generated: '2026-08-13' method: probed source: >- well-known/incentivio-mobile-api-oauth-authorization-server.json, well-known/incentivio-admin-api-oauth-authorization-server.json, https://incentivio.com/feature/incentivio-connect/, and live response-header probes of both API hosts name: Incentivio standards conformance description: >- Which cross-cutting standards Incentivio's live surface actually conforms to. The picture is lopsided: the OAuth 2.0 layer is genuinely standards-heavy — RFC 8414 metadata served anonymously, PKCE S256, device authorization, token exchange, revocation, introspection, and certificate-bound access tokens — while the REST layer above it conforms to almost nothing, reporting outcomes through proprietary headers with empty bodies and declaring no error responses at all. standards: - id: oauth2 name: OAuth 2.0 (RFC 6749) conforms: true evidence: >- Both services advertise authorization_code, client_credentials, refresh_token, device_code and token-exchange grants via published authorization-server metadata, and challenge with WWW-Authenticate: Bearer realm="restservice". - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: true evidence: >- GET /.well-known/oauth-authorization-server returns 200 with a complete metadata document on both mobile.incentivio.com/incentivio-mobile-api and adminapi.incentivio.com/incentivio-admin-api. - id: rfc7636 name: PKCE (RFC 7636) conforms: true evidence: 'code_challenge_methods_supported: ["S256"]' - id: rfc8628 name: OAuth 2.0 Device Authorization Grant (RFC 8628) conforms: true evidence: device_authorization_endpoint published; device_code in grant_types_supported. - id: rfc8693 name: OAuth 2.0 Token Exchange (RFC 8693) conforms: true evidence: 'urn:ietf:params:oauth:grant-type:token-exchange in grant_types_supported' - id: rfc7009 name: OAuth 2.0 Token Revocation (RFC 7009) conforms: true evidence: revocation_endpoint published with six client auth methods. - id: rfc7662 name: OAuth 2.0 Token Introspection (RFC 7662) conforms: true evidence: introspection_endpoint published. - id: rfc8705 name: OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access Tokens (RFC 8705) conforms: true evidence: >- tls_client_certificate_bound_access_tokens is true; tls_client_auth and self_signed_tls_client_auth are both offered as token endpoint auth methods. - id: rfc7523 name: JWT Client Authentication (RFC 7523) conforms: true evidence: client_secret_jwt and private_key_jwt in token_endpoint_auth_methods_supported. - id: oidc name: OpenID Connect Discovery conforms: false evidence: >- /.well-known/openid-configuration returns 401 on the mobile service and is not served anywhere. Neither metadata document declares userinfo_endpoint, id_token_signing_alg_values_supported or the openid scope. This is an OAuth 2.0 authorization server, not an OIDC provider. - id: openapi name: OpenAPI 3.x conforms: true partial: true evidence: >- OpenAPI 3.0.1 (mobile, 125 operations) and 3.1.0 (admin, 421 operations), both valid and both auto-generated by springdoc. Structurally conformant, semantically empty: no summaries, no descriptions, no examples, no securitySchemes, no 4xx/5xx responses, and 304 admin operations declare `*/*` as their response media type. - id: rfc9457 name: Problem Details for HTTP APIs (RFC 9457) conforms: false evidence: >- No application/problem+json anywhere. Errors carry an empty body and report through the proprietary incentivio-code / incentivio-message headers. - id: rfc9116 name: security.txt (RFC 9116) conforms: false evidence: '/.well-known/security.txt returns 404 on incentivio.com and 401 on both API hosts.' - id: rfc8594 name: Sunset header / deprecation policy (RFC 8594) conforms: false evidence: No Sunset or Deprecation header observed; no deprecated operations declared. - id: rfc9110-ratelimit name: RateLimit header fields conforms: false evidence: No RateLimit-*, X-RateLimit-* or Retry-After header on any of the 40 endpoints probed. - id: idempotency name: Idempotency keys conforms: false evidence: Zero idempotency parameters or headers across 546 operations. - id: pagination name: Conventional pagination conforms: true partial: true evidence: >- Consistent page/count query parameters (44 and 45 operations) with a PaginationRequest schema, but three different paging response shapes and no cursor support. - id: hsts name: HTTP Strict Transport Security conforms: true evidence: 'strict-transport-security: max-age=31536000 ; includeSubDomains on both API hosts and on incentivio.com' - id: b3-tracing name: Distributed tracing propagation conforms: true partial: true evidence: >- trace-id and span-id returned on responses (Micrometer/B3 shape), but there is no documented client-supplied correlation header. compliance: published: true posture: self-attested, not certified claims: - framework: SOC 2 claim: >- "SOC 2 aligned with encryption at rest and in transit, RBAC, and your data stays yours." source: https://incentivio.com/feature/incentivio-connect/ certified: false note: >- The wording is "aligned", not "certified" or "Type II". No report, no auditor, no bridge letter, and no trust centre is published. Recorded as a published compliance claim, not as a certification. not_found: - PCI DSS - ISO 27001 - HIPAA - GDPR data processing addendum - FedRAMP note: >- Incentivio handles card payments through gateway integrations (Spreedly connectors, Stripe, Braintree, Authorize.net, Heartland, Moneris, WorldPay) and stores payment instruments, so a PCI posture certainly exists — it is simply not published anywhere reachable. There is no trust centre at trust.incentivio.com, and https://incentivio.com/security/ returns 404. privacy_pages: - https://incentivio.com/privacy/ - https://incentivio.com/cookie-policy-eu/ - https://incentivio.com/cookie-policy-uk/ - https://incentivio.com/cookie-policy-ca/ - https://incentivio.com/opt-out-preferences/ - https://incentivio.com/gift-card-fraud-consumer-notice/