generated: '2026-07-19' method: derived source: >- openapi/klaus-public-export-api-openapi-original.json, openapi/klaus-public-import-api-openapi-original.json, https://www.zendesk.com/trust-center/ standards: - id: openapi-2.0 conforms: true evidence: 'both published specifications declare "swagger": "2.0"' - id: openapi-3.x conforms: false evidence: no OpenAPI 3.x document is published - id: oauth2 conforms: false evidence: the only securityDefinition is apiKey (Authorization header bearer token) - id: oidc conforms: false - id: bearer-token-rfc6750 conforms: partial evidence: >- the token is sent as "Authorization: Bearer " per RFC 6750, but the scheme is declared as apiKey rather than http/bearer in the specification - id: rfc9457-problem-details conforms: false evidence: errors use the google.rpc.Status envelope, not application/problem+json - id: grpc-gateway conforms: true evidence: proto*/protobuf* schema names, _ operationIds, google.rpc.Status errors - id: json-api conforms: false - id: odata conforms: false - id: scim2 conforms: false evidence: user import/export is a proprietary shape, not SCIM - id: fhir conforms: false - id: fapi conforms: false - id: psd2 conforms: false - id: pagination conforms: true evidence: page/pageSize query parameters with a protoPagination {page,pageSize,total} response object; cursor on AutoQA exports - id: idempotency conforms: partial evidence: >- import operations upsert on a caller-supplied record id (documented), but there is no Idempotency-Key request header — see conventions/klaus-conventions.yml - id: rfc8594-sunset-header conforms: false evidence: no Sunset/Deprecation header support is documented compliance_programs: source: https://www.zendesk.com/trust-center/ note: Carried by Zendesk, the parent of the Klaus/Zendesk QA product. certifications: - SOC 2 Type II - ISO 27001:2022 - ISO 27017:2015 - ISO 27018:2019 - ISO 27701:2019 - ISO 42001 - FedRAMP LI-SaaS - CSA STAR AI Levels 1 & 2 - HIPAA (BAA available) - HDS detail: security/klaus-trust-center.yml