generated: '2026-08-29' method: derived source: >- openapi/blue-prism-enterprise-api-openapi.yml (Blue Prism API 7.5.1), https://documentation.blueprism.com/bp-7-5/en-us/Guides/bp-api/api-configuration.htm, https://www.blueprism.com/blue-prism-security/, https://www.blueprism.com/.well-known/security.txt provider: Blue Prism providerId: blue-prism entries: - id: openapi conforms: true version: 3.0.3 evidence: >- Published OpenAPI 3.0.3 contract, 67 paths / 94 operations / 136 component schemas, embedded in the ReDoc reference at https://documentation.blueprism.com/bp-7-5/en-us/bp-api/bpe-7-5-1-api-spec.html - id: oauth2 conforms: true evidence: >- components.securitySchemes.OAuth2 declares the clientCredentials flow with tokenUrl /connect/token and scopes bp-api and bpserver. Applied globally via the top-level security block. - id: jwt-bearer conforms: true evidence: >- components.securitySchemes.Bearer — type http, scheme bearer, bearerFormat JWT, "JWT token issued from Authentication Server." - id: oidc conforms: partial evidence: >- Blue Prism Authentication Server exposes an IdentityServer-style /connect/token endpoint and the product documents OIDC/SAML external identity providers, but the API contract declares no openIdConnect securityScheme and no discovery document is publicly reachable (every /.well-known/openid-configuration probe on Blue Prism's public hosts returned 404). The discovery document, where it exists, is served by each customer's own installation. - id: rfc9457 conforms: false evidence: >- No application/problem+json anywhere in the contract. Errors use bare strings and bespoke objects — see errors/blue-prism-problem-types.yml. - id: rfc8594-sunset conforms: false evidence: No Sunset or Deprecation header is declared, and no deprecation policy is published. - id: idempotency conforms: false evidence: >- No Idempotency-Key header on any of the 43 write operations, and no idempotency semantics in the documentation. - id: pagination conforms: true style: opaque cursor evidence: >- pagingToken + itemsPerPage + sortBy query parameters on all 22 collection operations; PagingToken schema returned in the response. - id: rest-patch conforms: partial evidence: >- PatchRequest / PatchDocument schemas follow an RFC 6902-shaped path/value model, but the contract does not declare application/json-patch+json as the media type. - id: json-api conforms: false evidence: Plain application/json resource representations; no JSON:API document structure. - id: odata conforms: false evidence: No $metadata surface, no OData query options. - id: scim conforms: false evidence: >- No SCIM schema URNs. User management is not exposed by this API — the only user-facing operation is GET /api/v7/user/permissions. - id: soap-wsdl conforms: partial evidence: >- Blue Prism Enterprise can publish automations as SOAP web services, and the Automate.exe /wslocationprefix switch exists specifically to override "the displayed addressable location of published web services and the associated resources such as WSDLs hosted on this device" (https://documentation.blueprism.com/bp-7-5/en-us/helpCommandLine.htm). Those WSDLs are generated per customer automation on the customer's own runtime resource, so there is no vendor-published WSDL to capture and none has been authored here. domain_standards: market: enterprise RPA / intelligent process automation applicable_standard_found: false note: >- REWARD-ONLY check, left empty deliberately. Enterprise RPA has no interoperability standard for bot/queue/process contracts — no equivalent of FHIR, SCIM, OData, OpenRTB or ISO 20022 governs this market, and Blue Prism's contract declares none. The vocabulary in the spec (work queues, sessions, digital workers, schedules) is Blue Prism's own product model. Nothing is being penalised: there is no standard here to conform to. compliance: published: true source: https://www.blueprism.com/blue-prism-security/ certifications: - name: ISO/IEC 27001 status: certified evidence: >- BSI Certificate of Registration published as https://files.blueprism.com/downloads/public/data-sheets/2.1-ISO-27001-SSC-Blue-Prism-Certificate-2026.pdf (the page text renders the standard number as "ISO270001", a typo on the provider's page) - name: Cyber Essentials status: certified evidence: https://files.blueprism.com/downloads/public/data-sheets/6.1-Cyber-Essentials-Certificate-2026.pdf frameworks_aligned: - name: NIST Risk Management Framework status: aligned evidence: >- "We employ a comprehensive set of controls and monitors, which are implemented according to industry best practice, such as the NIST risk management framework." - name: OWASP status: aligned evidence: Secure Code Warrior developer training content aligned to NIST, OWASP and PCI. - name: PCI status: aligned-only evidence: Named as training-content alignment. NO PCI DSS certification is claimed. not_claimed: - SOC 2 — no SOC 2 report or attestation is referenced anywhere on the public site. - HIPAA — not claimed, despite healthcare being a named industry solution. - FedRAMP — not claimed, despite public sector being a named industry solution. maintainers: - FN: Kin Lane email: kin@apievangelist.com