generated: '2026-07-17' method: derived source: openapi/altimate-ai-openapi-original.json # Cross-cutting / industry standards conformance. Derived from the OpenAPI plus the # published Security & Compliance FAQ (SOC 2 Type II). standards: - id: openapi-3.1 conforms: true evidence: openapi.json declares openapi 3.1.0 - id: oauth2 conforms: false evidence: only HTTPBearer (http bearer) securityScheme present; no oauth2 flows - id: oidc conforms: false - id: rfc9457-problem-details conforms: false evidence: 'errors use the FastAPI detail envelope, not application/problem+json' - id: soc2-type-ii conforms: true evidence: Security & Compliance FAQ states audited annually (SOC 2 Type II) - id: gdpr conforms: true evidence: metadata-only data handling; DPAs on request per Security FAQ - id: idempotency conforms: false evidence: no Idempotency-Key contract documented or in the OpenAPI