{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "iterable",
    "name": "Iterable",
    "vendor": "Iterable, Inc.",
    "vendorUrl": "https://iterable.com",
    "kind": "http-api",
    "category": "lifecycle-marketing",
    "summary": "Iterable is a hosted customer engagement platform that stores user profiles and events and sends campaigns and journeys by email, SMS, push, in-app and WhatsApp. Agents reach it through a REST API and an official local MCP server, in beta.",
    "url": "https://www.anchorterminal.com/tools/iterable",
    "markdownUrl": "https://www.anchorterminal.com/tools/iterable.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/iterable.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/iterable.json",
    "repo": "https://github.com/Iterable/mcp-server",
    "license": "Proprietary service under Iterable's Master Services Agreement. The MCP server (@iterable/mcp) and the TypeScript API client (@iterable/api) are MIT",
    "transports": [
      "http",
      "stdio"
    ],
    "remoteUrl": "https://api.iterable.com",
    "packages": [
      {
        "registry": "npm",
        "name": "@iterable/mcp"
      },
      {
        "registry": "npm",
        "name": "@iterable/api"
      }
    ],
    "auth": "api-key",
    "authNotes": "Access needs an Iterable customer account, which is sold through sales. A project member creates an API key in the app and sends it in the `Api-Key` header. The specification names five key types (Server-side, Read-only, Mobile, Web, JavaScript) and lists which types each operation accepts. 148 of 159 operations accept a server-side key and 30 accept a read-only key. No OAuth, app review or partner approval was found. The MCP server reads the same key from the system keychain or `ITERABLE_API_KEY`, and adds its own flags for PII, writes and sends. The key guide on the support centre couldn't be read, so rotation and expiry are unchecked.",
    "pricing": "paid",
    "pricingNotes": "No public prices. https://iterable.com/pricing/ redirects to the home page, whose button asks for a demo, and no trial, free tier or self-serve signup was found. The MCP server README mentions sandbox projects, which exist inside a customer organisation, so an agent can't start without a contract. API and MCP calls aren't priced per call in any page we read (checked 2026-10-08).",
    "priceSummary": "Paid",
    "where": "both",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the API specification, the MCP server repository or the legal pages (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 118,
    "popularity": {
      "githubStars": 15,
      "npmWeekly": 4178,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://api.iterable.com/api/docs",
    "llmsTxt": "https://iterable.com/llms.txt",
    "openapi": "https://api.iterable.com/api-docs",
    "capabilities": [
      "marketing.profiles",
      "marketing.events",
      "marketing.segments",
      "marketing.campaigns",
      "marketing.journeys",
      "email.templates"
    ],
    "tags": [
      "official",
      "hosted",
      "mcp",
      "api-key",
      "openapi",
      "closed-source",
      "sales-led",
      "eu-region",
      "typescript",
      "status-page",
      "soc2",
      "beta-mcp"
    ],
    "lastRelease": "2026-09-30",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 55.2,
      "grade": "C",
      "agentReady": false,
      "rank": 457,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 4,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 57,
        "maintenance": 75,
        "payments": 0,
        "reliability": 66,
        "schema": 65,
        "security": 55,
        "transparency": 68
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 66,
          "points": 13.2,
          "reason": "Graded on the REST API, with the hosted lines. Statuspage site at status.iterable.com with component history (20). Five incidents between 10 July and 8 October 2026. One was marked critical, on 16 July, when the application and API in the US data centre failed for about 40 minutes. Four were minor, among them API user update timeouts on 22 September (about 70 minutes) and EU gateway errors on 10 September (about 110 minutes). That sits between the minor-only and one-major lines (15). 53 of 159 operations state a numeric limit (15). Only 6 operations document 429, two of them with `rateLimitReset` in the body. No Retry-After header or idempotency key was found in the specification, and backoff guidance on the support centre couldn't be read (6). No SLA was found in the Master Services Agreement or the product-specific terms (0). The REST API is generally available. The MCP server is beta (10). Total 66."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 65,
          "points": 10.56,
