generated: '2026-08-09' method: derived source: >- openapi/connext-everclear-openapi.yml, https://docs.everclear.org/developers/api.md, https://docs.everclear.org/developers/audits.md, https://github.com/everclearorg/audits summary: >- Everclear published no compliance program, no certifications and no trust center. What it did publish is smart-contract security auditing, which is the crypto-native equivalent and is recorded here — but it is not a SOC 2 / ISO 27001 style attestation and no `Compliance` pointer is emitted for it. standards: - id: openapi-3.0 conforms: true evidence: >- 17 OpenAPI 3.0.1 documents published at https://docs.everclear.org/developers/api.md, merged verbatim into openapi/connext-everclear-openapi.yml. - id: oauth2 conforms: false evidence: No oauth2 securityScheme in any published document; no /.well-known/oauth-authorization-server. - id: oidc conforms: false evidence: No /.well-known/openid-configuration on any host. - id: rfc9457-problem-details conforms: false evidence: >- Errors are a flat application/json {error, message} object, not application/problem+json. See errors/connext-problem-types.yml. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on docs.everclear.org and www.connext.network, 530 on api.everclear.org. - id: rfc8594-sunset-header conforms: false evidence: No Sunset/Deprecation header support documented; no deprecation policy published. - id: cursor-pagination conforms: partial evidence: >- Four of five collection endpoints use cursor/prevCursor/limit with nextCursor/prevCursor/maxCount; GET /configs/assets uses required page+limit instead. - id: idempotency-key conforms: false evidence: >- No Idempotency-Key header or equivalent. POSTs are transaction builders, so replay protection is on-chain (EVM nonce, Permit2 nonce). See conventions/connext-conventions.yml. - id: json-api conforms: false evidence: Plain JSON objects, no JSON:API document structure. - id: graphql conforms: partial evidence: >- Everclear published Goldsky subgraphs with a documented entity schema (graphql/connext-everclear-subgraph.graphql), but every documented query URL returned HTTP 404 "Subgraph not found" on 2026-08-09. - id: asyncapi conforms: false evidence: No event or webhook surface of any kind. - id: erc7683-cross-chain-intents conforms: unknown evidence: >- The API's intent vocabulary (origin, destinations, inputAsset, outputAsset, fillDeadline analogue ttl, order_id) is shaped like the cross-chain intents standards family, but Everclear never claimed ERC-7683 conformance in its docs, so this is not asserted. security_reviews: - name: Everclear Chimera mitigations review auditor: Creed date: '2024-09' report: >- https://github.com/everclearorg/audits/blob/main/reports/%5BCREED%5D%202024-08%20Everclear%20Chimera%20Mitigations.pdf - name: Everclear Swaps auditor: Creed date: '2025-09' report: https://github.com/everclearorg/audits/blob/main/reports/%5BCREED%5D%20Everclear%20Swaps%20September%202025.pdf security_reviews_index: https://github.com/everclearorg/audits certifications: [] compliance_program: published: false detail: >- No SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP or GDPR posture page was published, and no trust center exists. The Immunefi bug bounty the docs advertise was never launched — the audits page says "Visit the Immunefi portal (Coming soon)" and "The active programs can be found here: Coming soon", and https://immunefi.com/bounty/connext/ returns HTTP 404.