generated: '2026-09-10' method: searched source: >- openapi/fraud-net-public-apis-openapi.json (contract signature) and https://www.fraud.net/trust-center (published compliance program) provider: Fraud.net providerId: fraud-net sector: payments / fraud-risk / compliance standards: - id: http-basic-rfc7617 conforms: true evidence: >- securityDefinitions.basic-auth type "basic"; the provider's own scheme description restates the four RFC 7617 construction steps verbatim. - id: oauth2 conforms: false evidence: No oauth2 security scheme in the published contract and no OAuth documentation. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 (fraud.net, www) / 403 (api hosts). - id: rfc9457-problem-details conforms: false evidence: >- Errors are a flat custom envelope {success, code, source, message} on application/json; no application/problem+json anywhere in the contract. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header and no deprecation policy published. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt 404 on fraud.net and www.fraud.net (probed 2026-09-10). - id: idempotency-key-header conforms: false evidence: >- No Idempotency-Key header. Replay protection is natural-key duplicate rejection returning 409 — see conventions/fraud-net-conventions.yml. - id: pagination conforms: false evidence: No list or search operation exists in the public contract; nothing to paginate. - id: openapi-3 conforms: false evidence: >- The published contract is Swagger 2.0, not OpenAPI 3.x. Exported from the provider's Stoplight project as "public apis.oas2.json". - id: asyncapi conforms: false evidence: Webhooks are documented in prose; no AsyncAPI document is published. domain_standards: - id: 3-d-secure conforms: true role: consumes evidence: >- definitions.Models_Oas2_Request-payment declares 3DS_eci ("indicates the outcome of the authentication attempted on transactions enforced by 3DS"), 3DS_vid ("28 character authentication value") and 3DS_xid ("Transaction Identifier from 3DS") — the EMV 3-D Secure ECI / CAVV / XID triple, named as such in the contract. spec_location: '#/definitions/Models_Oas2_Request-payment (3DS_eci, 3DS_vid, 3DS_xid)' - id: emv conforms: true role: consumes evidence: >- The same payment object declares emv_aid ("Application Identifier for the EMV") and emv_chip_id ("The EMV chip application ID selected for the transaction"), plus terminal_type/terminal_method — an EMV card-present acceptance signature. spec_location: '#/definitions/Models_Oas2_Request-payment (emv_aid, emv_chip_id)' - id: card-network-rules conforms: true role: consumes evidence: >- avs_result_code ("The payment gateway's AVS response code"), cvv_result_code, `bin` ("the credit card number's first 6 to 11 digits"), `eci`, and a card-network enum [amex, discover, diners_club, mc, other, visa]. Fraud.net ingests the acquirer's network response codes rather than defining its own. spec_location: '#/definitions/Models_Oas2_Request-payment' - id: iso-18245-mcc conforms: true role: consumes evidence: >- mcc_id ("Merchant category code") on Request-partner, Request-seller and Request-counterparty_bank. spec_location: '#/definitions/Models_Oas2_Request-partner.mcc_id' - id: iso-4217 conforms: true role: consumes evidence: 'order_currency: maxLength 3, default "USD" on Request-order-transaction; trip_currency on the travel request.' spec_location: '#/definitions/Models_Oas2_Request-order-transaction.order_currency' - id: iso-13616-iban conforms: true role: consumes evidence: >- iban ("Customer's International Bank Account Number (IBAN)"), alongside swift_code on the bank objects. spec_location: '#/definitions/Models_Oas2_Request-order-transaction.iban' - id: iso-20022 conforms: false evidence: >- No ISO 20022 message type (pain/pacs/camt) is referenced. The banking surface uses Fraud.net's own JSON transaction object, not an ISO 20022 payload. - id: fapi conforms: false evidence: HTTP Basic only; no FAPI security profile, no mTLS, no signed requests. - id: fdx conforms: false evidence: Not an open-banking data-sharing surface; no FDX resources or consent model. compliance_program: published: true url: https://www.fraud.net/trust-center certifications: - {name: SOC 2 Type II, evidence: 'Trust Center "Frameworks and Certifications" list; a "SOC2 Type II Attestation Report" document is offered under Get Access'} - {name: ISO 27001, evidence: Trust Center Frameworks and Certifications list ("ISO27001")} - {name: PCI DSS, evidence: 'Trust Center Frameworks and Certifications list; a "PCI - DSS" document is offered under Get Access'} - {name: HIPAA, evidence: Trust Center Frameworks and Certifications list} - {name: GDPR, evidence: 'Trust Center list, and the API documentation states "We are compliant with the General Data Protection Regulation (GDPR) and apply the standard to all customer data"'} - {name: NIST 800-53, evidence: Trust Center Frameworks and Certifications list} - {name: NTIS, evidence: Trust Center Frameworks and Certifications list} gated: true gated_note: >- The frameworks are named publicly; the underlying PCI-DSS and SOC 2 Type II documents are behind a "Get Access" request form, which is normal practice. controls_published: >- The Trust Center publishes a control narrative across 17 NIST 800-53-shaped families (access control, awareness & training, audit & accountability, assessment, configuration management, contingency planning, identification & authentication, incident response, maintenance, media protection, planning, personnel security, risk assessment, system & services acquisition, system & communications protection, supply chain risk management), including annual penetration testing, continuous vulnerability scanning, TLS 1.2+ encryption in transit and at rest, and NIST 800-63B password policy. gaps: - No published vulnerability disclosure policy, security.txt or bug bounty — the Trust Center describes internal pen-testing and vulnerability scanning but gives no channel for an outside reporter and names no security contact address.