generated: '2026-08-23' method: searched source: https://www.janio.asia/llms.txt docs: - https://www.janio.asia/llms.txt - https://www.janio.asia/privacy - https://www.janio.asia/integrations note: >- Janio makes its compliance claims in prose only — in its own llms.txt and on the privacy page — and does not publish a trust center, an audit report, a certification number or a machine-readable contract. Two of the four claims are explicitly stated as IN PROGRESS by Janio itself ("compliant with the controls, independent certification audits in progress"), and this file records that distinction rather than flattening it into "certified". Cross-cutting API standards could not be assessed at all: no OpenAPI, AsyncAPI, GraphQL SDL or WSDL is published, and anonymous calls to the live API are rejected before any response body or header can be observed. conformance: - id: pdpa label: Singapore Personal Data Protection Act (PDPA) conforms: true status: claimed evidence: source: https://www.janio.asia/llms.txt quote: 'Compliance: PDPA compliant' verification: 'Self-asserted by Janio in its published llms.txt. No regulator registration number or assessment report is published.' - id: gdpr label: EU General Data Protection Regulation conforms: true status: claimed evidence: source: https://www.janio.asia/llms.txt quote: 'GDPR compliant' verification: 'Self-asserted. No DPA, no representative and no processor terms are linked from the public site.' - id: soc2-type-ii label: SOC 2 Type II conforms: false status: in-progress evidence: source: https://www.janio.asia/llms.txt quote: 'SOC 2 Type II and ISO 27001 — compliant with the controls, independent certification audits in progress.' verification: 'Janio states the controls are met but the independent audit is not complete. Recorded as NOT conformant: an in-progress audit is not a report, and no report is available on request or under NDA from a public page.' - id: iso-27001 label: ISO/IEC 27001 conforms: false status: in-progress evidence: source: https://www.janio.asia/llms.txt quote: 'SOC 2 Type II and ISO 27001 — compliant with the controls, independent certification audits in progress.' verification: 'Same statement as SOC 2 Type II. No certificate number, no certification body, no scope statement published.' - id: oauth2 label: OAuth 2.0 conforms: false status: not-found evidence: source: https://api.janio.asia/.well-known/oauth-authorization-server http_status: 404 verification: 'No authorization-server metadata, no documented OAuth flow, and no scope reference. The live API rejects anonymous requests with a Django REST Framework 403 {"detail":"Permission denied."} envelope, which indicates a credential-based scheme but does not disclose which one.' - id: rfc9457 label: RFC 9457 Problem Details for HTTP APIs conforms: false status: not-found evidence: source: https://api.janio.asia/api/order/orders/ http_status: 403 verification: 'The observed error body is {"detail":"Permission denied."} with content-type application/json — the Django REST Framework default envelope, not application/problem+json.' - id: rfc9116 label: RFC 9116 security.txt conforms: false status: not-found evidence: source: https://www.janio.asia/.well-known/security.txt http_status: 404 - id: rfc8594 label: RFC 8594 Sunset header / deprecation signalling conforms: false status: not-found evidence: verification: 'No versioning or deprecation policy is published, so no Sunset or Deprecation header behaviour could be asserted.' domain_standards: assessed: true result: none-found note: >- Janio's market — cross-border 4PL, customs and multi-carrier freight — has several real interchange standards a contract could declare: GS1 EPCIS for event visibility, UN/EDIFACT IFTMIN/IFTSTA and ANSI X12 204/214 for transport instruction and status, ISO 6346 container identification, IATA ONE Record for air cargo, and DCSA for ocean. None is declared anywhere Janio publishes, and with no machine-readable contract there is no spec location to point evidence at. Reward-only dimension: recorded as absent, not as a failure. Janio's public surface describes a proprietary REST/webhook interface plus platform-specific connectors (Shopify, WooCommerce, Magento) rather than a standards-based interchange, and unified tracking is described as "standardized status codes" of Janio's own definition. candidates_probed: - gs1-epcis - un-edifact-iftmin-iftsta - ansi-x12-204-214 - iso-6346 - iata-one-record - dcsa