generated: '2026-08-09' method: derived source: >- openapi/cloudsight-images-openapi.yml, authentication/cloudsight-authentication.yml, conventions/cloudsight-conventions.yml, and live probes of the CloudSight hosts (2026-08-09) description: >- Which cross-cutting standards the CloudSight API actually conforms to. Almost every modern API convention is absent: the contract predates them (last changed 2018) and the surface is three operations wide. standards: - id: rest conforms: true evidence: >- Resource-oriented HTTPS API with JSON and multipart request bodies and JSON responses, documented in API Blueprint 1A. - id: openapi conforms: false evidence: >- CloudSight publishes no OpenAPI. openapi/cloudsight-images-openapi.yml is an API Evangelist conversion of the provider's API Blueprint, not a provider artifact. - id: api-blueprint-1a conforms: true evidence: >- https://cloudsight.docs.apiary.io/api-description-document returns FORMAT: 1A, content-type text/vnd.apiblueprint+markdown. - id: oauth1-rfc5849 conforms: true evidence: >- Documented "OAuth1-Simple" method — signature over key, secret, nonce, URL and parameters in the Authorization header, with `image` excluded from the signature. CloudSight cites RFC 5849 directly. - id: oauth2 conforms: false evidence: No oauth2 securityScheme and no OAuth 2.0 documentation. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on api.cloudsight.ai. - id: rfc9457-problem-details conforms: false evidence: >- Errors use a proprietary {"error": {field: [messages]}} envelope with content-type application/json, not application/problem+json. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on api.cloudsight.ai. - id: rfc8594-sunset-header conforms: false evidence: No deprecation or sunset policy is published. - id: rfc8615-well-known conforms: false evidence: No /.well-known/ document is served on any CloudSight host. - id: idempotency-key conforms: false evidence: No idempotency key or replay semantics documented. - id: pagination conforms: false evidence: No collection endpoint exists. - id: webhooks conforms: false evidence: Completion is discovered by polling; no callback delivery documented. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface exists to describe. - id: hsts conforms: false evidence: >- No Strict-Transport-Security header observed on cloudsight.ai — see security/cloudsight-domain-security.yml. - id: dnssec conforms: false evidence: No DNSKEY on cloudsight.ai — see security/cloudsight-domain-security.yml. - id: caa conforms: false evidence: No CAA record on cloudsight.ai. - id: spf conforms: true evidence: SPF record present on cloudsight.ai. - id: dmarc conforms: partial evidence: DMARC record present with policy p=none (monitoring only, no enforcement). compliance_program: published: false certifications: [] trust_center: null note: >- No SOC 2, ISO 27001, HIPAA, PCI or GDPR posture is published on any CloudSight page reachable without an account, and probes for trust., security. and /trust, /security, /compliance found nothing. No `Compliance` pointer is wired.