generated: '2026-07-19' method: searched source: openapi/griffin-openapi-original.yml docs: - https://docs.griffin.com/docs/guides/api-security-overview - https://docs.griffin.com/docs/guides/errors-overview - https://griffin.com/llms.txt notes: >- Standards asserted from the OpenAPI, docs, and Griffin's published regulatory status. Griffin is a UK-regulated bank (FCA authorised, PRA regulated), publicly stated on griffin.com — a real regulatory/compliance posture, though Griffin does not publish a certifications trust center (SOC 2/ISO 27001 pages returned 404). No `Compliance` pointer is emitted since no dedicated compliance/certifications page was found. standards: - id: api-key-auth conforms: true evidence: securityDefinitions api-key-auth (apiKey in header, Authorization) - id: http-message-signatures-rfc9421 conforms: true evidence: Message-signature signing required in live; verify endpoints at /v0/security/message-signature/verify - id: json-api-errors conforms: partial evidence: Errors follow jsonapi.org shape but "not strictly"; use `source` JSON pointer - id: rfc9457-problem-details conforms: false evidence: Errors are application/json, not application/problem+json - id: oauth2 conforms: false - id: openid-connect conforms: false - id: webhooks-signed-events conforms: true evidence: Event notifications signed via the same message-signature process - id: open-banking-uk conforms: true evidence: Open banking Tell consents endpoints (/v0/open-banking/tell-consents) - id: confirmation-of-payee conforms: true evidence: CoP request endpoints (/v0/organizations/{id}/cop-request) regulatory: status: UK bank — Financial Conduct Authority authorised, Prudential Regulation Authority regulated source: https://griffin.com/llms.txt