generated: '2026-09-07' method: searched source: >- https://addx.co/en/about-us/, https://documents.addx.co/ADDX_ISO_IEC_27001_2013.pdf, https://api-docs.addx.co/open-api/ name: ADDX conformance and compliance summary: >- ADDX's compliance posture is regulatory and organisational rather than protocol-level. It is licensed by the Monetary Authority of Singapore and publishes an ISO/IEC 27001:2013 certificate plus a full set of exchange rulebooks. Its API, by contrast, conforms to none of the cross-cutting web-API standards this catalog checks — no OAuth 2.0, no OpenID Connect, no RFC 9457 problem details, no RFC 8594 deprecation signalling, no OpenAPI description — and it declares no domain standard for capital markets. certifications: - id: iso-27001 name: ISO/IEC 27001:2013 domain: information security management certified: true since: '2022-01' evidence: https://documents.addx.co/ADDX_ISO_IEC_27001_2013.pdf evidence_status: 200 note: Certificate published as a first-party PDF on the ADDX document host. regulatory: - id: mas-cmsl regime: Singapore — Monetary Authority of Singapore status: licensed detail: >- Capital Markets Services licensee for dealing in capital markets products and for providing custodial services. evidence: https://addx.co/en/about-us/ evidence_status: 200 - id: mas-rmo regime: Singapore — Monetary Authority of Singapore status: recognised detail: Recognised Market Operator, the basis for the ADDX secondary exchange. evidence: https://addx.co/en/about-us/ evidence_status: 200 - id: addx-rulebooks regime: self-published market rules status: published detail: >- Platform Rules, Exchange Rules, Trading Rules, Listing Rules, OTC Rules and a Best Execution Policy, all served as first-party PDFs. evidence: https://documents.addx.co/ADDX_Platform_Rules.pdf evidence_status: 200 entity: legal_name: ADDX Pte. Ltd. registration_number: 202125312H founded: '2017-11' headquarters: 8 Kallang Avenue, Aperia Tower One, #13-01/04, Singapore 339509 former_name: iSTOX conformance: - id: oauth2 conforms: false evidence: >- https://api-docs.addx.co/open-api/ documents an HMAC-SHA256 request-signature scheme (X-Signature, X-UserId, X-TimeStamp) with no authorization server, no token endpoint and no scopes. No /.well-known/oauth-authorization-server is served on any ADDX host. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on addx.co, www.addx.co, api-docs.addx.co and documents.addx.co - id: rfc9457 conforms: false evidence: >- Errors use a flat {message, code, success, extra} JSON envelope with no type/title/status/detail/instance and no application/problem+json media type — see errors/addx-problem-types.yml - id: rfc8594 conforms: false evidence: >- The one published deprecation (the avg_price ticker field) is prose in the reference; no Sunset or Deprecation header is documented — see lifecycle/addx-lifecycle.yml - id: rfc9116 conforms: false evidence: /.well-known/security.txt returns 404 on every ADDX host probed - id: openapi conforms: false evidence: >- The API is documented as a static HTML reference ("Open Api Library") at https://api-docs.addx.co/open-api/. No OpenAPI or Swagger document is published at that host, at addx.co, at client.addx.co or at digital-api.addx.co. - id: pagination conforms: true evidence: >- Consistent page-number pagination with page + limit (max 50) request params and a pagination object carrying page, pageCount, nextPage, currentPage — documented on the transaction-history operations at https://api-docs.addx.co/open-api/ - id: idempotency conforms: false evidence: >- No Idempotency-Key header or client-supplied request identifier anywhere in the 68 documented operations, including the money-moving confirm calls — see conventions/addx-conventions.yml - id: json-api conforms: false evidence: Responses are bare JSON objects and arrays, not JSON:API documents domain_standards: market: capital markets / private-market digital securities (Singapore) declared: false candidates_checked: - id: iso-20022 found: false evidence: >- No ISO 20022 message type, MX identifier or camt/pain/sese element appears in any documented request or response at https://api-docs.addx.co/open-api/ - id: fix-protocol found: false evidence: >- The exchange surface (/openapi/trading/api/v2/...) is a proprietary JSON order-book and ticker API, not FIX; no FIX session, tag or message type is documented - id: fdx found: false evidence: Not a bank-data-sharing surface; no FDX resources or consent model documented - id: openbanking-uk-psd2 found: false evidence: Singapore-regulated exchange, outside the PSD2/OBIE perimeter note: >- Reward-only check. ADDX's market has candidate standards (ISO 20022 for securities messaging in particular) but ADDX declares none in its contract, so nothing is credited and nothing is penalised. Recorded so the absence is a measurement rather than a gap in our looking. gaps: - An ISO 27001-certified, MAS-licensed exchange publishes no security.txt and no vulnerability-disclosure route. - No OpenAPI description for an API that already has a complete, structured HTML reference. - No protocol-level conformance claim of any kind on the developer surface.