generated: '2026-09-04' method: searched source: https://assertible.com/docs provider: Assertible providerId: assertible description: >- Cross-cutting standards conformance for Assertible's OWN API. Assertible is an API testing and monitoring tool, so it CONSUMES several standards on behalf of its customers (OpenAPI, Swagger, Postman Collection, JSON Schema, JSON Path, OAuth 1.0a and OAuth 2.0 against the service under test). Those are recorded separately under `consumed_standards` and are NOT conformance claims about Assertible's own interface. conformance: - id: http-basic-rfc7617 name: HTTP Basic authentication (RFC 7617) conforms: true evidence: >- Every documented operation authenticates with HTTP Basic, token as username and empty password, per https://assertible.com/docs/guide/deployments - id: rfc9457 name: Problem Details for HTTP APIs (RFC 9457 / RFC 7807) conforms: false evidence: >- Errors use a custom {"code","message"} envelope with Content-Type application/json, observed live 2026-09-04. No application/problem+json. - id: oauth2 name: OAuth 2.0 on Assertible's own API conforms: false evidence: >- No OAuth on Assertible's API. /.well-known/oauth-authorization-server returns 404 (probed 2026-09-04). Assertible's OAuth 2.0 support is a feature for authenticating to the customer's API under test. - id: oidc name: OpenID Connect conforms: false evidence: /.well-known/openid-configuration returns 404 (probed 2026-09-04). - id: rfc8594 name: Sunset HTTP header (RFC 8594) conforms: false evidence: No Sunset or Deprecation header documented or observed. - id: rfc9116 name: security.txt (RFC 9116) conforms: false evidence: /.well-known/security.txt returns 404 on all four first-party hosts. - id: idempotency-key name: Client-supplied idempotency key (draft-ietf-httpapi-idempotency-key-header) conforms: false evidence: >- No Idempotency-Key header. Replay safety is provided by natural keys the caller already controls. See conventions/assertible-conventions.yml - id: rate-limit-headers name: RateLimit header fields for HTTP (draft-ietf-httpapi-ratelimit-headers) conforms: false evidence: >- No RateLimit-* or X-RateLimit-* headers observed on live responses (probed 2026-09-04); Assertible publishes no request-rate limit. - id: pagination name: Pagination conforms: false evidence: The documented API has no collection or list operations. - id: json-api name: JSON:API conforms: false evidence: Plain JSON payloads; no JSON:API document structure. - id: openapi name: OpenAPI description of Assertible's own API conforms: false evidence: >- Assertible publishes no OpenAPI, Swagger or Postman collection for its own API. /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs and /redoc all return 404 (probed 2026-09-04), and https://assertible.com/docs/api reads "Our api is under construction right now." The specs in openapi/ were generated by API Evangelist from Assertible's published parameter tables and curl examples. domain_standard: applicable: false note: >- API testing and synthetic monitoring has no adopted domain interchange standard (no SCIM/OData/OpenRTB/FHIR analogue), so there is nothing to conform to and nothing is being withheld. REWARD-ONLY check: not scored against Assertible. consumed_standards: - id: openapi-import name: OpenAPI 3.x import and sync supported: true evidence: https://assertible.com/docs/guide/web-services note: Imports v2 and v3 in JSON or YAML; creates a test per method/endpoint. - id: swagger-import name: Swagger 2.0 import and sync supported: true evidence: https://assertible.com/docs/guide/sync - id: postman-collection-import name: Postman Collection import and sync supported: true evidence: https://assertible.com/docs/guide/sync - id: json-schema-assertions name: JSON Schema response assertions supported: true evidence: >- https://assertible.com/json-schema-validation and https://assertible.com/blog/automatically-import-openapi-v3-response-json-schema-assertions - id: jsonpath name: JSON Path assertions supported: true evidence: https://assertible.com/docs/guide/json-path - id: graphql name: GraphQL request editor support (for the service under test) supported: true evidence: https://assertible.com/blog/new-feature-support-for-testing-graphql-apis compliance: certifications: [] trust_center: null note: >- No SOC 2, ISO 27001, PCI, HIPAA or FedRAMP claim is published anywhere on assertible.com, and no trust center exists. /security returns 404 (probed 2026-09-04). No Compliance pointer is emitted.