          "reason": "Public Swagger 2.0 specification at api.iterable.com/api-docs, 159 operations and 210 schemas (25). iterable.com/llms.txt exists but describes the company and links the documentation without carrying it, and no Markdown docs were found (4). All 159 operations have a summary and 147 a description, several with cautions such as the 60-second wait after a user update and the suppression list rule on campaign creation (14). Required fields are marked and there are 35 enums, while `dataFields` and template content stay free-form objects (11). The specification has 21 examples. 400 and 401 appear on nearly every operation, and the error body has a 26-value `code` enum (8). The specification is labelled version 1.8 with no version in the path. Release notes sit on the support centre, which we couldn't read, so only 3 of 15 here. Total 65."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 57,
          "points": 9.26,
          "reason": "API list calls take `page` and `pageSize`, and the MCP server shows 31 of its 118 tools by default, with three flags that add the rest (15). `nextPageUrl` paging on campaigns, catalogues, journeys and templates, state and sort filters on campaigns, and `limit` on events, but list member reads are capped at 5 requests a minute (14). Errors carry a `code` from a 26-value enum, a message and `params`, with reset seconds on some 429s (15). No idempotency keys. User updates merge and catalogue PUT replaces, so those retries are safe, but sends aren't. The MCP tools have no readOnlyHint or destructiveHint, and an issue asking for them has been open since 4 June 2026 (6). Most calls need few parameters. The one server-side SDK is the TypeScript client, which its README calls experimental (7). Total 57."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 55,
          "points": 9.63,
          "reason": "API keys come in five types and each operation lists the types it accepts. A read-only type works on 30 operations, and the key travels only in a header. Rotation and expiry are unchecked because the key guide couldn't be read (22). The read-only key type, and an MCP server that starts with PII, writes and sends all off and stores those settings per key. Neither surface has a confirmation step, and the README leaves review of each call to the person (16). Profiles, events and templates hold customer-written text. The README warns about irreversible actions but gives no injection guidance (3). No audit log or per-call record for the operator was found in the pages we could read (0). Responsible disclosure policy with a reply in one to three business days, no bug bounty, no security.txt, SOC 2 Type 2, ISO 27001 and HIPAA on the trust centre, and CodeQL on the open repositories (14). Total 55."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 0,
          "points": 0,
          "reason": "No x402, MPP or L402 (0). No public prices. iterable.com/pricing redirects to the home page, which asks for a demo (0). No free tier or trial was found (0). A person has to buy through sales and create a key in the app (0). Total 0."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 75,
          "points": 6.56,
          "reason": "@iterable/mcp 1.9.0 and @iterable/api 0.13.0 were published on 30 September 2026 (30). Six package releases since 10 July, counting @iterable/web-sdk 2.3.0 to 2.3.3 (20). The MCP repository has two open issues, one answered once in April and one unanswered since 4 June. Pull requests are merged by staff. Support is the support centre and email under the Master Services Agreement, and release notes there couldn't be read (7). The MCP server isn't in the official MCP registry. Official packages are current, though the API client is declared experimental (10). CI runs on Node 20, 22 and 24 on Ubuntu and Windows with a frozen lockfile and CodeQL (8). Total 75."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 68,
          "points": 5.95,
          "note": "editorial 57, provenance 79",
          "reason": "Closed service with a published Master Services Agreement, and MIT licences on the MCP server and API client (18). The agreement deletes customer confidential information within 30 days of expiry and the privacy notice sets out retention by data type, but the notice is dated 14 July 2023 and no public DPA was found (18). No API deprecation policy was found. The website terms let Iterable change or discontinue the services at any time, and the specification marks some fields deprecated without dates (3). Sub-processor list updated August 2026 with processing locations, and US and EU data centres (18). Total 57."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "API list calls take `page` and `pageSize`, and the MCP server shows 31 of its 118 tools by default, with three flags that add the rest (15). `nextPageUrl` paging on campaigns, catalogues, journeys and templates, state and sort filters on campaigns, and `limit` on events, but list member reads are capped at 5 requests a minute (14). Errors carry a `code` from a 26-value enum, a message and `params`, with reset seconds on some 429s (15). No idempotency keys. User updates merge and catalogue PUT replaces, so those retries are safe, but sends aren't. The MCP tools have no readOnlyHint or destructiveHint, and an issue asking for them has been open since 4 June 2026 (6). Most calls need few parameters. The one server-side SDK is the TypeScript client, which its README calls experimental (7). Total 57.",
