generated: '2026-07-19' method: derived source: openapi/fieldguide-openapi-original.json note: >- Standards conformance derived from the OpenAPI security schemes, response conventions, and webhook surface, plus published compliance certifications from the Fieldguide trust page (https://www.fieldguide.io/trust). standards: - id: oauth2 conforms: false evidence: No oauth2 securityScheme; auth is http bearer JWT with resource scopes. - id: openid-connect conforms: false - id: http-bearer-jwt conforms: true evidence: securitySchemes.bearer is http/bearer with bearerFormat JWT. - id: rfc9457-problem-details conforms: false evidence: Errors use plain HTTP status codes, not application/problem+json. - id: pagination conforms: true evidence: page/per_page query parameters across list operations. - id: webhooks conforms: true evidence: Webhook subscription CRUD (/v1/webhooks) with signed event payloads. - id: idempotency conforms: false evidence: No Idempotency-Key header/parameter declared. compliance: - program: SOC 2 Type 2 published: true source: https://www.fieldguide.io/trust - program: ISO/IEC 42001:2023 published: true source: https://www.fieldguide.io/trust - program: AIUC-1 published: true source: https://www.fieldguide.io/trust - program: ISO 27001 published: true scope: infrastructure (AWS) source: https://www.fieldguide.io/trust - program: GDPR published: true source: https://www.fieldguide.io/trust - program: CCPA published: true source: https://www.fieldguide.io/trust