generated: '2026-08-13' method: searched source: >- https://rosetta.ai/privacy , https://rosetta.ai/terms , https://rosetta-ai.gitbook.io/help-center/ notes: >- Rosetta.ai publishes NO named security or privacy CERTIFICATION — no SOC 2, no ISO 27001, no PCI DSS attestation of its own, no HIPAA, no FedRAMP — and there is no trust centre (trust.rosetta.ai does not resolve) and no compliance page. What it does publish are regulatory-posture statements inside its privacy policy. Those are recorded below as claims with evidence, and NO `Compliance` pointer is emitted in apis.yml: a GDPR/CCPA section in a privacy policy is a statutory obligation every site carries, not a published compliance programme, and treating it as one would credit Rosetta.ai with an assurance posture it has not asserted. standards: [] regulatory: - id: gdpr conforms: claimed evidence: >- Privacy policy states "For the purpose of the GDPR, the Company is the Data Controller" and enumerates access, rectification, erasure and portability rights. source: https://rosetta.ai/privacy certification: none - id: ccpa conforms: claimed evidence: >- Privacy policy carries a California-residents supplement: "This privacy notice section for California residents supplements the information contained in Our Privacy Policy and it applies solely to all visitors, users, and others who reside in the State of California." source: https://rosetta.ai/privacy certification: none - id: pci-dss conforms: false evidence: >- The privacy policy references PCI DSS only as an attribute of THIRD-PARTY payment processors ("adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council"). This is not a Rosetta.ai attestation and must not be read as one. source: https://rosetta.ai/privacy certification: none api_standards: - id: oauth2 conforms: false evidence: No OAuth 2.0 anywhere; the API uses an opaque Bearer token. See authentication/. - id: oidc conforms: false evidence: /.well-known/openid-configuration 404s on every host. See well-known/. - id: rfc9457 conforms: false evidence: No application/problem+json and no published error contract. See conventions/. - id: rfc8594 conforms: false evidence: No Deprecation or Sunset headers observed; no deprecation policy published. - id: rfc9116 conforms: false evidence: /.well-known/security.txt 404s on every host. See well-known/. - id: json-api conforms: false evidence: >- Responses use a plain Laravel `{data: ...}` envelope, not the JSON:API media type or document structure. - id: openapi conforms: false evidence: >- No OpenAPI or Swagger document is published at any probed location on rosetta.ai, api.rosetta.ai, dashboard.rosetta.ai or the help-center host. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface is published. certifications: [] trust_center: null