generated: '2026-08-14' method: searched source: >- openapi/_original/, https://docs.ada.cx/reference/introduction/errors, https://docs.ada.cx/reference/introduction/pagination, https://docs.ada.cx/reference/integrations/getting-started, https://docs.ada.cx/mcp/introduction/overview, https://docs.ada.cx/.well-known/api-catalog, https://security.ada.cx/ compliance_page: https://security.ada.cx/ standards: - id: openapi-3.1 conforms: true evidence: >- All four published documents declare `openapi: 3.1.0`, are served as application/yaml from docs.ada.cx/openapi/*.yaml, and are advertised in an RFC 9727 api-catalog. - id: rfc9727-api-catalog conforms: true evidence: >- https://docs.ada.cx/.well-known/api-catalog returns 200 application/linkset+json; profile="https://www.rfc-editor.org/info/rfc9727" with four service-desc/service-doc pairs. Probed 2026-08-14. - id: rfc8615-well-known-uris conforms: true evidence: api-catalog served under /.well-known/ on docs.ada.cx. - id: rfc9457-problem-details conforms: false evidence: >- Errors are application/json with a custom `{"errors":[{type,message,details}]}` envelope. No application/problem+json, no type URIs. See errors/ada-problem-types.yml. - id: oauth2 conforms: true partial: true evidence: >- OAuth 2.0 authorization_code + refresh_token for platform integrations, token endpoint https://{bot-handle}.ada.support/api/platform_integrations/oauth/token, 8 published scopes, refresh-token rotation on every use. Documented in prose only — no oauth2 securityScheme appears in any published OpenAPI document. - id: oauth2-authorization-server-metadata conforms: false evidence: >- No /.well-known/oauth-authorization-server on any Ada-controlled host. The 200 at security.ada.cx belongs to SafeBase, not Ada. - id: oidc conforms: false evidence: No /.well-known/openid-configuration served by Ada; no openIdConnect securityScheme. - id: http-bearer-auth conforms: true evidence: 'Every spec declares http/bearer; docs specify the header `Authorization: Bearer `.' - id: cursor-pagination conforms: true evidence: >- Cursor-based pagination across v2, `limit`/`cursor` query params, `meta.next_page_url` in the response, null on the last page. https://docs.ada.cx/reference/introduction/pagination - id: idempotency conforms: true partial: true evidence: >- Caller-supplied `client_reference` deduplicates bulk end-user deletion jobs for 24 hours; `external_id` makes POST /v2/end-users/ an idempotent upsert (200 vs 201). No general Idempotency-Key header. See conventions/ada-conventions.yml. - id: rfc8594-sunset-header conforms: false evidence: >- Deprecation is announced in the dated release notes and in an OpenAPI info.title ("Data Compliance (Deprecated)"), never as Sunset/Deprecation response headers. - id: rfc6585-429 conforms: true evidence: 429 Too Many Requests on rate-limit exhaustion, documented in the limits page and in every spec. - id: ietf-ratelimit-headers conforms: false evidence: >- No RateLimit-*/X-RateLimit-*/Retry-After response headers are documented. A client learns it is throttled only from the 429 status. - id: json-api conforms: false evidence: Plain JSON resource representations; no JSON:API document structure. - id: odata conforms: false - id: graphql conforms: false evidence: >- No GraphQL endpoint is published. graphql/ada-graphql.md in this repo is a conceptual description, not a served schema. - id: mcp conforms: true evidence: >- Two MCP servers. The Platform server (https:///api/mcp, OAuth or API key, 18 documented tools, role-based access control) is documented at docs.ada.cx/mcp. The docs server (https://docs.ada.cx/_mcp/server) was probed anonymously on 2026-08-14: initialize returned protocolVersion 2025-06-18 and tools/list returned searchDocs with a real inputSchema. Ada states JSON-RPC 2.0 over HTTP; SSE streaming is NOT supported. - id: agent-skills conforms: true evidence: >- Six Apache-2.0 Agent Skills published by Ada at github.com/AdaSupport/ada-skills, each with name/description/license/compatibility/metadata/allowed-tools frontmatter, distributed as a Claude Code plugin marketplace and copyable to Codex/Cursor skill directories. - id: a2a conforms: false evidence: >- No /.well-known/agent-card.json or /.well-known/agent.json on any Ada host. Probed 2026-08-14 across docs.ada.cx, www.ada.cx, ada.cx, ada.support, api.ada.support, security.ada.cx. - id: llmstxt conforms: true evidence: >- https://docs.ada.cx/llms.txt returns 200 with a real index, plus version-scoped (/generative/llms.txt, /scripted/llms.txt) and section-scoped variants, and a `.md` twin for every page. - id: asyncapi conforms: false evidence: >- Six documented webhook event types delivered over Svix with signing secrets and a published retry schedule, but no AsyncAPI document. See asyncapi/ada-webhooks.yml. - id: webhook-signature-verification conforms: true evidence: Per-endpoint signing secret, retrievable and rotatable via GET/POST /v2/webhooks/{id}/secret/. - id: gdpr conforms: true evidence: >- Named on Ada's trust centre (https://security.ada.cx/). Backed by an API surface: bulk end-user deletion (POST /v2/end-users/delete), the deprecated data-subject-request endpoint, and 24-hour auto-purge of sensitive end-user metadata. - id: soc2 conforms: true evidence: >- SOC 2 Type 2 covering 2023-10-01 to 2024-09-30, plus a SOC 3 for the same window, named on https://security.ada.cx/. Reports are gated behind a Request Access form. - id: soc3 conforms: true evidence: SOC 3 for 2023-10-01 to 2024-09-30, named on https://security.ada.cx/. - id: hipaa conforms: true evidence: Named on Ada's trust centre (https://security.ada.cx/). - id: ccpa conforms: true evidence: Named on Ada's trust centre; also addressed in the privacy policy. - id: cpra conforms: true evidence: Named on Ada's trust centre. - id: pipeda conforms: true evidence: Named on Ada's trust centre. Ada Support Inc. is Canadian. - id: cis-controls-v8 conforms: true evidence: >- Ada states its security programme "primarily follows Center for Internet Security Cybersecurity Framework v8.0 (CIS 8.0) practices." - id: wcag-2.1-aa conforms: true evidence: VPAT 2024 against WCAG 2.1 AA, named on https://security.ada.cx/. - id: iso27001 conforms: false evidence: >- Not named on the trust centre alongside SOC 2/SOC 3/PCI/VPAT. Recorded as absent rather than unknown — the trust centre enumerates its certifications and ISO 27001 is not among them. - id: pci-dss conforms: true evidence: >- A PCI DSS Attestation of Compliance is listed on https://security.ada.cx/ (gated). Ada is not a payments provider; the AoC covers the platform handling cardholder data in conversations. - id: fedramp conforms: false evidence: Not observed. - id: rfc9116-security-txt conforms: true partial: true evidence: >- A security.txt with Policy and Contact was read at https://www.ada.cx/.well-known/security.txt on 2026-07-11 (security/ada-vulnerability-disclosure.yml). A re-probe on 2026-08-14 returned 403 because the marketing origin now bot-challenges unauthenticated clients, so the document could not be re-confirmed. Not downgraded on that basis. regulatory_context: industry: customer service automation / conversational AI regimes: - GDPR (EU personal data in conversation transcripts) - HIPAA (healthcare customers) - SOC 2 (enterprise procurement) note: >- Ada handles end-user PII by design — profiles, transcripts, email addresses. Its compliance-relevant API surface is the deletion/retention path, not a payments or open-banking regime.