generated: '2026-07-18' method: searched source: https://www.getdefacto.com/security summary: Cross-cutting standards and compliance posture for Defacto, from the reconstructed OpenAPI and the published security/trust pages. standards: - id: oauth2 conforms: false evidence: Auth is an API-key bearer token (securityScheme type apiKey in Authorization header), not OAuth 2.0. - id: openid-connect conforms: false - id: http-bearer-apikey conforms: true evidence: All operations secured by a single apiKey scheme (Authorization Bearer). - id: rfc9457-problem-details conforms: false evidence: Error bodies are plain JSON; no application/problem+json responses in the spec. - id: cursor-pagination conforms: true evidence: List endpoints use cursor + page_size + sort_by query parameters. - id: webhooks conforms: true evidence: 32 documented event types delivered via subscriber-registered POST callbacks. - id: psd2 conforms: true evidence: Bank-data sharing operates under the European PSD2 (DSP2) directive (getdefacto.com/security). - id: gdpr conforms: true evidence: Personal data processing governed by GDPR/RGPD (getdefacto.com/security). - id: iso-27001 conforms: true evidence: ISO 27001:2022 certified information security management system (getdefacto.com/security; trust.getdefacto.com). compliance_program: published: true page: https://www.getdefacto.com/security trust_center: https://trust.getdefacto.com regulator: ACPR (France) — Defacto is an ACPR-authorized financial institution. certifications: - ISO 27001:2022 - GDPR - PSD2