generated: '2026-08-13' method: searched source: >- https://www.reviewtrackers.com/terms-service/security/ plus live probes of https://api.reviewtrackers.com/ on 2026-08-13 name: ReviewTrackers Standards Conformance and Compliance description: >- Which cross-cutting standards the ReviewTrackers API conforms to, and which compliance commitments the company itself publishes. An important distinction is recorded below: the SOC 2 / ISO 27001 / PCI DSS / FedRAMP list on the ReviewTrackers security page describes AWS INFRASTRUCTURE certifications, not ReviewTrackers' own audited certifications. ReviewTrackers' own published commitments are HIPAA (BAA available) and GDPR (DPA available). standards: - id: http-basic-auth conforms: true evidence: 'WWW-Authenticate: Basic realm="rtx:production" on every protected resource' - id: hal-json conforms: true evidence: Responses served as application/hal+json and application/vnd.rtx.*.hal+json - id: oauth2 conforms: false evidence: No oauth2 scheme observed; no /.well-known/oauth-authorization-server (404) - id: oidc conforms: false evidence: No /.well-known/openid-configuration on any host (404) - id: rfc9457-problem-details conforms: false evidence: Errors use a flat {status, error} envelope on a vendored HAL media type, not application/problem+json - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on every host, though a bug bounty policy is published as HTML - id: rfc8615-well-known conforms: false evidence: No /.well-known/ document is served by any host - id: openapi conforms: false evidence: No OpenAPI/Swagger document found on any host; developer portal is HTTP Basic gated - id: asyncapi conforms: false evidence: Webhook resource exists at /webhooks but no AsyncAPI document is published - id: a2a conforms: false evidence: No agent card at /.well-known/agent-card.json or /.well-known/agent.json on any host - id: mcp conforms: false evidence: No hosted MCP server found - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header observed; no published deprecation policy compliance: published: true page: https://www.reviewtrackers.com/terms-service/security/ first_party: - name: HIPAA status: BAA executed on request url: https://www.reviewtrackers.com/terms-service/hipaa-business-associate-agreement/ - name: GDPR status: Data Processing Addendum published url: https://www.reviewtrackers.com/terms-service/gdpr-data-processing-addendum/ infrastructure_inherited: note: >- Listed by ReviewTrackers as certifications of the AWS cloud infrastructure it runs on, NOT as ReviewTrackers audit results. Recorded verbatim and labelled so they are not misread as first-party certifications. provider: Amazon Web Services certifications: - SOC 1 / SSAE 16 / ISAE 3402 - SOC 2 - SOC 3 - PCI DSS Level 1 - ISO 27001 - FedRAMP - DIACAP and FISMA - ITAR - FIPS 140-2 - CSA - MPAA - HIPAA assurance: - Annual third-party penetration testing (certificate on request) - Daily comprehensive security scanning with alerting - Bug bounty program with monetary awards payment_processing: processor: Stripe note: Card data is handled by Stripe (PCI Level 1); ReviewTrackers does not store card data. data_residency: United States (AWS) gaps_for_provider: - No first-party SOC 2 Type II or ISO 27001 certification is claimed for ReviewTrackers itself. - No trust center portal; the security posture is a single FAQ page.