generated: '2026-08-13' method: searched source: >- https://reputation.com/security-posture/ (HTTP 200), https://reputation.com/hipaa-compliance/ (HTTP 200), https://apidocs.reputation.com/ (HTTP 200), and openapi/_original/reputation-api-openapi.yml standards: - id: soc2-type-ii conforms: true evidence: >- "Reputation is SOC 2 Type II compliant, as attested by a third-party auditor." Report available under NDA on request. https://reputation.com/security-posture/ - id: iso-27001 conforms: true evidence: >- ISO 27001 certified and verified by a third-party auditor; certificate available under NDA on request. https://reputation.com/security-posture/ - id: hipaa conforms: true evidence: >- HIPAA compliant with a Business Associate Agreement available. https://reputation.com/hipaa-compliance/ - id: gdpr conforms: true evidence: >- GDPR compliance supported through geographically separated US and EU data regions, mirrored in the API by separate api.reputation.com / api-eu.reputation.com hosts. https://reputation.com/security-posture/ - id: glba-safeguards-rule conforms: true evidence: Gramm-Leach-Bliley Act Safeguards Rule controls applied for financial-services customers. - id: ccpa conforms: true evidence: Published CCPA compliance FAQ and data-protection request process. https://reputation.com/ccpa-compliance/ - id: pci-dss conforms: false evidence: Not claimed. Reputation processes no cardholder data through this API. - id: fedramp conforms: false evidence: Not claimed. - id: oauth2 conforms: false evidence: >- No oauth2 securityScheme in any OpenAPI. The single scheme is apiKey in header (X-API-KEY). GET /v3/credentials/oauth reports the OAuth status of connected third-party review sources — it is not an OAuth flow for the Reputation API itself. - id: oidc conforms: false evidence: No /.well-known/openid-configuration on any host (all 404, see well-known/reputation-well-known.yml). - id: rfc9457-problem-details conforms: false evidence: >- Errors use a vendor envelope { errors: [ { error: { field, code, message } } ] } served as application/json, not application/problem+json. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on all five Reputation hosts. - id: rfc8594-sunset-header conforms: false evidence: Endpoints are labelled "(Deprecated)" in prose only; no Sunset or Deprecation response header. - id: json-api conforms: false evidence: Plain JSON; no JSON:API document structure or media type. - id: odata conforms: false - id: scim2 conforms: false evidence: /v3/users is a proprietary user resource, not a SCIM 2.0 /Users endpoint. - id: fhir-r4 conforms: false evidence: Healthcare is a named vertical but the API exposes no FHIR resources. - id: pagination conforms: true evidence: >- Documented offset/limit request params with a `pagination` response object carrying offset/limit/next/previous; default limit 20. Newer endpoints accept a Base64 cursor in `offset`. - id: idempotency conforms: false evidence: No idempotency key or replay contract documented on any write operation. - id: tls-cipher-policy conforms: true evidence: A 15-cipher approved TLS cipher policy is published in the API overview at apidocs.reputation.com. compliance_program: published: true url: https://reputation.com/security-posture/ certifications: [SOC 2 Type II, ISO 27001, HIPAA, GDPR, GLBA Safeguards Rule, CCPA] third_party_pentest: at least annually by an independent third-party assessor encryption_at_rest: AES symmetric block cipher encryption_in_transit: TLS documents_under_nda: [SOC 2 Type II report, ISO 27001 certificate]