generated: '2026-08-13' method: derived source: >- openapi/_original/encharge-openapi.yml, https://gdpr.encharge.io/, https://encharge.io/responsible-disclosure/, https://docs.encharge.io/transactional-email-api/technical-overview standards: - id: openapi-3.0 conforms: true evidence: >- Encharge publishes an OpenAPI 3.0.0 document (46 paths / 69 operations) at https://app-encharge-resources.s3.amazonaws.com/merged.yaml, rendered via ReDoc and RapiDoc and linked from https://docs.encharge.io/api-documentation - id: oauth2 conforms: true evidence: >- components.securitySchemes.oauth2, authorizationCode flow, authorize/token endpoints on https://api.encharge.io/v1/oauth/*, with 8 scopes applied at the operation level - id: oidc conforms: false evidence: no openIdConnect scheme and no /.well-known/openid-configuration (404) - id: rfc8414-oauth-metadata conforms: false evidence: /.well-known/oauth-authorization-server returns 404 on every host - id: rfc9457-problem-details conforms: false evidence: >- errors use a custom `{ error: { message, markdown, traceId } }` envelope, not application/problem+json - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on every host - id: rfc8594-sunset-header conforms: false evidence: no deprecation or sunset policy published - id: rest-json conforms: true evidence: JSON request/response over HTTPS on every operation - id: pagination conforms: true evidence: limit/offset query parameters on the collection reads (+ sort/order) - id: idempotency conforms: false evidence: >- no Idempotency-Key contract in the spec or docs; only key-based upsert semantics on CreateUpdatePeople / CreateOrUpdateCustomObjects - id: webhooks conforms: true evidence: >- self-service event subscriptions via POST /event-subscriptions with a published event-name catalog (see asyncapi/encharge-webhooks.yml) - id: asyncapi conforms: false evidence: no AsyncAPI document published for the webhook/activity-stream surface - id: gdpr conforms: true evidence: >- Encharge (PXCH Holding I, LLC) publishes a GDPR compliance portal at https://gdpr.encharge.io/ with a DPA, subprocessor list, security page, data-request and data-breach flows, and a named privacy/security contact - id: soc2 conforms: false evidence: no SOC 2 attestation claimed on any public page - id: iso-27001 conforms: false evidence: no ISO 27001 certification claimed on any public page - id: responsible-disclosure conforms: true evidence: https://encharge.io/responsible-disclosure/ publishes a disclosure policy compliance_program: published: true url: https://gdpr.encharge.io/ regimes: [GDPR] artifacts: [DPA, subprocessor list, security overview, data-request flow, data-breach process] data_residency: 'AWS data center in Ireland hosts all application data (stated on the portal)'