generated: '2026-07-25' method: searched source: >- https://www.ease.com/product/security/ , https://www.ease.com/product/security/sso/ , https://www.employeenavigator.com/security/ , plus derivation from openapi/ease-content-openapi.yml and openapi/ease-status-openapi.yml summary: >- Ease's technical-standards conformance is thin - two anonymous read APIs with no OAuth, no OIDC, no problem-details errors and no event spec. Its regulatory and audit posture is the substantial part: HIPAA, SOC 2 Type II and a HITRUST CSF certification are claimed on ease.com, and since the April 2023 acquisition Ease falls under Employee Navigator's security program, which publishes annual SOC 2 Type II, HITRUST, NIST, GDPR, 23 NYCRR 500 and CCPA audits. standards: - id: oauth2 conforms: false evidence: No oauth2 securityScheme in either spec; no /.well-known/oauth-authorization-server on any Ease host (all 404). - id: openid-connect conforms: false evidence: https://secure.ease.com/.well-known/openid-configuration and www.ease.com equivalent both return 404. - id: http-basic-rfc7617 conforms: true evidence: >- WordPress Application Passwords (HTTP Basic) advertised in the authentication block of https://www.ease.com/wp-json/ for write/administrative routes. Not a developer program. - id: rfc9457-problem-details conforms: false evidence: 'Errors return application/json with the WordPress {code, message, data.status} envelope, not application/problem+json. See errors/ease-problem-types.yml.' - id: rfc8288-web-linking conforms: true evidence: 'Collection responses return Link: <...>; rel="next" pagination headers. Verified live 2026-07-25.' - id: rfc9116-security-txt conforms: false evidence: >- No first-party /.well-known/security.txt on any Ease host. The 200 on status.ease.com is Atlassian's vendor document, canonical to atlassian.com. See well-known/ease-well-known.yml. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation headers observed; the platform sunset is announced by blog post only. - id: openapi conforms: false evidence: >- Ease publishes no OpenAPI. The two specs in openapi/ are derived/generated by API Evangelist from the live WordPress route discovery document and the Ease-hosted Statuspage endpoint reference. - id: asyncapi conforms: false evidence: No AsyncAPI document exists. A webhook surface does exist on the status page - see asyncapi/ease-status-webhooks.yml. - id: graphql conforms: false evidence: /graphql returns 404 on secure.ease.com and api.ease.com. - id: grpc conforms: false evidence: No .proto published; no GitHub organization found. - id: json-api conforms: false evidence: Responses are plain JSON arrays/objects, not the JSON:API media type. - id: hal conforms: partial evidence: 'Content API records carry a HAL-style _links object and support _embed expansion, but the media type is application/json, not application/hal+json.' - id: oembed conforms: true evidence: 'https://www.ease.com/wp-json/oembed/1.0/embed returns an oEmbed 1.0 representation; verified 200 on 2026-07-25.' - id: ansi-x12-834 conforms: true evidence: >- EaseConnect maps ANSI ASC X12 EDI 834 benefit enrollment and maintenance files to carriers, documented at https://www.ease.com/product/platform/benefits-administration/managing-medical/834-files/. Private, customer-login surface - not a public API. - id: acord conforms: false evidence: >- No ACORD, AL3, NGDS or IVANS reference appears anywhere on ease.com. Ease operates in the group-benefits X12 834 idiom, not the P&C ACORD idiom. - id: saml-2.0 conforms: true evidence: 'Okta SAML single sign-on offered on the Enterprise package: https://www.ease.com/product/security/sso/' - id: fhir conforms: false evidence: No FHIR resources, endpoints or claims anywhere on the site. compliance_programs: - id: hipaa claimed: true scope: Ease platform evidence: https://www.ease.com/product/security/sso/ - id: soc2-type-ii claimed: true scope: Ease platform; audited annually at Employee Navigator evidence: https://www.ease.com/product/security/sso/ and https://www.employeenavigator.com/security/ - id: hitrust-csf claimed: true certification: HITRUST CSF Certification evidence: https://www.ease.com/product/security/sso/ - id: gdpr claimed: true scope: Employee Navigator security program (Ease now in scope) evidence: https://www.employeenavigator.com/security/ - id: ccpa claimed: true scope: Employee Navigator security program evidence: https://www.employeenavigator.com/security/ - id: nydfs-23-nycrr-500 claimed: true scope: Employee Navigator security program evidence: https://www.employeenavigator.com/security/ - id: nist claimed: true scope: Employee Navigator security program, audited annually evidence: https://www.employeenavigator.com/security/ - id: pci-dss claimed: false - id: fedramp claimed: false independent_testing: penetration_testing: true evidence: >- "third-party vulnerability and penetration testing" stated on https://www.ease.com/product/security/sso/