generated: '2026-07-18' method: derived source: openapi/brl-openapi-original.json standards: - id: openapi-3.1 conforms: true evidence: openapi field is 3.1.0 - id: jwt-rfc7519 conforms: true evidence: Authorization Bearer JWT (RS256), self-signed per request with bound claims - id: oauth2 conforms: false evidence: No oauth2 securityScheme; authorization is capability-based - id: openid-connect conforms: false evidence: No openIdConnect scheme; no working /.well-known/openid-configuration - id: rfc9457-problem-details conforms: false evidence: 'Errors use a custom { error: { type, message, code } } envelope, not application/problem+json' - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns the SPA HTML shell, not an RFC 9116 document - id: hmac-webhook-signing conforms: true evidence: Webhooks signed with X-Crown-Signature HMAC-SHA256 over the body - id: pix conforms: true evidence: BRL deposits/withdrawals over PIX (Brazilian instant payments); static PIX BR Code (EMV) endpoint - id: ted conforms: true evidence: BRL withdrawals via TED (Brazilian wire transfer) - id: evm-erc20 conforms: true evidence: BRLV/wBRLY/USDC/USDT tokens on Base and Ethereum mainnet; EVM (0x...) wallet addresses regulatory: authorization: Temporary Virtual Asset Service Provider (PSAV) authorization under the Banco Central do Brasil reserves: BRLV backed 1:1 by Brazilian federal government bonds in a bankruptcy-remote structure; daily third-party audits (per public claims) note: >- Regulatory posture is a public marketing/whitepaper claim, not a named security certification (SOC 2 / ISO 27001 / PCI DSS were not found), so no `Compliance` pointer is emitted.