          "maintenance": "@iterable/mcp 1.9.0 and @iterable/api 0.13.0 were published on 30 September 2026 (30). Six package releases since 10 July, counting @iterable/web-sdk 2.3.0 to 2.3.3 (20). The MCP repository has two open issues, one answered once in April and one unanswered since 4 June. Pull requests are merged by staff. Support is the support centre and email under the Master Services Agreement, and release notes there couldn't be read (7). The MCP server isn't in the official MCP registry. Official packages are current, though the API client is declared experimental (10). CI runs on Node 20, 22 and 24 on Ubuntu and Windows with a frozen lockfile and CodeQL (8). Total 75.",
          "payments": "No x402, MPP or L402 (0). No public prices. iterable.com/pricing redirects to the home page, which asks for a demo (0). No free tier or trial was found (0). A person has to buy through sales and create a key in the app (0). Total 0.",
          "reliability": "Graded on the REST API, with the hosted lines. Statuspage site at status.iterable.com with component history (20). Five incidents between 10 July and 8 October 2026. One was marked critical, on 16 July, when the application and API in the US data centre failed for about 40 minutes. Four were minor, among them API user update timeouts on 22 September (about 70 minutes) and EU gateway errors on 10 September (about 110 minutes). That sits between the minor-only and one-major lines (15). 53 of 159 operations state a numeric limit (15). Only 6 operations document 429, two of them with `rateLimitReset` in the body. No Retry-After header or idempotency key was found in the specification, and backoff guidance on the support centre couldn't be read (6). No SLA was found in the Master Services Agreement or the product-specific terms (0). The REST API is generally available. The MCP server is beta (10). Total 66.",
          "schema": "Public Swagger 2.0 specification at api.iterable.com/api-docs, 159 operations and 210 schemas (25). iterable.com/llms.txt exists but describes the company and links the documentation without carrying it, and no Markdown docs were found (4). All 159 operations have a summary and 147 a description, several with cautions such as the 60-second wait after a user update and the suppression list rule on campaign creation (14). Required fields are marked and there are 35 enums, while `dataFields` and template content stay free-form objects (11). The specification has 21 examples. 400 and 401 appear on nearly every operation, and the error body has a 26-value `code` enum (8). The specification is labelled version 1.8 with no version in the path. Release notes sit on the support centre, which we couldn't read, so only 3 of 15 here. Total 65.",
          "security": "API keys come in five types and each operation lists the types it accepts. A read-only type works on 30 operations, and the key travels only in a header. Rotation and expiry are unchecked because the key guide couldn't be read (22). The read-only key type, and an MCP server that starts with PII, writes and sends all off and stores those settings per key. Neither surface has a confirmation step, and the README leaves review of each call to the person (16). Profiles, events and templates hold customer-written text. The README warns about irreversible actions but gives no injection guidance (3). No audit log or per-call record for the operator was found in the pages we could read (0). Responsible disclosure policy with a reply in one to three business days, no bug bounty, no security.txt, SOC 2 Type 2, ISO 27001 and HIPAA on the trust centre, and CodeQL on the open repositories (14). Total 55.",
          "transparency": "Closed service with a published Master Services Agreement, and MIT licences on the MCP server and API client (18). The agreement deletes customer confidential information within 30 days of expiry and the privacy notice sets out retention by data type, but the notice is dated 14 July 2023 and no public DPA was found (18). No API deprecation policy was found. The website terms let Iterable change or discontinue the services at any time, and the specification marks some fields deprecated without dates (3). Sub-processor list updated August 2026 with processing locations, and US and EU data centres (18). Total 57."
