generated: '2026-08-12' method: derived source: >- openapi/crm-bonus-oto-data-api-openapi.yml + live response probes of https://data-api.otocrm.com.br (2026-08-12) + https://www.crmbonus.com.br/politicas/seguranca-de-dados api: Oto Data API standards: - id: openapi-3.1 conforms: true evidence: >- Provider-published OpenAPI 3.1.0 document served at https://data-api.otocrm.com.br/openapi.json (13 operations, 34 component schemas, unique operationIds, per-operation descriptions). - id: json-schema-2020-12 conforms: true evidence: OpenAPI 3.1.0 dialect — component schemas are JSON Schema 2020-12. - id: rest conforms: true evidence: HTTP + JSON resource endpoints under /v1/, as stated in the docs. - id: http-bearer-auth conforms: true evidence: components.securitySchemes.HTTPBearer — type http, scheme bearer. - id: jwt conforms: true evidence: >- POST /auth/login returns TokenResponse {access_token, expires_in}; the operation description states a JWT with a default 3600-second expiry. - id: oauth2 conforms: false evidence: >- No oauth2 securityScheme; tokens are support-issued or obtained from a username/password login endpoint. No scope surface exists, which is why no scopes/ artifact is emitted. - id: openid-connect conforms: false evidence: /.well-known/openid-configuration returns 404 on every provider host. - id: rfc9457-problem-details conforms: false evidence: >- Errors are FastAPI-style {"detail": ...} as application/json; no application/problem+json, no type/title members. - id: idempotency conforms: partial evidence: >- No Idempotency-Key header, but every write is documented as an upsert-by-primary-key that replaces an existing record in full, so replay converges on the same state. See conventions/crm-bonus-conventions.yml. - id: pagination conforms: false evidence: Write-only surface (13 POSTs, no GET) — nothing to paginate. - id: rfc8594-sunset conforms: false evidence: No Sunset or Deprecation header; no deprecation policy published. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on every provider host. - id: hsts conforms: true evidence: >- strict-transport-security max-age=31536000; includeSubDomains observed live on data-api.otocrm.com.br. - id: json-api conforms: false - id: odata conforms: false - id: scim2 conforms: false - id: fhir conforms: false - id: psd2 conforms: false - id: fapi conforms: false - id: asyncapi conforms: false evidence: >- No AsyncAPI document and no documented webhook or event-subscription surface. The API is ingestion-only; Oto Tags is an inbound event stream the customer pushes, not an outbound one the provider emits. Not a penalty — there is no event surface to describe. regulatory: - id: lgpd claimed: true certified: null evidence: >- Brazilian data-protection posture is asserted on https://www.crmbonus.com.br/politicas/seguranca-de-dados and a Central de Privacidade / DSAR portal is operated at dpo.privacytools.com.br. A DPO contact (suporte@crmbonus.com) is published. This is a stated compliance posture, not an audited certification. certifications: published: [] note: >- NO named certification is published. The security page says only that data is stored "seguindo parâmetros, certificados de segurança e criptografia" — generic prose naming no scheme. SOC 2, ISO 27001, PCI DSS, HIPAA and FedRAMP were each searched for and none is claimed anywhere on the CRMBonus or Oto surface. Because no certification or formal compliance program is published, NO `Compliance` pointer is wired into apis.yml. x-evidence: - url: https://data-api.otocrm.com.br/openapi.json http_status: 200 - url: https://www.crmbonus.com.br/politicas/seguranca-de-dados http_status: 200 - url: https://data-api.otocrm.com.br/.well-known/security.txt http_status: 404