generated: '2026-07-19' method: searched source: https://imply.io/trust-center standards: - id: oauth2 conforms: true evidence: Polaris documents OAuth2 access-token authentication (auth-overview). - id: api-key-auth conforms: true evidence: Polaris API keys passed via HTTP Basic (key as username). - id: soc2-type2 conforms: true evidence: SOC 2 Type II attested (Trust Center). - id: iso-27001 conforms: true evidence: ISO 27001 certified (Trust Center). - id: hipaa conforms: true evidence: HIPAA compliance attested (Trust Center). - id: gdpr conforms: true evidence: GDPR compliance and DPA published (Trust Center / legal). - id: ccpa conforms: true evidence: CCPA compliance stated (Trust Center). - id: csa-star conforms: true evidence: Controls listed on CSA Security, Trust & Assurance Registry (STAR). - id: rfc9457-problem-details conforms: false evidence: No local OpenAPI captured; problem+json usage not verified. - id: fhir-r4 conforms: false - id: fapi conforms: false notes: > Compliance program is published (SOC 2 Type II, ISO 27001, HIPAA, GDPR, CCPA, CSA STAR) — see security/imply-trust-center.yml. Standards without published evidence are recorded conforms:false rather than omitted.