        },
        "sources": [
          {
            "what": "API explorer",
            "url": "https://api.iterable.com/api/docs",
            "seen": "2026-10-08"
          },
          {
            "what": "raw API specification (Swagger 2.0)",
            "url": "https://api.iterable.com/api-docs",
            "seen": "2026-10-08"
          },
          {
            "what": "EU API specification",
            "url": "https://api.eu.iterable.com/api-docs",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server repository (README, TOOLS.md, SECURITY.md, source, CI)",
            "url": "https://github.com/Iterable/mcp-server",
            "seen": "2026-10-08"
          },
          {
            "what": "API client repository",
            "url": "https://github.com/Iterable/api-client",
            "seen": "2026-10-08"
          },
          {
            "what": "npm metadata for @iterable/mcp",
            "url": "https://registry.npmjs.org/@iterable/mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "status incidents",
            "url": "https://status.iterable.com/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "trust centre",
            "url": "https://trust.iterable.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "Master Services Agreement",
            "url": "https://iterable.com/legal/master-services-agreement/",
            "seen": "2026-10-08"
          },
          {
            "what": "product-specific terms",
            "url": "https://iterable.com/legal/product-specific-terms/",
            "seen": "2026-10-08"
          },
          {
            "what": "beta terms",
            "url": "https://iterable.com/legal/beta-terms/",
            "seen": "2026-10-08"
          },
          {
            "what": "terms of service",
            "url": "https://iterable.com/legal/terms/",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy notice",
            "url": "https://iterable.com/legal/privacy-policy/",
            "seen": "2026-10-08"
          },
          {
            "what": "sub-processors",
            "url": "https://iterable.com/legal/iterable-sub-processors/",
            "seen": "2026-10-08"
          },
          {
            "what": "responsible disclosure policy",
            "url": "https://iterable.com/legal/responsible-disclosure-policy/",
            "seen": "2026-10-08"
          },
          {
            "what": "llms.txt",
            "url": "https://iterable.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=iterable",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: support.iterable.com (API guides, API key guide, MCP server articles, release notes) answered with a Cloudflare check for both curl and WebFetch, so key rotation, backoff guidance, audit logs and the changelog are scored from the specification and repositories alone",
          "unchecked: whether a public DPA or an SLA exists outside the Master Services Agreement and product-specific terms, for example in order forms",
          "unchecked: 90-day uptime percentages on status.iterable.com, which weren't in the page text we read",
          "No official server-side SDK other than the TypeScript client was found. The vendor's GitHub organisation listing wasn't read",
          "The MCP server is local stdio and beta. Scores follow the generally available REST API, with the MCP server counted where the checklist asks about tools"
        ]
      },
      "negative": 0,
      "verdict": "The REST API publishes a Swagger 2.0 contract with 159 operations, typed API keys including a read-only type, and per-endpoint rate limits. The MCP server starts read-only, with PII, writes and sends each switched on separately. No price, trial or self-serve signup is published, and the support centre, which holds the API guides, refused automated readers.",
      "bestFor": "A team already on Iterable that wants an agent to read campaigns, templates and metrics, or to update profiles, track events and trigger sends under review.",
      "strengths": [
        "Public Swagger 2.0 specification at api.iterable.com/api-docs with 159 operations and 210 schemas, the same for the EU data centre",
        "Each operation lists the key types it accepts (Server-side, Read-only, Mobile, Web, JavaScript), and 30 operations accept a read-only key",
        "The MCP server exposes 31 read tools by default. PII, writes and sends are three separate flags stored per key",
        "53 operations state a numeric rate limit, for example 500 requests a second per project on `POST /api/users/update`",
        "SOC 2 Type 2, ISO 27001 and HIPAA listed on the trust centre, and a sub-processor list with locations updated August 2026"
      ],
      "weaknesses": [
        "No public price, trial or self-serve signup. iterable.com/pricing redirects to the home page, which asks for a demo",
        "No idempotency keys in the specification, and only 6 of 159 operations document a 429 response",
        "The MCP server is in beta under terms that allow change or withdrawal without notice, and carries no tool annotations",
        "No published SLA or API deprecation policy was found in the Master Services Agreement or the product-specific terms",
        "The API can create static lists and read list members, but no operation builds a dynamic segment or edits a journey"
