generated: '2026-08-13' method: searched source: openapi/databook-openapi-original.json docs: https://databook.com/security standards: - id: openapi-3.1 conforms: true evidence: 'openapi: 3.1.0 served at https://api.databook.com/openapi.json' - id: rfc6750-bearer-token conforms: true evidence: 'securitySchemes.HTTPBearer type http scheme bearer; Authorization: Bearer ' - id: oauth2 conforms: false evidence: 'no oauth2 securityScheme; tokens are issued out-of-band by Databook support' - id: oidc conforms: false evidence: '/.well-known/openid-configuration 404 on every host' - id: rfc9457-problem-details conforms: false evidence: 'errors are application/json with a custom error{type,message} envelope, not application/problem+json' - id: rfc8594-sunset-header conforms: false evidence: 'no deprecation policy or Sunset/Deprecation header documented' - id: rfc9116-security-txt conforms: false evidence: '/.well-known/security.txt 404 on api.databook.com and databook.com' - id: rfc8615-well-known conforms: false evidence: 'no /.well-known/ document served on any host' - id: idempotency-key conforms: false evidence: 'no idempotency header or parameter in the spec or the reference' - id: pagination conforms: false evidence: 'list operations return an unbounded result array with no limit/offset/cursor' - id: soc2-type2 conforms: true evidence: >- SOC 2 Type 2 attestation (security and availability trust service criteria), audited by Dansa D'Arata Soucia LLP; most recent certification date 2024-10-31 per DatabookAI's own attestation to the Microsoft 365 App Certification program. - id: nist-800-171 conforms: true evidence: 'DatabookAI attested "Yes" to NIST 800-171 in the Microsoft 365 App Certification record' - id: gdpr conforms: true evidence: 'DatabookAI attested to GDPR/CCPA obligations; DPA published at https://databook.com/dpa' - id: ccpa conforms: true evidence: 'DatabookAI attested to CCPA obligations in the Microsoft 365 App Certification record' - id: iso-27001 conforms: false evidence: 'attested "No" to ISO 27001 certification (the security page cites alignment with ISO 27001 control families, not certification)' - id: fedramp conforms: false evidence: 'attested "No" to FedRAMP in the Microsoft 365 App Certification record' - id: hipaa conforms: false evidence: 'attested "N/A" to HIPAA in the Microsoft 365 App Certification record' - id: pci-dss conforms: false evidence: 'attested "N/A" to PCI DSS in the Microsoft 365 App Certification record' - id: csa-star conforms: false evidence: 'attested "No" to CSA STAR in the Microsoft 365 App Certification record' sources: - {url: 'https://api.databook.com/openapi.json', status: 200} - {url: 'https://databook.com/security', status: 200} - {url: 'https://trust.databook.com/', status: 200} - {url: 'https://learn.microsoft.com/en-us/microsoft-365-app-certification/teams/databookai-databook', status: 200, note: 'publisher-attested self-assessment, last updated by the developer 2025-11-20'} - {url: 'https://databook.com/pressrelease/databook-achieves-soc-2-type-2-certification/', status: 200}