generated: '2026-09-12' method: derived source: openapi/affectiva-eaas-*.json + live probes of https://index.affectiva.com, 2026-09-12 description: >- Cross-cutting standards the Affectiva Facial Coding API does and does not conform to, derived from its thirteen published Swagger 2.0 documents and from live response probes. Affectiva publishes no compliance or certification program of its own — no trust center, no SOC 2 / ISO 27001 / HIPAA / FedRAMP claim was found on affectiva.com — so no `Compliance` pointer is wired. Its market (affective computing / facial coding) has no machine-readable domain standard for a contract to declare, so domain_standard_conformance is recorded as not-applicable rather than failed; that field is reward-only. conformance: - id: openapi conforms: false evidence: >- All thirteen documents are Swagger 2.0 (`"swagger": "2.0"`), not OpenAPI 3.x. Real and parseable, but a generation behind. - id: swagger-2.0 conforms: true evidence: https://index.affectiva.com/swagger/templates/jobs.json - id: http-basic-auth conforms: true evidence: >- RFC 7617. Every document declares `securityDefinitions.basicAuth` with `type: basic`, and the live API answers `WWW-Authenticate: Basic realm="Affectiva Facial Coding API"` on https://index.affectiva.com/jobs (HTTP 401, observed 2026-09-12). - id: oauth2 conforms: false evidence: No oauth2 security definition in any document; /.well-known/oauth-authorization-server 404s on every host. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on www.affectiva.com, affectiva.com and index.affectiva.com. - id: rfc9457 conforms: false evidence: >- No application/problem+json response is declared anywhere in the spec set, and the live 401 returns a bare {"error":"Please login to continue."} envelope with content-type application/json. - id: rfc9116 conforms: false evidence: /.well-known/security.txt returns 404 on every Affectiva host. - id: idempotency conforms: false evidence: No Idempotency-Key header or replay-protection parameter appears in any of the 51 operations. - id: pagination conforms: false evidence: >- The collection operations (GET /jobs, GET /data_collection_projects, GET /entries/{entryID}) declare no page, per_page, limit, offset or cursor parameter — the only query parameters in the entire spec set are source/key/value on /entries/search_by_annotation and labeling_job_id on the labeling routes. - id: https-only conforms: false evidence: >- Every document lists `schemes: [https, http]`, advertising plaintext alongside TLS. The live host does send HSTS (max-age=15552000; includeSubDomains). - id: hsts conforms: true evidence: 'index.affectiva.com response header: Strict-Transport-Security: max-age=15552000; includeSubDomains' - id: request-id-tracing conforms: true evidence: >- index.affectiva.com returns an `X-Request-Id` UUID and an `X-Runtime` timing header on every response, including the 401. Neither is documented in the spec. domain_standard_conformance: applicable: false note: >- No machine-readable domain standard exists for facial coding / affective computing API contracts. Affectiva's science is described against FACS (the Facial Action Coding System) Action Units in its marketing and academic material, but FACS is a human coding taxonomy, not a wire format, and none of the thirteen contracts names it. Recording this as not-applicable rather than inventing a conformance. certifications: []