      ],
      "agentNotes": [
        "Send the key in the `Api-Key` header, and use api.eu.iterable.com for projects in the EU data centre",
        "Wait at least 60 seconds after `POST /api/users/update` before a dependent call such as `POST /api/email/target`, as the specification advises",
        "Keep the MCP server on its default read-only setup unless a person reviews each call. Writes and sends act on real users and can't be undone",
        "Pass `suppressionListIds` to `POST /api/campaigns/create`. Global suppression lists aren't added automatically",
        "Read `rateLimitReset` in the 429 `params` on user update calls for the seconds to wait. List member reads allow 5 requests a minute per project"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 55.2
        }
      ],
      "editorialScores": {
        "ergonomics": 57,
        "maintenance": 75,
        "payments": 0,
        "reliability": 66,
        "schema": 65,
        "security": 55,
        "transparency": 57
      },
      "provenanceScore": 79
    },
    "connect": {
      "install": "npx @iterable/mcp setup",
      "claudeCode": "claude mcp add iterable -- npx -y @iterable/mcp",
      "config": {
        "mcpServers": {
          "iterable": {
            "args": [
              "-y",
              "@iterable/mcp"
            ],
            "command": "npx"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/marketing.profiles",
      "tool": "https://letme.dev/iterable"
    },
    "notable": [
      "The raw specification is Swagger 2.0, title Iterable API, version 1.8, with 159 operations on 138 paths and an `x-iterable-api-key-types` list on each (https://api.iterable.com/api-docs)",
      "The MCP server is a local stdio package, `npx @iterable/mcp setup`, with 118 tools in 13 groups. The default setup is read-only with no PII tools, writes or sends (https://github.com/Iterable/mcp-server)",
      "The README says the MCP server is in beta and may change, be suspended or be discontinued at any time without notice (https://github.com/Iterable/mcp-server#beta-feature-reminder)",
      "status.iterable.com lists five incidents between 10 July and 8 October 2026, one marked critical (16 July, application and API in the US data centre, about 40 minutes) and four minor (https://status.iterable.com/history)",
      "The trust centre lists SOC 2 Type 2, ISO 27001, HIPAA and the Data Privacy Framework (https://trust.iterable.com/)",
      "The responsible disclosure policy promises a reply in one to three business days and says there is no public bug bounty (https://iterable.com/legal/responsible-disclosure-policy/)",
      "support.iterable.com answered our reader with a Cloudflare check, so the API guides, key guide and release notes there weren't read"
    ],
    "area": "communication",
    "details": [
      {
        "label": "API",
        "value": "REST, Swagger 2.0, version 1.8, 159 operations on 138 paths (84 POST, 54 GET, 12 DELETE, 5 PUT, 4 PATCH). Hosts api.iterable.com (US) and api.eu.iterable.com (EU)"
      },
      {
        "label": "Resource groups",
        "value": "Templates (24 operations), users (21), campaigns (13), experiments (13), catalogues (12), events (11), lists (8), export (7), subscriptions (6), metadata (6), plus sends by email, SMS, push, web push, in-app, RCS and WhatsApp"
      },
      {
        "label": "Credentials",
        "value": "API key in the `Api-Key` header. Key types Server-side, Read-only, Mobile, Web and JavaScript, with the accepted types listed per operation. JWTs for client-side keys can be invalidated per user"
      },
      {
        "label": "Rate limits",
        "value": "Stated on 53 operations. `POST /api/events/track` 2,000 a second per project, `POST /api/users/update` 500, most reads 100, `GET /api/lists/getUsers` 5 a minute, `GET /api/campaigns/metrics` 10 a minute, exports 4 a minute"
      },
      {
        "label": "Errors",
        "value": "JSON body with `code`, `msg` and `params`. `code` is one of 26 values such as BadParams, RateLimitExceeded, ForgottenUserError and UniqueFieldsLimitExceeded. 429 on user update calls returns `rateLimitLimit`, `rateLimitRemaining` and `rateLimitReset`"
      },
      {
        "label": "Pagination",
        "value": "`page` and `pageSize` with `nextPageUrl` and `previousPageUrl` on campaigns, catalogues, journeys and templates. `limit` on user events"
      },
      {
        "label": "MCP server",
        "value": "@iterable/mcp 1.9.0 (30 September 2026), local stdio, Node 20 or later, MIT, beta. 118 tools. Campaigns 14, catalogues 13, export 5, events 4, experiments 13, journeys 2, lists 8, messaging 16, snippets 5, subscriptions 5, templates 21, users 10, webhooks 2"
      },
      {
        "label": "MCP permissions",
        "value": "31 tools need no flag. `ITERABLE_USER_PII` gates 46, `ITERABLE_ENABLE_WRITES` 76 and `ITERABLE_ENABLE_SENDS` 19, with sends needing writes. Settings are stored per key"
      },
      {
        "label": "SDKs",
        "value": "@iterable/api 0.13.0 (TypeScript, MIT, described by its README as experimental) and @iterable/web-sdk 2.3.3. No other server-side language was found"
      },
      {
        "label": "Status",
