generated: '2026-08-08' method: searched source: https://www.bvnk.com/compliance + https://docs.bvnk.com/ standards: - id: oauth2 conforms: true evidence: Layer1 Digital Asset OpenAPI declares an oauth2 clientCredentials scheme; Keycloak realm publishes 10 grant types. - id: oidc conforms: true evidence: openIdConnect securityScheme plus live OIDC discovery documents on auth.layer1.com and auth.sandbox.layer1.com. - id: rfc8414-oauth-authorization-server-metadata conforms: false evidence: /.well-known/oauth-authorization-server is not served; discovery is OIDC-only. - id: rfc9421-http-message-signatures conforms: true evidence: httpSignature securityScheme in the Layer1 spec; layer1-mcp-digital signs requests with @ltonetwork/http-message-signatures. - id: hawk-http-authentication conforms: true evidence: BVNK API authenticates with Hawk HMAC-SHA256 request signing (Authorization header). - id: rfc9457-problem-details conforms: false evidence: Errors use a proprietary {code,status,traceId,message,details} envelope; no application/problem+json in either spec. - id: rfc8594-sunset-header conforms: false evidence: No Sunset/Deprecation response headers documented; deprecation is communicated by inline notices and migration guides. - id: idempotency-key conforms: true evidence: X-Idempotency-Key (Idempotency-Key on v.2 endpoints), UUID-formatted, documented replay semantics. - id: pagination conforms: true evidence: page/size/sort/offset query parameters with a Spring Pageable response envelope. - id: openapi-3 conforms: true evidence: OpenAPI 3.0.3 (BVNK API Endpoints 1.0.1) and OpenAPI 3.1.0 (Digital Asset 1.0.0) published in the bvnk GitHub org. - id: asyncapi conforms: false evidence: Webhook catalog is documented but no AsyncAPI document is published. - id: psd2 conforms: true evidence: Third-party provider (TPP) reference documents PSD2 obligations; BVNK is a regulated EMI in the UK (FCA) and Malta (MFSA). - id: fatf-travel-rule conforms: true evidence: Travel Rule information requests, originator submission endpoint and compliance-information-request webhook. - id: iso-27001 conforms: true evidence: ISO 27001:2022 certified per https://www.bvnk.com/compliance - id: soc2-type-ii conforms: true evidence: SOC 2 Type II certified per https://www.bvnk.com/compliance - id: dora conforms: true evidence: Stated DORA compliance per https://www.bvnk.com/compliance - id: iso-4217 conforms: true evidence: Currency codes are ISO-4217 across payment and simulator payloads. - id: fhir-r4 conforms: false - id: scim2 conforms: false - id: odata conforms: false - id: json-api conforms: false