generated: '2026-08-09' method: searched source: https://claimgenius.com/geniusapi note: >- Assessed against the provider's own public statements only. Claim Genius publishes no OpenAPI, no reference documentation and no trust center, so most standards below cannot be assessed either way and are recorded as unknown rather than false — absence of evidence, not evidence of absence. standards: - id: oauth2 conforms: false evidence: >- Authentication is a JWT issued from an API ID + secret at /api/auth/token. No OAuth 2.0 grant, authorization endpoint or scope model is documented, and /.well-known/oauth-authorization-server returns no document on any host. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns no document on any host (soft 404 / nginx 404). - id: jwt-rfc7519 conforms: true evidence: >- Provider states "JWT-based authentication ... with unique API IDs and secrets ensures each session is protected" on https://claimgenius.com/geniusapi. - id: rest-json conforms: true evidence: >- Provider states "Clean RESTful design with predictable JSON structures" and returns "structured JSON outputs for decision automation, estimates, and reporting". - id: openapi conforms: unknown evidence: >- The company advertises an "OpenAPI 3.0 spec" on its homepage, but no spec is published at any public URL. Probed /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs, /redoc and /v2/api-docs on api.claimgenius.com (all 404) and on claimgenius.com (all SPA soft 404). Claimed, not verifiable. - id: rfc9457-problem-details conforms: unknown evidence: No public error reference or error envelope documentation. - id: asyncapi conforms: false evidence: >- The event model is submit-and-poll (queue ID then GET /api/pipeline/requests/{requestId}); no webhooks, no streaming surface, no AsyncAPI document. - id: gdpr conforms: claimed evidence: >- "GDPR-compliant — Data handling and audit trail visibility for enterprise clients." Stated on https://claimgenius.com/geniusapi. A marketing claim on a product page; no DPA, certification, or trust center is published. - id: soc2 conforms: unknown evidence: No SOC 2 claim found on any public page; no trust center (trust.claimgenius.com 404). - id: iso-27001 conforms: unknown evidence: No ISO 27001 claim found on any public page. - id: hipaa conforms: unknown evidence: Not applicable to the stated use cases and not claimed. - id: pci-dss conforms: unknown evidence: Not applicable — no payment surface. Not claimed. compliance_program: published: false trust_center: null certifications: [] claims: - GDPR-compliant note: >- The only published compliance posture is the GDPR badge on the GeniusAPI page. No certification document, audit report, subprocessor list or trust center exists at a public URL. x-evidence: - url: https://claimgenius.com/assets/GeniusApiPage-2efvqe5o.js http_status: 200 fetched: '2026-08-09' - url: https://api.claimgenius.com/openapi.json http_status: 404 fetched: '2026-08-09' - url: https://trust.claimgenius.com/ http_status: 404 fetched: '2026-08-09'