        "value": "status.iterable.com on Statuspage, with global components for the web application, API success, API ingestion, campaign sends, journey processing, links and webhooks, and per-cluster components"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 Type 2, ISO 27001, HIPAA, Data Privacy Framework, Global CBPR and PRP per trust.iterable.com. No public bug bounty"
      },
      {
        "label": "Sub-processors",
        "value": "List updated August 2026 with locations. Amazon Web Services for hosting (US, Ireland, Germany), plus Bird, Mailgun, Twilio, Telnyx, Infobip, Snowflake, Databricks, Datadog, OpenAI and others"
      }
    ],
    "provenance": {
      "legalEntity": "Iterable, Inc.",
      "domain": "iterable.com",
      "domainRegistered": "2011-12-28",
      "endpointOnVendorDomain": true,
      "terms": "https://iterable.com/legal/terms/",
      "privacy": "https://iterable.com/legal/privacy-policy/",
      "statusPage": "https://status.iterable.com",
      "changelog": "",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The Master Services Agreement (last updated 8 June 2026) names Iterable, Inc., a Delaware corporation. The privacy notice gives 201 Spear Street, Suite 1050, San Francisco, CA 94105.",
        "The website terms of service are dated 6 May 2021 and the privacy notice 14 July 2023.",
        "The API answers at api.iterable.com and api.eu.iterable.com, both on the vendor's domain.",
        "iterable.com/.well-known/security.txt and app.iterable.com/.well-known/security.txt return 404. Reports go through the responsible disclosure policy or security@iterable.com.",
        "No changelog URL is recorded because the release notes sit on support.iterable.com, which answered with a Cloudflare check.",
        "RDAP for iterable.com gives a registration date of 2011-12-28."
      ],
      "score": 79,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Iterable, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "iterable.com, registered 2011-12-28 (14 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.iterable.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects",
          "points": 9.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "status.iterable.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://iterable.com/legal/terms/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2021-05-06",
          "words": 3526,
          "points": 9.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: May 6, 2021",
              "says": "Last updated 2021-05-06"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "You agree that the Terms, and your relationship with Iterable will be governed by the laws of the State of California, U.S.A.",
              "says": "The law of the State of California"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "ITERABLE’S LIABILITY UNDER THIS AGREEMENT SHALL BE LIMITED TO THE LESSER OF THE AMOUNT PAID BY YOU, IF ANY, FOR ACCESSING THE SERVICES DURING THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE DAY THE ACT OR OMISSION OCCURRED THAT GAVE RISE TO YOUR CLAIM OR $100USD.",
              "says": "Capped at the lesser of $100 and the fees paid in the 12 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "If at any time you do not agree to the updated terms, you may terminate your use of the Services."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "If we make material changes to these Terms, we will notify you via the Services and/or by email.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "You agree not to use another user’s account or registration information, for Iterable or any third party services you access through Iterable, without permission."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "Iterable may change, suspend or discontinue the Services for any reason, at any time, including the availability of any feature."
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "To the extent that the following provision is not in conflict with applicable law, you may only resolve disputes with us on an individual basis and may not bring a claim or proceed in a group arbitration proceeding as a plaintiff or a class member in a class, consolidated, or representative action."
            },
            {
              "key": "old",
              "label": "Has not been updated for three years or more",
              "found": true,
              "quote": "Last updated: May 6, 2021"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Liability is capped at the lesser of the amount paid in the preceding twelve months or 100 US dollars.",
              "quote": "ITERABLE’S LIABILITY UNDER THIS AGREEMENT SHALL BE LIMITED TO THE LESSER OF THE AMOUNT PAID BY YOU, IF ANY, FOR ACCESSING THE SERVICES DURING THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE DAY THE ACT OR OMISSION OCCURRED THAT GAVE RISE TO YOUR CLAIM OR $100USD."
            },
            {
              "date": "2026-10-08",
              "text": "The customer allows Iterable to use its logo and name on Iterable websites and in certain marketing materials.",
              "quote": "You understand and allow Iterable (i) the rights provided under these Terms to provide you the selected Services and (ii) to use your logo and name as appropriate on the Iterable website(s) and certain marketing materials."
