generated: '2026-08-26' method: searched source: https://www.scriptainsights.com/security summary: >- Scripta Insights publishes its security, privacy and compliance posture as prose on a single public page. It claims HIPAA compliance and a SOC 2 attestation (AICPA SOC badge), and describes encryption at rest and in transit, anti-virus, vulnerability scanning, periodic penetration testing, formal access management, secure SDLC and a dedicated product security incident response team. No machine-readable contract is published, so no standards conformance can be asserted from a spec — every entry below is either a documented claim or an honest false. sector: healthcare regulatory_regime: hipaa compliance: - id: hipaa conforms: true evidence: type: docs-claim url: https://www.scriptainsights.com/security quote: HIPAA Compliant (badge displayed on the Security page) note: >- Consistent with the business model — Scripta ingests pharmacy claims and eligibility feeds from PBMs on behalf of self-insured plan sponsors, which is PHI. - id: soc2 conforms: true evidence: type: docs-claim url: https://www.scriptainsights.com/security quote: AICPA SOC badge displayed on the Security page note: >- The page displays the AICPA SOC mark but does not state Type I vs Type II, the trust services criteria in scope, the audit period, or the auditor, and does not offer the report under NDA through a trust portal. Recorded as a claim, not a verified report. - id: iso-27001 conforms: false evidence: type: absent url: https://www.scriptainsights.com/security note: Not claimed anywhere on the public site. - id: hitrust conforms: false evidence: type: absent url: https://www.scriptainsights.com/security note: Not claimed. HITRUST CSF is the common certification among PBM-adjacent vendors; its absence is notable for this sector. - id: pci-dss conforms: false evidence: type: absent url: https://www.scriptainsights.com/security note: Not claimed; Scripta does not appear to process card payments directly. - id: ccpa-cpra conforms: true evidence: type: docs-claim url: https://www.scriptainsights.com/california-privacy note: A dedicated California privacy notice is published (HTTP 200). standards: - id: oauth2 conforms: false evidence: type: probe url: https://members.scriptainsights.com/.well-known/oauth-authorization-server status: 200 note: >- HTTP 200 but the body is the member portal's 8,041-byte SPA HTML shell, not authorization-server metadata. No OAuth 2.0 metadata is published on any host. - id: oidc conforms: false evidence: type: probe url: https://www.scriptainsights.com/.well-known/openid-configuration status: 400 - id: rfc9116-security-txt conforms: false evidence: type: probe url: https://www.scriptainsights.com/.well-known/security.txt status: 400 note: >- A security contact and a responsible vulnerability disclosure policy exist in prose; they are simply not published in the RFC 9116 machine-readable form. - id: rfc9457-problem-details conforms: false evidence: type: absent note: No public API contract, so no error envelope is observable. - id: mcp conforms: true evidence: type: probe url: https://www.scriptainsights.com/_api/mcp status: 200 note: >- JSON-RPC 2.0 initialize returned protocolVersion 2025-06-18 and tools/list returned nine tools with inputSchema, unauthenticated. Platform-authored (Wix Site MCP), not Scripta-authored — see mcp/scripta-insights-mcp.yml. - id: llms-txt conforms: true evidence: type: probe url: https://www.scriptainsights.com/llms.txt status: 200 note: Served as text/plain, 3,174 bytes. Auto-generated by Wix, not hand-authored by Scripta. - id: a2a-agent-card conforms: false evidence: type: probe url: https://www.scriptainsights.com/.well-known/agent-card.json status: 400 domain_standards: note: >- REWARD-ONLY. Scripta's market — pharmacy benefits — has real domain standards that a contract could declare: NCPDP SCRIPT and NCPDP Telecommunication D.0 for e-prescribing and pharmacy claims, X12 835/837 for claims and remittance, X12 834 for benefit enrollment and eligibility maintenance, and HL7 FHIR R4 (US Core, Da Vinci PDex formulary) for EHR and formulary exchange. Scripta's own technology page describes ingesting monthly claims and eligibility feeds from PBMs and integrating with EHR and pharmacy systems, which is exactly the surface these standards cover. declared: [] evidence: url: https://www.scriptainsights.com/technology status: 200 note: >- NO domain standard is declared anywhere publicly — not in a contract, and not in prose. Scripta publishes no machine-readable contract at all, so there is nothing to inspect for an NCPDP, X12 or FHIR signature. Recorded as absent, not as failing.