generated: '2026-08-12' method: searched source: >- https://skyvia.com/security + openapi/_original/skyvia-public-api-openapi-original.json + live probes of api.skyvia.com and mcp.skyvia.com + security/skyvia-domain-security.yml summary: >- Skyvia's conformance profile splits cleanly. On the COMPLIANCE side it is strong and independently attested — SOC 2 with audited controls, plus HIPAA, PCI DSS and GDPR posture published on its security page. On the TECHNICAL STANDARDS side it is thin: no OAuth, no OIDC, no RFC 9457 errors, no /.well-known discovery, no AsyncAPI. The two standards it does implement well are OData v4 (the entire Connect product) and MCP (the Connect MCP endpoint, though at a protocol revision several versions behind current). standards: - id: openapi-3.0 conforms: true evidence: >- OpenAPI 3.0.1 document served publicly and unauthenticated at https://api.skyvia.com/swagger/v1/swagger.json (also .yaml), 47 paths / 52 operations, generated by Swashbuckle. quality_note: >- Valid but thin — no servers[] block, no operationIds on any operation, summaries on only 12 of 52 operations, no descriptions, no examples, and no 4xx/5xx responses declared anywhere. - id: odata-v4 conforms: true evidence: >- Skyvia Connect publishes any connection as an OData v4 service consumable from Power BI, Excel, Tableau and generic OData clients. Documented at https://docs.skyvia.com/connect/odata-endpoints/. - id: mcp conforms: true version: '2024-11-05' evidence: >- Live MCP server at https://mcp.skyvia.com/mcp answering initialize and tools/list over streamable HTTP (legacy /sse also served), advertising four tools with JSON Schema inputSchema blocks. deviations: - Protocol version 2024-11-05, several revisions behind the current MCP specification. - Non-standard `execution.taskSupport` and `_meta.category` keys on tool objects. - No MCP OAuth — neither /.well-known/oauth-authorization-server nor /.well-known/oauth-protected-resource is served (both 404). - id: json-schema conforms: true evidence: MCP tool inputSchema blocks are JSON Schema; OpenAPI components.schemas carries 45 schemas. - id: oauth2 conforms: false evidence: >- No OAuth 2.0 anywhere. The Public API uses an opaque apiKey token in the Authorization header; Connect endpoints use optional HTTP Basic. No authorization-server metadata is served on any host. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns the marketing HTML shell on skyvia.com and 403 on api.skyvia.com. - id: rfc9457-problem-details conforms: false evidence: >- Errors use a proprietary {errorCode, errors, message, refresh} envelope with content-type application/json, not application/problem+json. See errors/skyvia-problem-types.yml. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns the marketing homepage HTML (soft-404) on skyvia.com and 403 on api.skyvia.com. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header support and no deprecation policy. See lifecycle/skyvia-lifecycle.yml. - id: rfc8615-well-known conforms: false evidence: No /.well-known document is served on any host. See well-known/skyvia-well-known.yml. - id: asyncapi conforms: false evidence: No AsyncAPI document; no outbound event surface. See asyncapi/skyvia-automation-webhooks.yml. - id: a2a conforms: false evidence: >- No agent card at /.well-known/agent-card.json or /.well-known/agent.json on any host — skyvia.com answers 200 with the homepage HTML shell (a soft-404, not a card), api.skyvia.com 403s, mcp.skyvia.com and docs.skyvia.com 404. - id: idempotency conforms: false evidence: No Idempotency-Key header or parameter in the spec and no idempotency guidance in the docs. See conventions/skyvia-conventions.yml. - id: llms-txt conforms: true evidence: https://skyvia.com/llms.txt returns 200 text/plain with a compliant llms.txt structure (H1, blockquote summary, annotated link list, llms-full.txt reference). - id: hmac-sha256-webhook-signing conforms: true partial: true evidence: >- Automation webhook triggers support SHA256 HMAC payload verification against a user-supplied secret. Partial because the signature header name is customer-configured rather than a fixed convention, so there is nothing interoperable to code against. - id: tls-1.3 conforms: partial evidence: >- skyvia.com and docs.skyvia.com negotiate TLSv1.3; api.skyvia.com negotiates only TLSv1.2. Probed 2026-08-12, see security/skyvia-domain-security.yml. - id: hsts conforms: partial evidence: skyvia.com sends HSTS with max-age 31536000; docs.skyvia.com does not; api.skyvia.com did not return one on probe. - id: dnssec conforms: true evidence: skyvia.com is DNSSEC-signed (probed 2026-08-12). - id: dmarc conforms: true evidence: SPF present and DMARC published with policy p=reject (probed 2026-08-12). - id: caa conforms: false evidence: No CAA records on skyvia.com (probed 2026-08-12). compliance_program: published: true url: https://skyvia.com/security certifications: - name: SOC 2 status: certified quote: >- "Skyvia is SOC 2 certified, with independently audited controls covering access management, data protection, system monitoring, and infrastructure security." - name: HIPAA status: compliant quote: '"Skyvia complies with HIPAA requirements for Protected Health Information (PHI)"' - name: PCI DSS status: compliant quote: '"Skyvia is PCI DSS-compliant"' note: Payments are handled by the third party 2Checkout. - name: GDPR status: compliant quote: '"Skyvia complies with the European Union''s Global Data Protection Regulation (GDPR)"' - name: ISO 27001 status: inherited note: >- Cited as a standard met by the underlying Microsoft Azure infrastructure, not claimed as a Skyvia certification. Recorded as inherited rather than held. encryption: at_rest: AES 256-bit, with unique keys per user; connection credentials encrypted with AES 256-bit in_transit: TLS end-to-end, keys of at least 128 bits hosting: Microsoft Azure, west US data centers access_control: Firewall and routing rules; access restricted to authorized personnel see: security/skyvia-trust-center.yml gaps: - No vulnerability disclosure policy, bug bounty, or published security contact — only a general support address. - No penetration-testing statement. - No trust portal with downloadable evidence; the security page is prose.