfc8594-sunset conforms: false evidence: No Sunset/Deprecation headers documented. - id: rfc9116-security-txt conforms: false evidence: No /.well-known/security.txt on any PingCAP host, although a disclosure policy and security@pingcap.com are published. - id: asyncapi conforms: false evidence: No event/webhook contract published. - id: mcp conforms: true evidence: Official TiDB MCP Server maintained by PingCAP, shipped in pytidb, stdio and SSE transports. - id: a2a conforms: false evidence: No /.well-known/agent-card.json or /.well-known/agent.json on any PingCAP or TiDB Cloud host (probed 2026-08-02). - id: llmstxt conforms: true evidence: https://www.pingcap.com/llms.txt and https://docs.pingcap.com/llms.txt both return 200, with per-product llms.txt files linked beneath the docs root. - id: mysql-protocol conforms: true evidence: TiDB is wire-compatible with the MySQL protocol; standard MySQL clients and drivers connect directly. compliance: published: true url: https://www.pingcap.com/trust-hub/ certifications: - ISO 27001 - ISO 27701 - SOC 2 - PCI DSS - GDPR - HIPAA - EU-US Data Privacy Framework note: Named on the public PingCAP Trust Hub, which states PingCAP conducts regular third-party audits against SOC 2 and PCI-DSS. SOC 2 type designation is not stated publicly; audit reports are available on request through PingCAP contact channels. sub_processors: https://www.pingcap.com/legal/sub-processors-and-affiliates-for-tidb-cloud-services/ dpa: https://www.pingcap.com/legal/data-processing-agreement-for-tidb-cloud-services/