generated: '2026-07-19' method: searched source: https://www.impart.ai/ note: >- Compliance posture published on the Impart marketing site. Standards conformance below is derived from the public REST API shape (bearer token auth, versioned URI path) where the OpenAPI is not publicly downloadable (docs are console-gated). compliance_program: - id: soc2-type-ii name: SOC 2 Type II conforms: true evidence: "Impart states 'SOC 2 Type II certified' on impart.ai" - id: gdpr name: GDPR conforms: true evidence: "Impart states 'GDPR Ready' on impart.ai" standards: - id: oauth2-oidc conforms: true evidence: Console/docs login uses an Auth0 OIDC tenant (auth.impartsecurity.net/.well-known/openid-configuration, 200) - id: bearer-token-auth conforms: true evidence: v0 REST API authenticates with a scoped bearer API access token (terraform-provider-impart README + internal/apiclient) - id: uri-path-versioning conforms: true evidence: Base URL https://api.impartsecurity.net/v0 uses URI-path versioning - id: rfc9457-problem-details conforms: false evidence: not verifiable (OpenAPI not public) - id: fhir-r4 conforms: false - id: fapi conforms: false - id: scim conforms: false