generated: '2026-08-11' method: derived source: openapi/cosmose-ai-deal-hunter-registration-api-openapi.yml note: >- Assertions about cross-cutting standards, derived from the published contract and from live probes on 2026-08-11. No compliance program, certification, audit report or trust page was found on any Cosmose AI property, so no `Compliance` or `TrustCenter` pointer is emitted. `conforms: false` here means "we checked and it does not", not "we did not check". standards: - id: openapi conforms: true version: 3.0.1 evidence: >- A valid OpenAPI 3.0.1 document with 22 paths / 24 operations is served anonymously from https://api.sg.cosmose.co/deal-hunter-registration-api/v3/api-docs (HTTP 200, application/json), with a YAML twin at /v3/api-docs.yaml and a Swagger UI at /deal-hunter-registration-api/swagger-ui.html. Generated by springdoc. caveat: >- Valid but thin — zero operation summaries, zero descriptions, zero examples, controller-bean tag names, wildcard response media types, and a servers[] block naming an unreachable internal cluster host. See overlays/cosmose-ai-deal-hunter-registration-api-overlay.yaml. - id: oauth2 conforms: false evidence: >- No securityScheme of type oauth2 is declared. POST /v2/token borrows OAuth vocabulary — `grant_type` (required), `refresh_token`, `scope` (default "kaikai") — but passes them as query parameters rather than a form-encoded body, publishes no authorization endpoint, and exposes a second undocumented issuer at /v2/crucible-token. It is OAuth-shaped, not OAuth-conformant. - id: oidc conforms: false evidence: >- /.well-known/openid-configuration probed on all six hosts: SPA soft-200 on the web hosts, 401 on the gateways, 404 on repo.cosmose.co. No discovery document. - id: rfc9457 conforms: false evidence: >- Errors use a proprietary {errorCode, message} envelope. No application/problem+json media type, and none of type, title, status, detail or instance. See errors/cosmose-ai-problem-types.yml. - id: rfc9116 conforms: false evidence: /.well-known/security.txt absent on all six hosts. See well-known/cosmose-ai-well-known.yml. - id: rfc8594 conforms: false evidence: No Sunset or Deprecation header is documented; no operation is marked deprecated despite v1 and v2 running side by side. - id: idempotency conforms: false evidence: >- No Idempotency-Key parameter on any operation, on a surface that is 19/24 non-idempotent writes. See conventions/cosmose-ai-conventions.yml. - id: pagination conforms: partial evidence: >- Spring Data page/size/sort pagination on GET /v1/registration-admin/waiting-list-users, with a full totalElements/totalPages/first/last envelope. Declared incorrectly as a single object-valued query parameter named `pageable`, so a generated client will not serialise it correctly. - id: json-api conforms: false evidence: Bespoke JSON payloads; no JSON:API media type, no data/attributes/relationships envelope. - id: odata conforms: false evidence: No $metadata, no OData query options. - id: fhir conforms: false evidence: Not a healthcare API. - id: psd2 conforms: false evidence: Not a financial API. - id: scim conforms: false evidence: >- Identity provisioning exists (register, approve, delete, restore) but is bespoke — no /Users or /Groups SCIM endpoints, no SCIM schemas. - id: fapi conforms: false evidence: Not applicable; no OAuth 2.0 to profile. - id: mcp conforms: false evidence: No MCP server was found on any host. See mcp/cosmose-ai-mcp.yml. - id: a2a conforms: false evidence: >- No agent card at /.well-known/agent-card.json or the legacy /.well-known/agent.json on any of six hosts. See well-known/cosmose-ai-well-known.yml. compliance_program: published: false certifications_found: [] probes: - url: https://trust.cosmose.ai status: 0 note: DNS does not resolve. - url: https://cosmose.ai/privacy-policy status: 200 note: >- Route exists in the SPA router, but the host serves the same client-rendered shell for every path, so the policy text is not machine-readable. This is the only public governance document Cosmose AI appears to publish. detail: >- No SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP or GDPR-certification claim was found anywhere on the company's public surface. This is a notable gap for the business Cosmose is in: the company's stated product is location-derived behavioural data on roughly a billion consumers, collected through an SDK embedded in third-party apps, and the contract it does publish includes a GDPR-shaped forget-me delete/restore pair — so the regulatory exposure is real and the published assurance is nil. privacy_surface: opt_out_route: https://cosmose.ai/opt-out privacy_policy: https://cosmose.ai/privacy-policy right_to_erasure_api: - DELETE /v1/user-account - PUT /v1/user-account/restore note: >- Cosmose does expose consumer erasure as API operations rather than only as a support workflow, which is more than most data brokers do. It is undercut by the restore cap (MAX_RESETS_EXCEEDED) being unpublished and by there being no stated retention window.