            },
            {
              "date": "2026-10-08",
              "text": "Iterable may remove any Customer Data from the Services at any time, for any reason or for none.",
              "quote": "Iterable reserves the right to remove any Customer Data from the Services at any time, for any reason or for no reason at all."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://iterable.com/legal/privacy-policy/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2023-01-01",
          "words": 10230,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "CCPA is known as CPRA effective January 1, 2023 updating CCPA legislation, making it easier to understand and will provide employees and contractors (HR Individuals) rights under CCPA.",
              "says": "Last updated 2023-01-01"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "…which we might otherwise process when providing Services to our Customers (including the personal data we collect, why we collected it and your rights in respect of our processing of your personal data)."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "Prospective customers: We only keep data obtained from our third party service providers for B2B prospecting for 24 months from the last interaction you have had with us.",
              "says": "Names a period of 24 months"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "…third parties may include our Customers who have used our refer a friend facility on our Site, analytics providers, third parties that collect data from publicly available sources in order to assist us identifying prospective Customers and with delivering personalised communications to prospective Customers and third…"
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "Iterable does not sell your personal information or share information for cross context behavioural advertising.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "You can opt-out of our sharing of your personal information with the third-party providers by exercising your rights as a data subject as set out below."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "To find out more about the SCCs we use, please see: Standard contractual clauses for international transfers | European Commission (europa.eu) or please email us at privacy@iterable.com",
              "says": "privacy@iterable.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "or (2) where we use certain service providers, we may use specific contracts approved by the UK Government or the European Commission referred to as the “Standard Contractual Clauses” or “SCCs” which give personal data the same protection it has in the UK and EU.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "toKnow": [
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "We share personal data with third party advertising partners, including those set out in our Cookie Policy and/or our Cookie preference centre when you use our Site."
            },
            {
              "key": "old",
              "label": "Has not been updated for three years or more",
              "found": true,
              "quote": "CCPA is known as CPRA effective January 1, 2023 updating CCPA legislation, making it easier to understand and will provide employees and contractors (HR Individuals) rights under CCPA."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Iterable may generate aggregated statistics from the end user data that customers submit to the Services.",
              "quote": "Iterable may generate aggregated statistics from End User Data."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/iterable.json",
    "live": {
      "slug": "iterable",
      "probe": {
        "target": "https://api.iterable.com",
        "method": "get",
        "lastAt": "2026-10-08T18:20:32.193580217Z",
        "lastOk": true,
        "lastStatus": 200,
        "lastMs": 544,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 531,
        "p95ms24h": 630,
        "samples24h": 33,
        "samples30d": 33,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 33,
            "ok": 33
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.iterable.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T18:22:04.723750839Z"
      },
      "versions": [
        {
          "registry": "github",
          "name": "Iterable/mcp-server",
          "version": "v1.9.0",
          "released": "2026-09-30",
          "seenAt": "2026-10-08T16:17:13.579373494Z"
        },
        {
          "registry": "npm",
          "name": "@iterable/api",
          "version": "0.13.0",
          "seenAt": "2026-10-08T16:17:13.325775553Z"
        },
        {
          "registry": "npm",
          "name": "@iterable/mcp",
          "version": "1.9.0",
          "seenAt": "2026-10-08T16:17:09.206564109Z"
        }
      ],
      "githubStars": 15,
      "npmWeekly": 4178,
      "securityTxt": {
        "url": "https://iterable.com/.well-known/security.txt",
        "state": "none",
        "checkedAt": "2026-10-08T15:38:44.079638167Z"
      },
      "pages": [
        {
          "url": "https://iterable.com/pricing/",
          "kind": "pricing",
          "status": 200,
          "checkedAt": "2026-10-08T18:21:06.907655734Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "ff0025e6b74a"
        },
        {
          "url": "https://iterable.com/legal/privacy-policy/",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-08T18:21:02.768125484Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "919d5d7bffa8"
        },
        {
          "url": "https://iterable.com/legal/terms/",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-08T18:21:04.92865919Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "8a2a6f05a6e1"
        }
      ],
      "updatedAt": "2026-10-08T18:22:04.723750839Z"
    }
  }
}
