generated: '2026-08-13' method: derived source: >- openapi/_original/*.json, https://developer.brandcast.io/, https://support.timesites.com/en/articles/966545-security-overview and live probes of https://api.brandcast-prod.io/ summary: asserted: 2 not_conformant: 11 standards: - id: swagger-1.2 name: Swagger 1.2 API declaration conforms: true evidence: >- Brandcast publishes a valid Swagger 1.2 resource listing at https://s3.amazonaws.com/apidoc.brandcast-prod.io/resources.json (swaggerVersion "1.2", apiVersion "1.0.0") with four API declarations — account, salesforce, templates, websites — rendered by Swagger UI 1.x on https://developer.brandcast.io/. This is the contract format the provider actually publishes. - id: openapi-3 name: OpenAPI 3.x conforms: false evidence: >- No OpenAPI 3.x document is published. The four OpenAPI 3.1.0 documents in openapi/ are a mechanical conversion by this pipeline (method: derived) of the provider's Swagger 1.2 declarations, not something Brandcast ships. - id: https-only name: TLS-only transport conforms: true evidence: >- "API requests are authenticated via an API key that's specified in an x-api-key HTTP header and must be sent via HTTPS" (https://developer.brandcast.io/). All published basePaths are https. Domain probe: TLSv1.3 on www.brandcast.com — see security/brandcast-domain-security.yml. - id: oauth2 name: OAuth 2.0 conforms: false evidence: >- No OAuth flow is documented and no securityScheme of type oauth2 exists. Authentication is a static API key in the x-api-key header. Three export operations accept a bearer JWT in Authorization, but the JWT is described as internal to Design Studio and no authorization server, token endpoint or scope set is published. No scopes/ artifact is emitted. - id: oidc name: OpenID Connect conforms: false evidence: >- /.well-known/openid-configuration returns 403 on api.brandcast-prod.io and 404 on developer.brandcast.io — see well-known/brandcast-well-known.yml. - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: >- The error envelope is a proprietary single-field JSON object {"message": "..."} with content-type application/json, not application/problem+json. Observed 2026-08-13 on https://api.brandcast-prod.io/ (HTTP 403). - id: rfc8594 name: RFC 8594 Sunset header / deprecation signalling conforms: false evidence: >- No Sunset or Deprecation header is documented. One parameter (`tags` on the content endpoints) is marked "Deprecated." in prose only, with no sunset date — see lifecycle/brandcast-lifecycle.yml. - id: idempotency name: Idempotency keys on unsafe methods conforms: false evidence: >- No Idempotency-Key header or equivalent appears on any of the 26 operations. See conventions/brandcast-conventions.yml. - id: pagination name: Documented pagination conforms: partial evidence: >- limit/offset with a next-offset continuation value is documented on the two content-listing operations (getWebsiteContent, getTemplateContent) and on no others. getWebsites, getTemplates, getPublishJobs and getExportList publish no pagination at all. - id: rate-limit-headers name: RateLimit header fields (RFC 9331 / X-RateLimit-*) conforms: false evidence: >- No rate-limit headers or limits are documented — see rate-limits/brandcast-rate-limits.yml. - id: webhooks name: Webhooks / event callbacks conforms: false evidence: >- None published. Asynchronous publish and export work is delivered by client-side polling of a job id, not by callback. - id: json-api name: JSON:API conforms: false evidence: Responses are plain application/json with no JSON:API document structure. - id: soc2 name: SOC 2 conforms: false evidence: >- No certification is claimed. The provider's Security Overview describes AWS hosting, TLS, backups, hashed passwords and Stripe-handled payments, but names no audit or certification — see security/brandcast-trust-center.yml. No Compliance pointer is emitted. - id: gdpr name: GDPR / privacy compliance statement conforms: unknown evidence: >- The product site links California Consumer Privacy Rights, Cookie Policy and Privacy Policy pages, and the platform offers a GDPR cookie-notification feature to customers, but no GDPR compliance statement covering the API is published. Recorded as unknown rather than asserted either way.