generated: '2026-07-18' method: searched source: https://security.catonetworks.com/ standards: - id: graphql conforms: true evidence: Public API is served as GraphQL at api/v1/graphql2. - id: apikey-auth conforms: true evidence: Authentication via x-api-key header (see authentication/). - id: oauth2 conforms: false evidence: No OAuth 2.0 authorization surface; API-key auth only. - id: oidc conforms: false evidence: No /.well-known/openid-configuration published. - id: rfc9457-problem-details conforms: false evidence: Errors use the GraphQL errors[] envelope, not application/problem+json. - id: soc2-type2 conforms: true evidence: SOC 2 Type II reported on the Cato Trust Center (security.catonetworks.com). - id: iso-27001 conforms: true evidence: ISO 27001 reported on the Cato Trust Center. - id: pci-dss conforms: true evidence: PCI DSS reported on the Cato Trust Center. - id: hipaa conforms: true evidence: HIPAA reported on the Cato Trust Center. - id: gdpr conforms: true evidence: GDPR reported on the Cato Trust Center. - id: csa-star conforms: true evidence: CSA STAR reported on the Cato Trust Center.