generated: '2026-09-04' method: derived source: >- openapi/budibase-public-api-openapi.yml, https://budibase.com/security, https://budibase.com/pricing.json, live responses observed 2026-09-04 description: >- Cross-cutting standards conformance for Budibase, asserted only where evidence exists. Budibase operates in the low-code / internal-tooling market, which has no domain interchange standard of its own — there is no FHIR, ISO 20022 or OpenRTB equivalent for "internal app builder" — so the domain-standard slot is genuinely empty rather than unfilled. It is left as not_applicable rather than invented. conformance: - id: openapi name: OpenAPI Specification version: 3.1.0 conforms: true evidence: >- Budibase publishes and maintains its own OpenAPI 3.1.0 in-repo at packages/server/specs/openapi.yaml and openapi.json, and its documentation directs integrators to it by URL for Postman and Insomnia import. evidence_url: https://github.com/Budibase/budibase/blob/master/packages/server/specs/openapi.yaml - id: rfc9457 name: Problem Details for HTTP APIs conforms: false evidence: >- Errors are returned as application/json with a proprietary { message, status } envelope, not application/problem+json. Observed live 2026-09-04. evidence_url: errors/budibase-problem-types.yml - id: rfc8594 name: Sunset HTTP Header conforms: false evidence: No Sunset or Deprecation header is returned and no deprecation policy is published. evidence_url: lifecycle/budibase-lifecycle.yml - id: idempotency name: Idempotent write semantics conforms: false evidence: >- No Idempotency-Key header or equivalent on any of the 27 mutating operations. evidence_url: conventions/budibase-conventions.yml - id: pagination name: Documented pagination conforms: partial evidence: >- Bookmark/hasNextPage cursor pagination is fully specified for rowSearch and rowViewSearch, and a separate page/limit model exists for queryExecute. The other six search operations return an unpaged data[] with no documented ceiling. evidence_url: conventions/budibase-conventions.yml - id: rate-limit-headers name: Rate limit response signaling conforms: partial evidence: >- X-RateLimit-Limit / -Remaining / -Reset are emitted on every response, observed live 2026-09-04. These are the legacy X-RateLimit-* family, not the IETF RateLimit-* draft headers, and no Retry-After is sent. evidence_url: rate-limits/budibase-rate-limits.yml - id: oauth2 name: OAuth 2.0 conforms: false evidence: >- The Public API authenticates with a single static API key header (x-budibase-api-key, securityScheme type apiKey). No OAuth 2.0 flows, no token endpoint, no /.well-known/oauth-authorization-server on any host — probed 2026-09-04, all 404/502. evidence_url: well-known/budibase-well-known.yml - id: oidc name: OpenID Connect conforms: partial evidence: >- OIDC is supported as an INBOUND single-sign-on method for Budibase end users ("SSO — integrate with auth tools including OpenID Connect", budibase.com/security) on every plan including open source. Budibase is an OIDC relying party, not an OIDC provider, and OIDC plays no part in Public API authentication. No /.well-known/openid-configuration is served on any Budibase host. evidence_url: https://budibase.com/security - id: scim name: SCIM 2.0 conforms: partial evidence: >- pricing.json lists "Active directory sync (SCIM)" as an Enterprise-tier feature, and budibase.com/security advertises "SCIM & AD". But no SCIM schema URN (urn:ietf:params:scim:schemas:*) appears in the Public API contract and no SCIM endpoint is published — the capability is a product feature, not a declared contract. A buyer who already speaks SCIM cannot verify the shape without a sales conversation. evidence_url: https://budibase.com/pricing.json - id: iso27001 name: ISO/IEC 27001 conforms: true evidence: >- "ISO 27001 Certified" stated in the site footer and on the security page ("Enterprise-grade security certifications to meet your compliance requirements"). evidence_url: https://budibase.com/security - id: gdpr name: GDPR conforms: true evidence: >- "GDPR Compliant" stated in the site footer; Budibase Cloud runs entirely in the EU (Ireland) and markets EU digital sovereignty as a positioning. evidence_url: https://budibase.com/security - id: soc2 name: SOC 2 conforms: false evidence: >- DELIBERATELY FALSE. budibase.com/security says "All servers are hosted within the EU (Ireland) in data centers certified by SOC 1/2 and ISO 27001" — that is a statement about the AWS data centres, NOT about Budibase's own controls. Budibase does not claim a SOC 2 report of its own anywhere on its site. Recorded explicitly so the inherited-certification wording is not later mistaken for a Budibase attestation. evidence_url: https://budibase.com/security - id: tls13 name: TLS 1.3 conforms: true evidence: >- TLSv1.3 negotiated on budibase.com, docs.budibase.com and budibase.app; HSTS max-age 31536000 with includeSubDomains and preload observed on the API host. evidence_url: security/budibase-domain-security.yml domain_standard: applicable: false market: low-code application platform / internal tooling detail: >- This market has no interchange standard for a provider's contract to declare. No SCIM URN, OData $metadata surface, OpenRTB endpoint, HL7/X12/ISO-20022 message type, ActivityPub actor, LTI/OneRoster shape or OAI-PMH verb appears in the Budibase contract, and none would be expected to. Scored not_applicable, not zero. maintainers: - FN: Kin Lane email: kin@apievangelist.com