generated: '2026-07-19' method: derived source: openapi/kita-capture-openapi.yml, openapi/kita-underwriter-openapi.yml, https://www.kita.ai/documentation standards: - id: rest-json conforms: true evidence: Resource-oriented HTTP APIs over JSON with conventional verb semantics and status codes. - id: openapi conforms: false evidence: 'Kita publishes no machine-readable OpenAPI description. The specs in openapi/ were generated by the API Evangelist enrichment pipeline from Kita''s published human documentation.' - id: oauth2 conforms: false evidence: 'No OAuth 2.0 authorization server, token endpoint or scopes. Authentication is a long-lived organization API key on the Authorization header.' - id: oidc conforms: false evidence: No OpenID Connect discovery document; /.well-known/openid-configuration is not served. - id: bearer-token-rfc6750 conforms: partial evidence: 'Keys are transmitted using the Bearer authentication scheme (Authorization: Bearer ), but the credential is a static API key rather than an OAuth 2.0 access token.' - id: rfc9457-problem-details conforms: false evidence: 'Errors are plain application/json — { "message": ... } on Underwriter and { "error", "message" } on Capture — not application/problem+json.' - id: json-api conforms: false evidence: 'Responses use a bare { "data": ... } envelope on Underwriter and an unwrapped result object on Capture; no JSON:API type/attributes/relationships structure.' - id: pagination-offset conforms: true evidence: Both APIs expose limit/offset pagination; Underwriter returns a pagination object with total, limit and offset. - id: idempotency conforms: partial evidence: 'POST /intake on the Underwriter API is idempotent on a client-supplied external_ref. There is no Idempotency-Key header and no idempotency contract on the Capture API.' - id: webhooks-hmac-signing conforms: true evidence: Kita Capture signs deliveries with HMAC-SHA256 over the raw body, carried on an X-Kita-Signature header with a t= timestamp and a 5-minute replay tolerance window. - id: asyncapi conforms: false evidence: No AsyncAPI document is published for the webhook surface. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation headers are documented. - id: tls13 conforms: true evidence: 'All probed hosts negotiate TLS 1.3 with HSTS enabled; Kita documents TLS 1.3 in transit and AES-256 at rest.' - id: soc2-type-ii conforms: false status: in-progress evidence: 'Kita states an active audit engagement with an engagement letter available on request; certification is not yet awarded.' - id: iso-27001 conforms: false status: in-progress evidence: Kita states an active engagement; certification is not yet awarded. - id: gdpr conforms: partial evidence: A DPA and Standard Contractual Clauses are stated to be available on request; no public GDPR compliance statement. - id: pci-dss conforms: false evidence: Not applicable — Kita does not process card data. - id: fhir-r4 conforms: false - id: scim2 conforms: false - id: odata conforms: false - id: psd2 conforms: false evidence: 'Kita is a document-intelligence and underwriting layer for lenders, not an account-servicing payment provider; it explicitly targets markets where open-finance infrastructure is limited.' - id: model-context-protocol conforms: true evidence: 'Kita publishes an official MCP server (kita-docs-mcp on npm, MIT) exposing docs and schemas as resources and the REST API as tools.' regional_domain_standards: note: 'Kita''s extraction vocabularies encode several jurisdiction-specific document standards. These are document formats Kita parses, not API conformance claims.' formats: - id: ph-sec-gis description: Philippine SEC General Information Sheet. - id: ph-statutory-deductions description: SSS, PhilHealth, Pag-IBIG and BIR withholding lines on payslips. - id: id-slik-ojk description: Indonesian SLIK (OJK) credit report — debtor profile, facilities, collateral, collectibility. - id: mx-acta-constitutiva description: Mexican Articles of Incorporation and related notarial instruments. - id: bir-forms description: Philippine BIR 2303 and 2307 tax forms (fallback extraction).