generated: '2026-07-19' method: searched source: https://sdk-docs.kittl.dev/ notes: >- Kittl publishes no HTTP API, so the usual REST/API-standard conformance axes are largely not applicable and are recorded as such rather than asserted false to pad the file. No published compliance program (SOC 2 / ISO 27001 / PCI DSS / HIPAA / FedRAMP) was found — trust.kittl.com does not resolve and /security, /trust and /compliance all return 404 — so NO `Compliance` pointer is emitted in apis.yml. standards: - id: oauth2 conforms: true role: client evidence: >- Apps declare third-party OAuth providers (clientId, authorizationUrl, tokenUrl, scope, accessType) in manifest.json config.oauthProviders and run the authorization code flow via kittl.auth.startAuth / kittl.auth.exchangeCode. Kittl acts as an OAuth client, not an authorization server. source: https://sdk-docs.kittl.dev/Guides/Advanced/authentication - id: oauth2.1-pkce conforms: true role: client evidence: >- kittl.auth.startAuth accepts generatePKCE: true and returns a code_verifier for the exchange; documented as recommended when the provider supports OAuth 2.1 / PKCE. source: https://sdk-docs.kittl.dev/Guides/Advanced/authentication - id: oidc conforms: false evidence: >- No /.well-known/openid-configuration on any Kittl host; Kittl operates no OpenID Provider. - id: jwt-rfc7519 conforms: true evidence: >- kittl.auth.getUserToken() issues a short-lived user JWT verified server-side by @kittl/sdk-backend, with appId enforced as the audience claim and a pseudonymous per-app subject in `sub`. Signing keys are fetched and cached, implying published JWKS-style key rotation. source: https://sdk-docs.kittl.dev/getting-started/sdk-backend - id: json-schema-2020-12 conforms: true evidence: >- The canonical extension manifest schema at https://api.kittl.com/extensions/manifest/schema.json declares $schema: https://json-schema.org/draft/2020-12/schema. Captured verbatim in json-schema/kittl-extension-manifest-schema.json. source: https://api.kittl.com/extensions/manifest/schema.json - id: rfc9116-security-txt conforms: true evidence: >- https://www.kittl.com/.well-known/security.txt returns 200 with Contact, Preferred-Languages and a valid unexpired Expires field (2027-01-01). source: https://www.kittl.com/.well-known/security.txt - id: llms-txt conforms: true evidence: >- Two published llms.txt documents — https://www.kittl.com/llms.txt (platform overview) and https://sdk-docs.kittl.dev/llms.txt (SDK docs map, with a companion llms-full.txt). source: https://sdk-docs.kittl.dev/llms.txt - id: openapi conforms: false evidence: >- No OpenAPI or Swagger document published; the developer surface is a client-side SDK rather than an HTTP API. /openapi.json 404 on all probed hosts. - id: asyncapi conforms: false evidence: >- No AsyncAPI document and no HTTP webhook surface. The SDK does expose an in-editor event model (state subscriptions and kittl.stateless inter-app messaging), but it is client-side postMessage, not a network event surface. - id: rfc9457-problem-details conforms: false not_applicable: true evidence: >- No HTTP responses to carry application/problem+json. Errors use a client-side discriminated union on the SdkResult failure branch; see errors/kittl-problem-types.yml. - id: rfc8594-sunset-header conforms: false evidence: No deprecation or sunset policy published; see lifecycle/kittl-lifecycle.yml. compliance_program: published: false probed: - https://trust.kittl.com - https://www.kittl.com/security - https://www.kittl.com/trust - https://www.kittl.com/compliance certifications: [] note: >- Kittl publishes public Terms and a Privacy Policy, and is a Berlin-based (EU) company subject to GDPR, but no named certification or trust center was found. Absence here is recorded data, not an assertion that no program exists internally. related: - authentication/kittl-authentication.yml - json-schema/kittl-extension-manifest-schema.json - security/kittl-vulnerability-disclosure.yml