generated: '2026-08-11' method: derived source: openapi/cosmoplat-iot-platform-openapi.yml docs: https://www.cosmoplat.com/help/detail/304/1038 summary: >- Cross-cutting standards conformance for the COSMOPlat IoT development platform, derived from the transcribed contract and the published documentation. COSMOPlat conforms to the IoT transport standards it advertises and to essentially none of the API-layer web standards. No compliance certification is published anywhere on the site, so no Compliance pointer is emitted. standards: - id: mqtt conforms: true evidence: >- Documented MQTT brokers with topic addresses, QoS and an example payload (iot.cosmoplat.com:1883 device ingest, iot-mqtt.cosmoplat.com:11883 tenant subscribe). source: https://www.cosmoplat.com/help/detail/304/1064 - id: coap conforms: advertised evidence: Listed as a supported device transport in the platform overview and as a Product.transportType enum value (CoAP). No CoAP endpoint or resource path published. source: https://www.cosmoplat.com/help/detail/304/1012 - id: lwm2m conforms: advertised evidence: Listed as a supported device transport and as a Product.transportType enum value (LWM2M). No object model or bootstrap detail published. source: https://www.cosmoplat.com/help/detail/304/1012 - id: snmp conforms: advertised evidence: Listed as a supported device transport and as a Product.transportType enum value (SNMP). No MIB published. source: https://www.cosmoplat.com/help/detail/304/1012 - id: x509 conforms: advertised evidence: X509_CERTIFICATE is a documented Device.credentialsType alongside ACCESS_TOKEN and MQTT_BASIC. No CA, enrolment or rotation procedure published. source: https://www.cosmoplat.com/help/detail/304/1038 - id: openapi conforms: false evidence: >- No OpenAPI, Swagger or Postman artifact is served on any COSMOPlat host. The contract is published as an HTML reference table only. Ironically, COSMOPlat sells an "OpenAPI 服务" API-hosting product (solutionId 1772172040879149058) while publishing none for its own API. - id: asyncapi conforms: false evidence: A real MQTT event surface is documented in prose; no AsyncAPI document is served. - id: oauth2 conforms: false evidence: No oauth2 security scheme, no authorization or token endpoint, and /.well-known/oauth-authorization-server 404s. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on www.cosmoplat.com. - id: rfc9457-problem-details conforms: false evidence: >- Failures use a custom {status, message, errorCode, timestamp} envelope served as application/json, not application/problem+json, with no type URI. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on www.cosmoplat.com and is not served on any other host. - id: rfc8594-sunset conforms: false evidence: No Sunset or Deprecation header support and no deprecation policy published. - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog returns 404. - id: idempotency conforms: false evidence: No idempotency key, header or retention window documented on any write operation, including the two device RPC dispatch operations. - id: pagination conforms: partial evidence: >- Consistent zero-based page/pageSize with totalPages/totalElements/hasNext, but carried in the query string on GET list operations and in the request body on POST list operations. - id: rest-resource-naming conforms: partial evidence: >- Mostly resource-oriented, with RPC-style exceptions — /pageTbProductManage, /tenant/devicesnew, /mergerTelemetryProfile, /deleteTelemetryProfileById/{id} (a DELETE whose path repeats the verb), and /alarm/{entityType}/getTenantAlarms. - id: gdpr conforms: unknown evidence: Privacy policy is published but served from a host that blocks non-browser clients; no GDPR statement was readable. compliance_certifications_published: [] compliance_pointer_emitted: false compliance_pointer_note: >- No SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP, MLPS/等保 or CSA STAR claim is published on any COSMOPlat page probed. Chinese regulatory registrations ARE published in the site footer — ICP 鲁ICP备2021010660号, 公安网备 37021202001456, value-added telecom business licence 合字B2-20250648, and a generative-AI service filing Shandong-TianZhiGongYe-202410290008 — but these are operating registrations, not security or privacy certifications, so no Compliance pointer is emitted. chinese_regulatory_filings: - {kind: ICP licence, value: 鲁ICP备2021010660号} - {kind: public network security record, value: 鲁公网安备37021202001456号} - {kind: value-added telecom business licence, value: 合字B2-20250648} - {kind: generative-AI service filing, value: Shandong-TianZhiGongYe-202410290008} x-evidence: - {url: 'https://www.cosmoplat.com/help/detail/304/1038', http_status: 200, fetched: '2026-08-11'} - {url: 'https://www.cosmoplat.com/help/detail/304/1064', http_status: 200, fetched: '2026-08-11'} - {url: 'https://www.cosmoplat.com/.well-known/security.txt', http_status: 404, fetched: '2026-08-11'} - {url: 'https://www.cosmoplat.com/.well-known/api-catalog', http_status: 404, fetched: '2026-08-11'}