generated: '2026-08-06' method: searched source: https://aperia-technologies.secureframetrust.com/ note: >- Cross-cutting standards posture for Aperia Technologies and the Halo Connect Partner API. Compliance entries are read from Aperia's public Secureframe trust center; protocol entries are read from the published PDF API reference and from live probes of haloconnect.aperiatech.com on 2026-08-06. Absence is recorded as conforms:false with the probe that established it — nothing is asserted that was not observed. standards: - id: rfc7617-http-basic name: HTTP Basic authentication conforms: true evidence: >- "Authorization: Basic Base64_encoded_string ... Base64 string of email:password" (Halo Connect API Documentation v0.6, p.2) - id: oauth2 conforms: false evidence: >- No OAuth flows documented; /.well-known/oauth-authorization-server returns the SPA shell on haloconnect.aperiatech.com and 404 on aperiatech.com. - id: oidc conforms: false evidence: /.well-known/openid-configuration not served on any Aperia host. - id: openapi conforms: false evidence: >- No OpenAPI/Swagger document on any host; /openapi.json, /swagger.json, /v3/api-docs and /api-docs/swagger-config all return the 2,576-byte SPA shell, and /api/v3/api-docs is behind the blanket 401. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface is documented for the Partner API. - id: rfc9457-problem-details conforms: false evidence: >- Errors use a custom {"errorType","errorMessage"} envelope with no type URI and no application/problem+json media type — see errors/aperia-technologies-problem-types.yml. - id: rfc9110-conditional-requests conforms: partial evidence: >- If-Modified-Since is supported on /api/partner/v1/issues but takes an ISO 8601 "Z" datetime rather than an IMF-fixdate, and filters the collection instead of returning 304. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation headers; no deprecation policy published. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on aperiatech.com and the SPA shell on haloconnect.aperiatech.com. - id: rfc8615-well-known-uris conforms: false evidence: >- No /.well-known/* document is served. haloconnect.aperiatech.com answers every /.well-known/* path with a 200 HTML SPA shell identical to its catch-all, which is a soft-404 rather than a discovery document. - id: hsts-preload conforms: true evidence: >- haloconnect.aperiatech.com returns Strict-Transport-Security max-age=63072000; includeSubDomains; preload (observed 2026-08-06). - id: tls-1-3 conforms: true evidence: TLSv1.3 negotiated on aperiatech.com and haloconnect.aperiatech.com. - id: dnssec conforms: false evidence: aperiatech.com is not DNSSEC-signed (probe-domain-security.py, 2026-08-06). - id: soc2-type-ii name: SOC 2 Type II conforms: true evidence: Listed under Compliance on https://aperia-technologies.secureframetrust.com/ - id: iso-27001 name: ISO/IEC 27001 conforms: true evidence: Listed under Compliance on https://aperia-technologies.secureframetrust.com/ - id: iso-9001 name: ISO 9001 conforms: true evidence: >- Listed under Compliance on https://aperia-technologies.secureframetrust.com/ with a downloadable ISO 9001 certificate. - id: gdpr conforms: true evidence: Listed under Compliance on https://aperia-technologies.secureframetrust.com/ - id: ccpa conforms: true evidence: Listed under Compliance on https://aperia-technologies.secureframetrust.com/ - id: fmcsa-tire-inflation conforms: unknown evidence: >- Not asserted. Aperia markets Halo against commercial-vehicle tire maintenance practice but publishes no regulatory conformance claim for the API surface.