Yes
MailChimp uses TLS 1.2 but only specifies SSL within their documentation.
Yes
MailChimp meets the recommended cryptographic profiles for TLS as published by the NCSC. In addition, MailChimp currently gets an ‘A’ rating from Qualys SSL Labs (Intermediate Certificate uses SHA1). Note that this was performed on their top level domain, and not all subdomains that may be used for API calls.
Yes
MailChimp specifies that SSL is supported throughout the entire application and that sensitive data is transmitted via SSL.
Unknown
At this time, it is unknown whether MailChimp protects external data in transit using correctly configured certificates.
Partial
All API requests made to MailChimp support authentication using HTTP Basic Authentication and OAuth2. However, this is not enforced.
Yes
Yes
Does the SaaS provider collect logs of events?
Types of log may include security logs and resource logs
Unknown
Unknown
Does the SaaS provider have a clear incident response and patching system in place to remedy any publicly reported issues in their service, or libraries that the service makes use of?
The provider’s previous track record on this is a good metric to see how they’ll cope with a new issue occurring.
Unknown
Source: NCSC