generated: '2026-08-12' method: searched source: https://segmetrics.io/security/ docs: - https://segmetrics.io/security/ - https://segmetrics.io/dpa/ - https://segmetrics.io/subprocessors/ - https://developers.segmetrics.io/ note: >- Standards conformance assessed against what SegMetrics publishes. There is no OpenAPI to derive from, so every row below cites a page, not a spec construct. Where SegMetrics explicitly states it does NOT hold something (certifications, HIPAA/BAA), that is recorded as conforms: false with their own wording rather than left blank. standards: - id: mcp name: Model Context Protocol conforms: true evidence: >- Hosted remote MCP server documented at https://app.segmetrics.io/mcp/ACCOUNT_ID with 11 named tools and OAuth authorization; documented as working with "any AI tool that supports the Model Context Protocol". source: https://docs.segmetrics.io/article/672-mcp-server - id: oauth2 name: OAuth 2.0 conforms: partial evidence: >- OAuth is used to authorize the MCP connection, but no authorization/token endpoints, no scope reference, and no RFC 8414 or RFC 9728 metadata are published. Cannot be verified beyond the provider's description. source: https://docs.segmetrics.io/article/672-mcp-server - id: oidc name: OpenID Connect conforms: false evidence: /.well-known/openid-configuration returned 404 on every SegMetrics host. - id: rfc9457-problem-details name: RFC 9457 Problem Details conforms: false evidence: >- Errors use a proprietary {"status":"error","errors":[...]} envelope with no type URI and no application/problem+json media type. source: https://developers.segmetrics.io/#responses - id: rfc9116-security-txt name: RFC 9116 security.txt conforms: false evidence: /.well-known/security.txt returned 404 on every host, despite a published security contact. - id: rfc8594-sunset name: RFC 8594 Sunset header conforms: false evidence: No deprecation policy or Sunset/Deprecation header support is published. - id: rfc9116-rate-limit-headers name: RateLimit header fields conforms: false evidence: No rate-limit headers or 429 semantics documented. - id: openapi name: OpenAPI conforms: false evidence: >- No OpenAPI/Swagger document served at any probed path on segmetrics.io, api.segmetrics.io, import.segmetrics.io, app.segmetrics.io, docs.segmetrics.io or developers.segmetrics.io. The reference at developers.segmetrics.io is Slate-rendered prose (source repo github.com/SegMetrics/segmetrics-dev-docs). - id: asyncapi name: AsyncAPI conforms: false evidence: >- Not applicable — SegMetrics publishes no outbound event, streaming, or webhook surface. It is a data CONSUMER (customers push data in via the Import API or Zapier). No penalty is implied. - id: llmstxt name: llms.txt conforms: true evidence: >- https://segmetrics.io/llms.txt returns 200 with a real llms.txt document (auto-generated by Yoast SEO v27.0). It is a marketing site index, not a developer/API index — it does not reference developers.segmetrics.io or the MCP server. source: https://segmetrics.io/llms.txt - id: a2a name: A2A Agent Card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json returned 404 on every host (403 on the broken mcp.segmetrics.io). No card exists; none was authored. compliance: certifications: [] certifications_note: >- SegMetrics holds NO certifications of its own. Its own wording: "We rely on the attestations of our key infrastructure providers — the certifications each holds are listed alongside them in our subprocessor list." It responds to customer security questionnaires and vendor risk reviews on request via security@segmetrics.io. programs: - id: gdpr conforms: true evidence: >- Published Data Processing Agreement entered into pursuant to Article 28 of the EU GDPR, the UK GDPR and the UK Data Protection Act 2018. source: https://segmetrics.io/dpa/ - id: eu-standard-contractual-clauses conforms: true evidence: >- EU SCCs (Commission Implementing Decision (EU) 2021/914) Module 2 Controller-to-Processor incorporated by reference for EEA-to-third-country transfers, plus the UK International Data Transfer Addendum for UK transfers. source: https://segmetrics.io/dpa/ - id: hipaa conforms: false evidence: >- Stated verbatim — "The Platform is not currently configured to receive, store, or process Protected Health Information (PHI)... not currently operating as a HIPAA Business Associate and does not have any active Business Associate Agreements (BAAs) in place." source: https://segmetrics.io/security/ data_residency: United States encryption: in_transit: TLS 1.2 or higher; unencrypted HTTP not accepted on authenticated endpoints at_rest: AES-256 backups: encrypted, daily, rolling 30-day expiry subprocessors_url: https://segmetrics.io/subprocessors/ subprocessors: [DigitalOcean (NYC), AWS (Oregon), SingleStore (Oregon), Cloudflare, OpenAI] subprocessors_note: >- OpenAI is listed as a subprocessor for the optional AI Insights feature — relevant to any agent/AI data-flow review. x-evidence: fetched: '2026-08-12' sources: - {url: 'https://segmetrics.io/security/', status: 200} - {url: 'https://segmetrics.io/dpa/', status: 200} - {url: 'https://segmetrics.io/subprocessors/', status: 200} - {url: 'https://segmetrics.io/llms.txt', status: 200}