generated: '2026-08-12' method: derived source: >- openapi/_original/*.json, https://login.decisiv.net/.well-known/openid-configuration, https://www.decisiv.com/trust-center/, https://api-docs.decisiv.net/docs/api/oauth/ standards: - id: openapi-3.1 conforms: true evidence: >- Four SRM Gateway modules declare openapi 3.1.0 (Account Management, Asset Management, Service Management, Telematics), build 0.48.24. - id: swagger-2.0 conforms: true evidence: Global Assets API 2.1.5 and Service Provider API 2.0.4 are Swagger 2.0 documents. - id: json-api conforms: true evidence: >- All SRM Gateway bodies are application/vnd.api+json with {type,id,attributes,relationships} resource objects, page[number]/page[size] pagination, filter[...] and include/sort query params, and an errors[] envelope. 1,539 references to the media type across the four specs. - id: rfc9457-problem-details conforms: false evidence: >- No application/problem+json anywhere. Errors use the JSON:API errors[] envelope ({title, detail, code, status, source}) instead. - id: oauth2 conforms: true evidence: >- securitySchemes declare oauth2 authorizationCode (authorizationUrl https://login.decisiv.net/auth/api_gateway, tokenUrl https://login.decisiv.net/oauth/token) and a deprecated password flow. RFC 8414 metadata is served at https://login.decisiv.net/.well-known/oauth-authorization-server. - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: 200 with real JSON at https://login.decisiv.net/.well-known/oauth-authorization-server - id: oidc-discovery conforms: true evidence: >- 200 at https://login.decisiv.net/.well-known/openid-configuration declaring issuer, jwks_uri, userinfo_endpoint, id_token_signing_alg_values_supported [ES256], claims_supported and the openid scope. Response is identical to the RFC 8414 document. - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported [plain, S256] in the discovery document. - id: rfc7009-token-revocation conforms: true evidence: revocation_endpoint https://login.decisiv.net/oauth/revoke - id: rfc7662-token-introspection conforms: true evidence: introspection_endpoint https://login.decisiv.net/oauth/introspect - id: rfc7519-jwt conforms: true evidence: AccessToken security scheme is http bearer with bearerFormat JWT; JWKS published at /oauth/discovery/keys (ES256). - id: idempotency-key conforms: partial evidence: >- X-DECISIV-IDEMPOTENCY-KEY / X-Decisiv-Idempotent-Replay implemented on case creation only, not across the write surface. Vendor-prefixed header, not the IETF draft Idempotency-Key. - id: pagination conforms: true evidence: page[number] / page[size] on 77 collection operations. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation response headers declared; no deprecation policy page published. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt 404s on decisiv.com and returns an HTML shell elsewhere. - id: asyncapi conforms: false evidence: >- No AsyncAPI document published, although a managed webhook surface with 18 named events exists (asyncapi/decisiv-srm-gateway-webhooks.yml). - id: iso-27001 conforms: true evidence: >- "Decisiv has been certified in accordance with ISO/IEC 27001 since February 2024. The certification is valid for 3 years and is verified every year by an independent auditing company." Certificate (ISO 27001:2022) issued by Prescient Security, accredited by IAS and IAF, downloadable from https://www.decisiv.com/trust-center/. Scope: the ISMS supporting the Decisiv SRM Platform. - id: gdpr conforms: claimed evidence: Referenced on https://www.decisiv.com/trust-center/ and the Data Governance / Privacy Policy pages. - id: soc2 conforms: false evidence: No SOC 2 report or claim found on the trust center or anywhere on decisiv.com. - id: e164-phone conforms: true evidence: >- Phone validation errors decisiv:phone:001-005 enforce E.164 (leading +, no spaces, valid country code, 3-15 characters). - id: rfc3696-email conforms: true evidence: >- Email validation errors decisiv:email:001-004 enforce RFC 3696 syntax, 64-octet local part, 255-character domain and DNS resolvability of the domain. - id: iso-3166 conforms: true evidence: >- decisiv:location:001 requires ISO 3166-1 alpha-2 country codes (US, CA, EC, MX, CL, JP) and decisiv:location:002 requires ISO 3166-2 state codes. - id: iso-8601 conforms: true evidence: >- Timestamps must conform to ISO 8601 "YYYY-MM-DDTHH:MM:SSZ" (decisiv:request_attributes:006); time filters reject non-ISO values (decisiv:filters:010). - id: vmrs conforms: true evidence: >- VMRS (Vehicle Maintenance Reporting Standards, TMC/ATA) is a first-class resource — 9 VMRS operations in each of Asset Management and Service Management, and the Platform API changelog records "Extended cases to support high-level VMRS coding" at initial release. - id: iso-3779-vin conforms: true evidence: >- VIN validation errors decisiv:vins:001-006 enforce 17 characters, a valid check digit, and exclusion of the letters I, O and Q. industry_standards: - id: vmrs body: American Trucking Associations Technology & Maintenance Council (TMC) role: primary coding vocabulary for repair work - id: vin body: ISO 3779 / NHTSA role: asset identity compliance_program: published: true url: https://www.decisiv.com/trust-center/ certifications: - ISO/IEC 27001:2022 artifact: security/decisiv-trust-center.yml