generated: '2026-09-13' method: searched source: >- https://trust.infor.com/ (Infor Trust Center), https://developer.infor.com/tutorials/api-gateway/how-to-call-an-ion-api, https://www.infor.com/about/compliance-and-governance, and openapi/_original/infor-ion-api-gateway-openapi.yml description: >- Cross-cutting standards the Infor ION API Gateway and the surrounding Infor OS platform assert, plus the compliance certifications Infor publishes on its Trust Center. Domain-standard conformance is recorded only where the CONTRACT or the published integration surface declares it — Infor's ERP/SCM market is served by EDI and OAGIS message standards, and Infor's declaration of those lives in ION's document/BOD layer rather than in the REST contract. conformance: - id: oauth2 conforms: true evidence: >- openapi/_original/infor-ion-api-gateway-openapi.yml declares two OAuth 2.0 securitySchemes (clientCredentials and authorizationCode) with explicit authorizationUrl/tokenUrl, and both are applied at the document level. - id: oauth2-saml-bearer conforms: true evidence: >- https://developer.infor.com/tutorials/api-gateway/how-to-call-an-ion-api documents the OAuth2 SAML Bearer Grant (RFC 7522) as the primary path for calling an ION API from an application already authenticated with Infor OS. - id: oidc conforms: false evidence: >- No openIdConnect securityScheme in the contract, and no /.well-known/openid-configuration is served on any Infor host (well-known/infor-well-known.yml, all hosts 404 or soft-404). - id: rfc9457 conforms: false evidence: >- No application/problem+json response is declared on any operation; errors are vendor-shaped (errors/infor-problem-types.yml). - id: idempotency conforms: false evidence: >- No Idempotency-Key header or equivalent replay protection is documented (conventions/infor-conventions.yml, idempotency.coverage = none). - id: pagination conforms: false evidence: >- No gateway-wide pagination convention is published; paging is a property of the individual M3 business API program. - id: rfc9116 conforms: false evidence: >- No /.well-known/security.txt on any Infor host, probed 2026-09-13 (well-known/infor-well-known.yml). - id: rfc8594 conforms: false evidence: >- No Sunset or Deprecation response headers and no deprecation policy page (lifecycle/infor-lifecycle.yml). domain_standards: - id: oagis name: OAGIS Business Object Documents (BODs) conforms: true evidence: >- Infor ION is built on OAGIS-derived Business Object Documents; the ION Documents surface in openapi/_original/infor-ion-api-gateway-openapi.yml (/ion-api/documents, /ion-api/documents/{documentId}) is the REST projection of that document layer, and the Document schema carries the BOD envelope (documentType / document identity). The ION event surface in asyncapi/infor-ion-events-asyncapi.yml carries the same document model. note: >- Recorded because the contract itself exposes the document model, not because a marketing page claims OAGIS. This is the domain standard of the ERP / supply-chain market Infor sells into: a buyer who already speaks BODs integrates without a bespoke connector. - id: edi name: EDI (X12 / EDIFACT) via ION conforms: false evidence: >- Infor ION supports EDI document exchange in the ERP/distribution CloudSuites, but no EDI message type is declared in any contract in this repo and no machine-readable declaration was found on a public Infor surface. Recorded false because nothing is declared — not because EDI is absent from the product. compliance: source: https://trust.infor.com/ probed: '2026-09-13' certifications: - SOC 2 - ISO 27001 - HIPAA - FedRAMP - GDPR detail: security/infor-trust-center.yml