generated: '2026-08-04' method: derived source: openapi/eruditus-executive-education-leads-openapi.yml, openapi/eruditus-executive-education-programs-openapi.yml, https://emeritus-tech.github.io/emeritus-api-docs/ summary: >- Cross-cutting standards posture for the Emeritus partner APIs, derived from the two OpenAPI documents in this repo plus the provider's published reference and live probes. This is a minimal REST estate: JSON over HTTPS with static per-API key headers. No OAuth, no OIDC, no RFC 9457, no published pagination contract, and no published compliance certifications. standards: - id: rest-json conforms: true evidence: JSON request and response bodies over HTTPS on all four published operations. - id: api-key-auth conforms: true evidence: OpenAPI securitySchemes type apiKey, in header — LEAD_WEBHOOK_KEY and HTTP-EE-RESOURCES-API-KEY. - id: https-tls conforms: true evidence: TLSv1.3 on eruditus.com, emeritus.org and admissions.emeritus.org (probed 2026-08-04); HSTS returned on API responses. - id: rfc8615-well-known conforms: false evidence: /.well-known/security.txt, /api-catalog, /openid-configuration, /oauth-authorization-server, /agent-card.json and /agent.json all return 404 on every host (probed 2026-08-04). - id: rfc9116-security-txt conforms: false evidence: No /.well-known/security.txt on any host; the vulnerability disclosure policy is published as an HTML page at https://emeritus.org/reporting-a-vulnerabilities/ instead. - id: oauth2 conforms: false evidence: No oauth2 securityScheme in either spec; no OAuth documented anywhere in the reference. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on all hosts. - id: rfc9457-problem-details conforms: false evidence: 'Errors are served as application/json with proprietary envelopes ({"error": ...} and {"title": ..., "errors": {...}}); no application/problem+json and no type URIs.' - id: rfc8594-sunset-header conforms: false evidence: No Deprecation or Sunset headers observed; no deprecation policy published. - id: openapi conforms: false evidence: Emeritus publishes an HTML API reference but no OpenAPI/Swagger document. The two specs in openapi/ were generated by API Evangelist from that reference. - id: asyncapi conforms: false evidence: No event, streaming or outbound-webhook surface is published. - id: json-schema conforms: false evidence: No JSON Schema documents are published by the provider. - id: pagination conforms: unknown evidence: The three Programs API collection reads publish no parameters; the reference pages carry documentation-template placeholder rows. - id: idempotency conforms: false evidence: No idempotency key header, parameter or retry contract is documented for the single write operation (POST /api/v1/generic_lead). - id: rate-limiting conforms: false evidence: No rate-limit policy published; no RateLimit-* / X-RateLimit-* / Retry-After headers observed on live responses. - id: gdpr conforms: unknown evidence: Emeritus publishes a privacy notice (https://emeritus.org/privacy-notice/) and a cookie policy, and operates across the EU, but publishes no compliance/certification page. No SOC 2 / ISO 27001 / PCI claim is made on any Emeritus-controlled page — third-party vendor-risk directories assert certifications, which is not a provider claim and is not recorded here. No `Compliance` pointer is wired. certifications_published: [] trust_center: null