generated: '2026-08-12' method: derived source: >- openapi/adready-cpxi-kickstart-openapi.yml, live response headers from https://platform.digitalremedy.com, and https://trust.digitalremedy.com/ note: >- Cross-cutting standards conformance derived from the published OpenAPI 3.1 description and observed runtime behaviour. Digital Remedy publishes no conformance claims of its own, so every entry below is a measurement rather than a restatement of a vendor claim. standards: - id: openapi-3.1 conforms: true evidence: >- openapi 3.1.0 served at https://platform.digitalremedy.com/v3/api-docs, 285 paths, 355 operations, 285 component schemas, all operationIds unique. Generated by springdoc. - id: swagger-ui conforms: true evidence: Browsable UI served at https://platform.digitalremedy.com/swagger-ui.html - id: oauth2 conforms: false evidence: No oauth2 securityScheme; no authorization or token endpoint of the OAuth shape. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 401 on both platform hosts, 404 on the marketing host. - id: rfc9457-problem-details conforms: false evidence: >- Errors use a custom ApiResponse {status, message, result} envelope; application/problem+json does not appear anywhere in the description. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header in the description or in observed responses. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 (marketing host) and 401 (platform hosts). - id: rfc8615-well-known conforms: false evidence: No /.well-known/ document is served on any host; see well-known/adready-cpxi-well-known.yml. - id: rfc9457-or-json-api-errors conforms: false evidence: Neither JSON:API nor Problem Details shapes are used. - id: idempotency-key conforms: false evidence: No idempotency header, parameter or language anywhere in the description. - id: ratelimit-headers conforms: false evidence: No RateLimit-* / X-RateLimit-* / Retry-After headers observed or declared; no 429 declared. - id: hsts conforms: true evidence: >- strict-transport-security max-age=31536000; includeSubDomains observed on platform.digitalremedy.com. Not present on www.digitalremedy.com. - id: tls-1.3 conforms: true evidence: TLSv1.3 negotiated on both www.digitalremedy.com and platform.digitalremedy.com. - id: dnssec conforms: false evidence: digitalremedy.com is not DNSSEC signed. - id: caa conforms: false evidence: No CAA records published for digitalremedy.com. - id: spf conforms: true evidence: SPF record published for digitalremedy.com. - id: dmarc conforms: true evidence: DMARC published for digitalremedy.com with policy quarantine (not reject). - id: soc2 conforms: true evidence: >- SOC 2 named on the Digital Remedy trust center at https://trust.digitalremedy.com/ - see security/adready-cpxi-trust-center.yml. This is a corporate compliance program, not an API conformance claim. - id: iso-27001 conforms: false evidence: Not named on the trust center. - id: gdpr-ccpa-disclosures conforms: true evidence: >- https://www.digitalremedy.com/privacy-policy/ and a dedicated California residents notice at /privacy-policy/for-california-residents/ are published. Relevant because this is an advertising-data business. summary: conforms: 8 does_not_conform: 12 headline: >- A real, current OpenAPI 3.1 contract with none of the runtime-semantics standards that make an API safe to automate against - no problem details, no idempotency, no rate-limit signalling, no deprecation headers, and no discovery documents.