generated: '2026-07-19' method: searched source: https://docs.halliday.xyz/pages/compliance-security.md standards: - id: openapi-3.1 conforms: true evidence: Halliday API V2 published as OpenAPI 3.1.0 (openapi/halliday-openapi-original.yml). - id: api-key-auth conforms: true evidence: HTTP bearer API-key auth (ApiKeyAuth securityScheme) required on all endpoints. - id: rfc9457-problem-details conforms: false evidence: Errors use a custom {errors:[{kind,message,...}]} envelope, not application/problem+json. - id: oauth2 conforms: false evidence: No OAuth2 security scheme; API-key auth only. - id: webhooks-signed conforms: true evidence: Workflow webhooks are HMAC-signed (v1= signatures) with rotatable signing secrets. - id: cursor-pagination conforms: true evidence: pagination_key / next_pagination_key cursor pagination on payment history. compliance_posture: certifications_published: [] note: > Halliday publishes a Compliance & Security page but names no formal certifications (no SOC 2 / ISO 27001 / PCI DSS / HIPAA attestation was found). Posture is protocol/security-audit-based. smart_contract_audits: - ChainSecurity - Zellic - Halborn sanctions_screening: TRM Labs (OFAC list screening + wallet-level risk assessment) kyc_aml: Performed by third-party onramp / centralized-exchange providers (MoonPay, Transak, Stripe). security_contact: security@halliday.xyz