generated: '2026-08-16' method: searched source: openapi/galatea-bio-octopod-openapi.yml docs: https://galatea.bio/life-sciences note: >- Cross-cutting standards conformance derived from the published Octopod API Swagger document and the GalateaBio Ancestry API documentation, plus the laboratory accreditations Galatea Bio states on its own website. Every false below is a recorded absence, not a guess. standards: - id: openapi conforms: true version: Swagger 2.0 (OpenAPI 2.0) evidence: >- A live machine-readable document is served at https://api.galatea.bio/swagger/?format=openapi with "swagger": "2.0", host api.galatea.bio, basePath /api/v1, 79 paths and 99 operations. Generated by drf-yasg from the running application. gap: >- The document is Swagger 2.0, not OpenAPI 3.x, and declares zero reusable components (definitions is empty) - every schema is inlined per response, so nothing is shared or named. - id: openapi-3 conforms: false evidence: No OpenAPI 3.0/3.1 document is published; only the Swagger 2.0 form. - id: bearer-token-auth conforms: true evidence: >- securityDefinitions declares an apiKey named "Authorization" in header, applied globally; the docs and first-party client send "Authorization: Bearer ". - id: jwt conforms: true evidence: >- POST /users/auth returns access, refresh and websocket_access tokens; POST /users/refresh exchanges a refresh token plus an expired access token. Standard JWT access/refresh pairing. - id: oauth2 conforms: false evidence: >- No oauth2 security scheme in the spec, no authorization or token endpoint documented, and /.well-known/oauth-authorization-server is not served. No scopes/ artifact is written. - id: oidc conforms: false evidence: /.well-known/openid-configuration is not served on any host (403 Cloudflare challenge). - id: mfa conforms: true evidence: >- POST /users/confirm (users_confirm_create) requires mfa_session_id plus a numeric code, and POST /users/request-new-code reissues it. Multi-factor authentication is part of the published login flow. - id: rfc9457-problem-details conforms: false evidence: >- Errors are a flat {"detail": "..."} object with content-type application/json. No application/problem+json response is declared anywhere in the spec, and no type/title/status/ instance members are used. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt is not served on any host. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation response header is declared or documented. - id: pagination conforms: true style: page-number evidence: >- Consistent page/page_size query parameters and a count/next/previous/results envelope across every collection endpoint - the Django REST Framework PageNumberPagination contract. - id: idempotency conforms: false evidence: >- No idempotency key header or parameter is documented or present in the spec, and no retry-safety guarantee is published for POST /exec/orders. No Idempotency pointer is emitted. - id: webhooks-hmac-signing conforms: true evidence: >- Deliveries carry X-Octopod-Signature, a base64 HMAC-SHA256 over sender_host + raw body, keyed by a per-organization secret that can be rotated via the API. A verification recipe is published. - id: asyncapi conforms: false evidence: >- No AsyncAPI document is published. The webhook surface is real and documented but described in prose and in the REST spec only - see asyncapi/galatea-bio-octopod-webhooks.yml. - id: json-api conforms: false evidence: Responses are plain JSON, not JSON:API documents. - id: fhir conforms: false evidence: >- No FHIR resource shapes, no /fhir base path, no FHIR media types. Results are delivered as TSV, JSON, SVG, ZIP and PDF artifacts keyed by result_type rather than as FHIR resources - a notable gap for a clinical genomics API, where FHIR Genomics is the interoperability expectation. - id: hl7v2 conforms: false evidence: No HL7 v2 messaging surface documented. - id: ga4gh conforms: false evidence: >- No Global Alliance for Genomics and Health API conformance claimed - no htsget, no Beacon, no Data Repository Service, no Workflow Execution Service endpoints in the spec. - id: scim conforms: false evidence: >- User and organization management is a bespoke surface (/users, /organizations) rather than SCIM 2.0. - id: odata conforms: false evidence: No OData query conventions. - id: mcp conforms: false evidence: No MCP server published - see mcp/galatea-bio-mcp.yml. - id: a2a conforms: false evidence: No agent card served at either well-known path on any host. - id: llms-txt conforms: false evidence: >- /llms.txt returns the single-page-app shell on the website, console and docs hosts and 404 on the API host. A generated one is provided at llms/galatea-bio-llms.txt. compliance_program: published: true source: https://galatea.bio/life-sciences fetched: '2026-08-16' certifications: - name: CLIA detail: CLIA-CMS certified clinical laboratory scope: laboratory - name: CAP detail: CAP-accredited high-complexity laboratory scope: laboratory statement: >- "We operate a next-generation sequencing molecular diagnostics clinical laboratory and biobank (CLIA- CMS certified, CAP- accredited high-complexity lab), servicing clinical and research customers." - Galatea Bio, galatea.bio/life-sciences note: >- These are laboratory accreditations covering the diagnostic operation, published by Galatea Bio on its own site. They are the basis for the Compliance pointer in apis.yml. They are NOT information-security certifications - no SOC 2, ISO 27001, HIPAA attestation, or trust center was found, and no trust-center artifact is written. not_found: - SOC 2 - ISO 27001 - PCI DSS - HIPAA attestation or BAA page - FedRAMP - GDPR statement - trust center - public privacy policy - public terms of service