generated: '2026-08-13' method: searched source: >- openapi/talkable-v2-openapi-original.yml + well-known/ + https://docs.talkable.com/mcp_server/ + https://www.talkable.com/talkable-features compliance: published: true page: https://www.talkable.com/talkable-features certifications: - name: SOC 2 claim: 'Talkable''s campaigns "are SOC II certified".' published_as: SOC II evidence_url: https://www.talkable.com/talkable-features note: >- Claimed in prose on Talkable's own Features page under "Protect Your Data". No SOC 2 report, audit date, type (I vs II), or auditor is published, and Talkable operates no trust center or compliance portal — probed trust.talkable.com (no DNS), /security (404), /security-compliance (404). Recorded as a published claim, not as a verified certificate. regulations: - name: GDPR claim: Talkable campaigns "can be made GDPR and CCPA compliant". evidence_url: https://www.talkable.com/talkable-features note: >- Conditional, not absolute — the compliance posture is a property of how the merchant configures the campaign, and Talkable says so. - name: CCPA claim: Talkable campaigns "can be made GDPR and CCPA compliant". evidence_url: https://www.talkable.com/talkable-features data_residency: United States ("data hosted in the USA") api_support: - operation: getPersonalInformationAboutPerson supports: GDPR/CCPA subject access request - operation: anonymizePerson supports: GDPR/CCPA right to erasure - operation: unsubscribePerson supports: consent withdrawal api_support_note: >- The REST API v2 carries first-class privacy operations, which is the strongest machine-readable evidence of the privacy posture claimed on the marketing page. standards: - id: oauth2 conforms: true evidence: MCP server uses OAuth 2.1 authorization/token endpoints (well-known/talkable-oauth-authorization-server.json). - id: oauth2.1-pkce conforms: true evidence: code_challenge_methods_supported = [S256]; interactive clients use PKCE. - id: rfc7591-dynamic-client-registration conforms: true evidence: registration_endpoint https://www.talkable.com/oauth/register advertised. - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: /.well-known/oauth-authorization-server returns 200 with issuer/endpoints. - id: rfc9728-oauth-protected-resource-metadata conforms: true evidence: /.well-known/oauth-protected-resource returns 200 with resource + authorization_servers. - id: model-context-protocol conforms: true evidence: Published hosted MCP server over streamable HTTP at https://www.talkable.com/mcp. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404. - id: rfc9457-problem-details conforms: false evidence: Errors use an ok/error_message envelope, not application/problem+json. - id: pagination conforms: true evidence: Collection endpoints use page/per_page query parameters. - id: idempotency conforms: false evidence: No idempotency-key header documented for REST API v2. - id: bearer-token-auth conforms: true evidence: REST API v2 securityScheme api_key (http bearer).