generated: '2026-08-04' method: derived source: >- docs.innovapptive.com published integration/configuration guides + live probes of every Innovapptive host api: innovapptive:innovapptive-operator-rounds-api note: >- Derived from documentation and probes, not from a machine-readable spec — no OpenAPI/AsyncAPI/GraphQL document is published anonymously. Every `conforms: false` below is an observed absence, not an assumption. standards: - id: openapi conforms: false evidence: >- A Swagger UI console is published at /operatorroundsapi/external/api-docs/ on cbo, cboqa, cbodev and cwpuat2, but the OpenAPI document itself is not reachable: api-docs-json, v3/api-docs and swagger-ui-init.js all 404, and every other path under the console directory returns the same 3106-byte HTML shell. - id: oauth2 conforms: false evidence: >- External API uses an x-api-key header only. OAuth 2.0 appears solely in the customer-deployed SAP BTP API Management reference architecture, not on an Innovapptive-operated authorization server. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on every host probed. - id: rfc8414-oauth-metadata conforms: false evidence: /.well-known/oauth-authorization-server returns 404 on every host probed. - id: rfc9116-security-txt conforms: false evidence: >- /.well-known/security.txt 404s on www and docs. trust.innovapptive.com serves Atlassian's platform-default security.txt, which is not Innovapptive's. - id: rfc9457-problem-details conforms: false evidence: >- Error reference is a flat HTTP-status + English-message table; no application/problem+json, no type URIs. - id: rfc8594-sunset-header conforms: false evidence: No deprecation/sunset policy or header support published. - id: rfc8615-well-known conforms: false evidence: No /.well-known/ document of any kind found on any Innovapptive host. - id: llmstxt conforms: true evidence: >- https://docs.innovapptive.com/llms.txt returns 200 text/plain with a valid llms.txt structure (H1, blockquote summary, sectioned link lists), plus a companion llms-full.txt. Saved verbatim to llms/innovapptive-llms.txt. - id: a2a-agent-card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json 404 on www and docs; the CBO hosts answer 200 with an SPA HTML catch-all, which is rejected. - id: mcp conforms: false evidence: No hosted or packaged MCP server found in docs, registries or search. - id: asyncapi conforms: false evidence: >- No event/streaming/webhook contract published. Integration is push/pull via connectors (SAP, Maximo, ODBC/SQL Server, SFTP, SMTP), not subscribable events. - id: odata conforms: partial evidence: >- SAP OData services (RACE, mWorkOrder) are activated inside the CUSTOMER's SAP NetWeaver/Gateway landscape as part of deployment, per the mWorkOrder install and iMaintenance deployment guides. This is a customer-side surface, not an Innovapptive-operated public API. - id: dita-oxygen-webhelp conforms: true evidence: >- Entire documentation estate is DITA published through Oxygen WebHelp (data-whc_version 22.0/23.1), with per-release-train namespaces. compliance_program: published: false certifications: [] evidence: >- No SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP or GDPR certification page was found. /security, /trust, /compliance and /legal all 404 on www.innovapptive.com; trust.innovapptive.com is an Atlassian Statuspage, not a trust center. No `Compliance` or `TrustCenter` pointer is emitted. related_claims: - claim: SAP-certified solutions / SAP partner awards source: https://www.innovapptive.com/news/innovapptive-announces-sap-qualified-rapid-deployment-solutions-sap-fiori-sap-mobile-apps-sap-mobile-platform note: Vendor-partner certification, not an information-security certification. x-evidence: fetched: '2026-08-04'