generated: '2026-08-11' method: derived source: openapi/ + live responses from https://cruzfoam.com/wp-json/ description: >- Cross-cutting standards this surface does and does not conform to, derived from the derived OpenAPI documents and from responses observed live on 2026-08-11. Cruz Foam makes no compliance or conformance claims of its own — it publishes no trust center, no certifications page and no API documentation — so nothing here is a provider assertion. standards: - id: json-schema conforms: true evidence: >- Every route serves a JSON Schema for its resource via HTTP OPTIONS (post 29 properties, page 27, attachment 33, customers 21, user 20, category 10, tag 8, portfolio-categories 9, type 16, taxonomy 11, search-result 5). These published schemas are what the OpenAPI in this repo was derived from. - id: rfc8288-web-linking conforms: true evidence: 'Link header with rel="next" observed on GET /wp/v2/posts?per_page=2.' - id: oembed-1.0 conforms: true evidence: 'Provider endpoint GET /oembed/1.0/embed returned 200 for a cruzfoam.com URL.' - id: schema-org-json-ld conforms: true evidence: 'GET /yoast/v1/get_head returns a parsed schema.org @graph for any site URL.' - id: rfc7617-basic-auth conforms: true evidence: >- WordPress application passwords, declared in the API root document, are Basic over TLS. Applies only to the non-public write surface. - id: cors conforms: true evidence: 'Access-Control-Expose-Headers and Access-Control-Allow-Headers present on responses.' - id: rfc9457-problem-details conforms: false evidence: >- Errors use the WordPress envelope {code, message, data:{status}} served as application/json, not application/problem+json. - id: oauth2 conforms: false evidence: No oauth2 securityScheme in any spec; no authorization server on any host. - id: oidc conforms: false evidence: /.well-known/openid-configuration returned 404. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returned 404. - id: rfc8594-sunset conforms: false evidence: No Sunset or Deprecation header observed; no deprecation policy published. - id: idempotency-keys conforms: false evidence: No Idempotency-Key header or parameter accepted or documented. - id: pagination conforms: true evidence: 'page/per_page/offset parameters plus X-WP-Total and X-WP-TotalPages response headers.' compliance_program: published: false certifications: [] detail: >- No SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP or CSA STAR claim appears anywhere on cruzfoam.com, and trust.cruzfoam.com does not resolve. The company's public certification story is materials certification (compostability), not information-security certification, and that is a different regime scored elsewhere.