generated: '2026-08-11' method: derived source: >- openapi/anyimagedetector-ai-image-detector-openapi.yml (transcribed from https://imagedetector.online/docs), plus searches of https://imagedetector.online/privacy-policy, /terms-of-service, /about, /methodology and /accuracy-and-limitations for compliance claims. description: >- Cross-cutting standards conformance for the AI Image Detector API. AnyImageDetector claims NO certification, attestation or regulatory program anywhere on its public site — no SOC 2, no ISO 27001, no GDPR/DPA page, no HIPAA, no PCI, no trust center, no subprocessor list. The privacy policy asserts "industry-standard security measures" in prose with nothing named behind it. No `Compliance` pointer is wired into apis.yml, because there is no published program to point at. standards: - id: oauth2 conforms: false evidence: >- No OAuth 2.0 anywhere. Authentication is a static API key as Bearer token or x-api-key header. /.well-known/oauth-authorization-server returns 404. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404. No OpenID Connect surface. - id: rfc9457 conforms: false evidence: >- Errors are application/json with a flat { error, message } envelope, not application/problem+json. No type URI, title or instance member. - id: rfc9116 conforms: false evidence: /.well-known/security.txt returns 404. No published security contact or policy file. - id: rfc8594 conforms: false evidence: No Sunset or Deprecation header contract and no deprecation policy published. - id: rfc9239 conforms: false evidence: >- No RateLimit-* or X-RateLimit-* headers. Only Retry-After is returned, on 429. - id: idempotency conforms: false evidence: >- No Idempotency-Key header or de-duplication window documented on a billable POST. See conventions/anyimagedetector-conventions.yml. - id: pagination conforms: false not_applicable: true evidence: Single non-collection operation; nothing to paginate. - id: openapi conforms: false evidence: >- The provider publishes no OpenAPI. The spec in openapi/ is transcribed by API Evangelist from the provider's HTML reference and is marked as such in its x-provenance block. - id: json-schema conforms: partial evidence: >- Response and error shapes are fully enumerated in prose with closed enums, which is enough to express as JSON Schema — but the provider publishes no schema document. - id: tls conforms: true evidence: >- TLSv1.3, HTTPS-only, certificate valid to 2026-10-15. HSTS is NOT set. See security/anyimagedetector-domain-security.yml. - id: c2pa conforms: false evidence: >- Notable for the sector: an AI-image-detection service that neither reads nor reports C2PA / Content Credentials manifests. The response carries no provenance-signal field; the only structured output is a score, a verdict and a confidence label, and source_breakdown is documented as permanently empty. The Accuracy and Limitations page tells users to "check content credentials" as a separate step, confirming the API deliberately does not. certifications: [] compliance_programs: [] regulatory: gdpr: claimed: false note: >- Privacy policy states data-subject rights (access, update, export, delete) generically and names no legal basis, no controller entity, no DPO, no EU representative and no subprocessor list, despite disclosing that images are sent to unnamed "contracted processing services". ai_act: claimed: false note: >- No EU AI Act positioning, despite the service being an AI classification system used for fact-checking and fraud screening (both use cases the provider markets on /use-cases/journalists-fact-checkers and /use-cases/marketplace-scam-detection). model_transparency: methodology_page: https://imagedetector.online/methodology accuracy_page: https://imagedetector.online/accuracy-and-limitations published_accuracy_numbers: false published_verdict_thresholds: true note: >- The provider explicitly DECLINES to publish an accuracy percentage — "We do not currently publish a universal accuracy percentage. A single number would hide meaningful differences between generators, image styles, resolutions, and editing conditions" — and commits that future benchmarks will include the test set, date, transformations, and false-positive and false-negative rates. That is a deliberate, defensible stance rather than an omission. What IS published is the score-to-verdict threshold table (see data-model/anyimagedetector-data-model.yml), which makes the response fields interpretable. The model itself and the upstream "contracted processing services" that perform the detection are not named.