generated: '2026-08-12' method: searched source: https://www.poptin.com/llms.txt sources: - https://www.poptin.com/llms.txt - https://www.poptin.com/gdpr/ - https://headwayapp.co/poptin-com-updates/poptin-is-is0-27001-compliant-279473 - live DNS/HTTP probes of poptin.com and app.popt.in on 2026-08-12 note: >- Assertions below are limited to what Poptin publishes or what was directly probed. Because Poptin ships no OpenAPI, no AsyncAPI and no GraphQL SDL, every API-shaped standard is recorded as conforms:false with the reason "no machine-readable contract to evaluate" rather than left unstated. conformance: - id: iso-27001 name: ISO/IEC 27001:2013 Information Security Management conforms: true basis: provider claim evidence: 'Certificate number 1122094, announced 2023-11-20 — https://headwayapp.co/poptin-com-updates/poptin-is-is0-27001-compliant-279473' - id: gdpr name: EU General Data Protection Regulation conforms: true basis: provider program page + published consent/retention/deletion capabilities evidence: https://www.poptin.com/gdpr/ - id: rfc-7208-spf name: SPF (Sender Policy Framework) conforms: true basis: probed evidence: 'DNS TXT on poptin.com — SPF record present (2026-08-12); see security/poptin-domain-security.yml' - id: rfc-7489-dmarc name: DMARC conforms: true basis: probed evidence: 'DNS TXT _dmarc.poptin.com — present, p=quarantine (2026-08-12)' - id: dkim name: DKIM conforms: true basis: provider claim evidence: '"DKIM support" listed under deliverability capabilities — https://www.poptin.com/llms.txt' - id: tls-1-3 name: TLS 1.3 conforms: true basis: probed evidence: 'TLSv1.3 negotiated on poptin.com (2026-08-12); see security/poptin-domain-security.yml' - id: hsts name: HTTP Strict Transport Security (RFC 6797) conforms: false basis: probed evidence: 'no Strict-Transport-Security header on poptin.com (2026-08-12)' - id: dnssec name: DNSSEC conforms: false basis: probed evidence: 'poptin.com is not DNSSEC-signed (2026-08-12)' - id: rfc-9116-security-txt name: security.txt conforms: false basis: probed evidence: '/.well-known/security.txt returned 404 on www.poptin.com and app.popt.in (2026-08-12)' - id: openapi name: OpenAPI Specification conforms: false basis: probed evidence: >- no spec at any candidate path on www.poptin.com or app.popt.in (/openapi.json, /swagger.json, /api-docs, /api all 404); no developer portal exists - id: asyncapi name: AsyncAPI Specification conforms: false basis: searched evidence: 'webhooks exist and are documented in prose only — see asyncapi/poptin-webhooks.yml' - id: graphql name: GraphQL conforms: false basis: probed evidence: no /graphql surface on any Poptin host - id: oauth2 name: OAuth 2.0 conforms: false basis: probed evidence: '/.well-known/oauth-authorization-server 404 on both hosts; no authorization endpoint published' - id: oidc name: OpenID Connect conforms: false basis: probed evidence: '/.well-known/openid-configuration 404 on both hosts' - id: rfc-9457-problem-details name: RFC 9457 Problem Details conforms: false basis: no machine-readable contract to evaluate - id: idempotency name: Idempotent request keys conforms: false basis: no machine-readable contract to evaluate, and no documented convention - id: rfc-8594-sunset name: RFC 8594 Sunset header / deprecation signaling conforms: false basis: no deprecation policy published — see lifecycle/poptin-lifecycle.yml