generated: '2026-07-22' method: searched source: bmll Python SDK 1.24.7 source + https://www.bmlltech.com/news/our-news/bmll-awarded-iso-27001-certification standards: - id: iso-27001 conforms: true evidence: BMLL announced ISO 27001 certification for its information security management system covering the UK development, operation and administration of BMLL Vantage, Data Feed, Data Lab and Exchange Market Participant Analytics (provider announcement, https://www.bmlltech.com/news/our-news/bmll-awarded-iso-27001-certification). method: searched - id: oauth2 conforms: false evidence: Authentication is a proprietary key-pair signed-JWT handshake, not OAuth 2.0 (bmll SDK _rest.py; no oauth endpoints, no /.well-known/oauth-authorization-server). method: derived - id: oidc conforms: false evidence: No OpenID Connect discovery document on any host (/.well-known/openid-configuration is a 401 or an SPA shell). method: derived - id: rfc6750-bearer-token conforms: true evidence: Access tokens are presented as "Authorization Bearer " headers on every request (bmll SDK _rest.py get_auth_headers). method: derived - id: rfc9457-problem-details conforms: false evidence: Errors use a bare {"message" ...} JSON envelope, not application/problem+json. method: derived - id: jwt-rfc7519 conforms: true evidence: Login exchanges JWT claims (iss/aud/exp/sid) signed with the user's PEM private key (bmll SDK _rest.py _get_auth_token; imports pyjwt + cryptography). method: derived notes: | BMLL is an institutional market-data vendor; no FAPI/PSD2/FHIR/SCIM/OData claims were found and none are asserted. ISO 27001 is the published compliance program (also the basis of the Compliance pointer in apis.yml).