generated: '2026-08-09' method: searched source: >- https://autoderm.ai/regulatory/, https://api.autoderm.ai/v1/label, https://docs.autoderm.ai/en/medical-device/eifu, and derived from openapi/autoderm-ai-dermatology-api-openapi.yml description: >- Autoderm's conformance posture is dominated by MEDICAL DEVICE REGULATION rather than by API standards. The device identification below is not a marketing claim — it is served by the API itself at GET /v1/label, which is an unusually strong form of evidence: the regulatory label is a live, anonymous, machine-readable endpoint. On the API-standards side the picture is thinner: modern OpenAPI 3.1 and RFC 6750 bearer auth, but no OAuth/OIDC, no RFC 9457 errors, and no RFC 8594 sunset headers. standards: - id: openapi-3.1 conforms: true evidence: >- openapi: 3.1.0 served at https://api.autoderm.ai/openapi.json and https://docs.autoderm.ai/openapi.json (byte-identical documents). - id: rfc6750-bearer-token conforms: true evidence: >- components.securitySchemes.HTTPBearer is type http / scheme bearer; docs specify "Authorization: Bearer YOUR_API_TOKEN". caveat: >- The 401 response does not carry a WWW-Authenticate challenge header, which RFC 6750 §3 expects. - id: icd-10 conforms: true evidence: >- Every DiseasePrediction carries a required icd_10 field, and each DiseaseCatalogEntry is keyed by icd_10. ICD-10 coding is the interchange identifier for the entire prediction surface. - id: fitzpatrick-skin-type conforms: true evidence: >- SkinToneModelResponse.fitzpatrick is an integer 1-6 ("1 is lightest and 6 is darkest") from POST /v1/infer-skin-tone/v1 and optionally inlined in the disease response via include_skin_tone. - id: dicom conforms: partial evidence: >- DICOM is listed among accepted upload formats in both the getting-started page and the eIFU. Ingest only — Autoderm exposes no DICOMweb service, no SOP class conformance statement, and returns JSON rather than DICOM SR. - id: semver conforms: true evidence: >- https://docs.autoderm.ai/en/support/api-versioning states the API follows Semantic Versioning; GET /version returns 2.3.6. - id: eu-mdd-93-42-eec conforms: true evidence: >- "CE-marked under EU MDD 93/42/EEC as a legacy Class I Medical Device" (https://autoderm.ai/regulatory/). Confirmed live by GET https://api.autoderm.ai/v1/label -> ce_mark "MDD Class I". - id: eu-mdr-2017-745 conforms: partial evidence: >- "currently transitioning to MDR Class IIa under EU MDR 2017/745, with the technical file submission planned for 2026". Operates under Article 120 legacy provisions until the transition completes. PMCF studies performed under MDR Annex XIV. status: in-transition - id: fda-breakthrough-device-designation conforms: true evidence: >- "Autoderm holds FDA Breakthrough Device Designation for AI-powered dermatology screening." caveat: >- A Breakthrough Device Designation is NOT a clearance or approval. Public material describes a 510(k) submission as under review; there is no cleared 510(k) number published. - id: udi conforms: true evidence: >- GET https://api.autoderm.ai/v1/label returns unique_device_identifier "(01)4262385680024(10)2.3.6(11)20260803" — GS1 application identifiers for GTIN (01), lot/version (10) and manufacture date (11). - id: eifu-2021-2226 conforms: true evidence: >- Electronic Instructions For Use published at https://docs.autoderm.ai/en/medical-device/eifu and referenced from the device label field eifu ("Read the (electronic) Instructions for Use before use."). - id: gdpr conforms: claimed evidence: >- "Images are processed anonymously within EU infrastructure. No personal data linkage occurs within" Autoderm; a Data Processing Agreement (DPA) is offered defining Autoderm as processor and the platform as controller. Health images are acknowledged as potential Article 9 special category data. caveat: Self-asserted on the regulatory page; no certification or audit report published. - id: rfc9457-problem-details conforms: false evidence: >- Errors are FastAPI's {"detail": ...} envelope served as application/json, not application/problem+json. No type/title/instance members. - id: oauth2 conforms: false evidence: >- No oauth2 securityScheme in the spec; /.well-known/oauth-authorization-server returned 404. - id: oidc conforms: false evidence: /.well-known/openid-configuration returned 404 on api.autoderm.ai. - id: rfc8594-sunset-header conforms: false evidence: >- A 90-day deprecation notice policy is published in prose, but no Sunset or Deprecation response header is documented or observed. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returned 404 on api.autoderm.ai and autoderm.ai. - id: fhir conforms: false evidence: No FHIR resource shapes, endpoints, or CapabilityStatement. - id: hl7-v2 conforms: false - id: hipaa conforms: unclaimed evidence: >- No HIPAA, BAA, SOC 2, ISO 13485 or ISO 27001 claim appears on https://autoderm.ai/regulatory/ or anywhere else on the public site. Recorded as unclaimed rather than false — absence of a published claim is not evidence of non-compliance. - id: json-api conforms: false - id: scim conforms: false - id: odata conforms: false manufacturer: note: >- Two different legal entities appear in Autoderm's own public material. Recorded as found, unreconciled. device_label_entity: iDoc24 AB, Berzeliigatan 25, 41253 Gothenburg, Sweden. device_label_source: https://api.autoderm.ai/v1/label regulatory_page_entity: Autoderm Inc., 2991 Sacramento St, Unit #183, Berkeley, CA 94702, USA regulatory_page_source: https://autoderm.ai/regulatory/ sla_entity: Autoderm, Inc. uk_responsible_person: >- Easy Medical Device Limited, Atlantic Business Centre, Atlantic Street, Broadheath, Altrincham, United Kingdom, WA14 5NQ post_market_surveillance: claim: >- "Post-market surveillance data covers over two million API calls with zero adverse events reported across MHRA, BfArM, and FDA MAUDE database reviews." source: https://autoderm.ai/regulatory/ certifications_published: - CE mark (MDD 93/42/EEC, Class I legacy) - FDA Breakthrough Device Designation not_published: - ISO 13485 - ISO 27001 - SOC 2 - HIPAA / BAA - UKCA - Notified Body number