generated: '2026-07-18' method: derived source: openapi/compresr-openapi-original.json standards: - id: openapi-3.1 conforms: true evidence: Publishes an OpenAPI 3.1.0 document at https://api.compresr.ai/openapi.json (Compresr Platform API v1.0.0). - id: oauth2 conforms: true evidence: Runs an OAuth 2.0 authorization server (/oauth/authorize, /oauth/token, /oauth/device_authorization) with authorization-code, device-code, and refresh-token grants. - id: oauth2-pkce conforms: true evidence: /oauth/authorize accepts code_challenge + code_challenge_method; token exchange accepts code_verifier (RFC 7636). - id: oauth2-device-flow conforms: true evidence: /oauth/device_authorization + /oauth/device/decision (RFC 8628). - id: api-key-auth conforms: true evidence: X-API-Key header with cmp_-prefixed keys on all authenticated endpoints. - id: server-sent-events conforms: true evidence: Streaming endpoints (paths ending /stream) return text/event-stream. - id: rfc9457-problem-details conforms: false evidence: Errors use a custom { success, data, error } envelope, not application/problem+json. - id: rate-limit-headers conforms: true evidence: Responses carry X-RateLimit-Limit/Remaining-Minute/Day + X-RateLimit-Tier; 429 carries Retry-After. - id: oidc-discovery conforms: false evidence: No /.well-known/openid-configuration or /.well-known/oauth-authorization-server (both 404). - id: rfc9116-security-txt conforms: false evidence: No /.well-known/security.txt on either host (404). compliance_program: published: false note: >- No public certifications (SOC 2 / ISO 27001 / PCI / HIPAA / FedRAMP) or trust center were found (2026-07-18). No Compliance pointer is wired — this file asserts standards conformance only, not a published compliance program.