generated: '2026-08-14' method: derived source: openapi/_original/frontline-openapi-original.yml searched: - https://trust.getfrontline.ai/ - https://docs.getfrontline.ai/docs/errors.md - https://docs.getfrontline.ai/docs/rate-limits.md standards: - id: oauth2 conforms: false evidence: No oauth2 securityScheme; API uses Bearer API keys (http/bearer). - id: oidc conforms: false evidence: No /.well-known/openid-configuration on any host (all 404). - id: api-key-bearer conforms: true evidence: Two http/bearer securitySchemes (accountApiKey GENERAL, userApiKey USER). - id: rfc9457-problem-details conforms: false evidence: Errors use a custom envelope ({ ok:false, error:{code,message,details} }), not application/problem+json. - id: pagination conforms: true evidence: List endpoints expose page / page_size query parameters. - id: idempotency conforms: false evidence: No idempotency-key header/parameter documented or in the spec. - id: rate-limiting conforms: true evidence: X-RateLimit-Limit / X-RateLimit-Remaining headers; 429 on limit. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on every host. - id: rfc8594-sunset conforms: false evidence: No Sunset/Deprecation header support or deprecation policy published. - id: soc2-type1 conforms: true evidence: trust.getfrontline.ai badges SOC 2 Type 1 "Compliant". - id: soc2-type2 conforms: false evidence: trust.getfrontline.ai badges SOC 2 Type 2 "Started" — in progress, not attained. - id: iso27001 conforms: false evidence: >- CORRECTED 2026-08-14 — previously recorded as conforming. trust.getfrontline.ai badges ISO 27001 "Started", not compliant. - id: gdpr conforms: false evidence: trust.getfrontline.ai badges GDPR "Started" — program underway, not attested. compliance_program: published: true url: https://trust.getfrontline.ai/ platform: Comp AI frameworks_active: 4 certifications: - SOC 2 Type 1 in_progress: - SOC 2 Type 2 - ISO 27001 - GDPR see: security/frontline-trust-center.yml