generated: '2026-07-19' method: derived source: openapi/kota-openapi-original.json, https://docs.kota.io/api-reference/errors, https://www.kota.io/security standards: - id: openapi-3.1 conforms: true evidence: 'openapi: 3.1.1 document published at https://api.kota.io/openapi.json' - id: rfc9457-problem-details conforms: true evidence: All documented error responses use application/problem+json with type/title/status/detail; 109 problem+json responses in the spec - id: rfc9110-http-semantics conforms: true evidence: Problem type URIs reference RFC 9110 status-code sections - id: idempotency-key conforms: true evidence: Idempotency-Key header parameter on POST operations; 409 conflict on parameter mismatch - id: http-bearer-auth conforms: true evidence: components.securitySchemes.bearerAuth type http scheme bearer - id: pagination conforms: true evidence: page/page_size query params with items/page/page_size/total_count envelope - id: webhooks conforms: true evidence: 61 entries under OpenAPI 3.1 webhooks (v1 and v2 event families) - id: oauth2 conforms: false evidence: No oauth2 security scheme; API keys only - id: oidc conforms: false - id: asyncapi conforms: false evidence: No AsyncAPI document published; event surface is described via OpenAPI webhooks - id: json-api conforms: false - id: odata conforms: false - id: fhir conforms: false - id: fapi conforms: false - id: scim conforms: false - id: psd2 conforms: false - id: iso-27001 conforms: true evidence: ISO 27001:2022 audit completed - https://www.kota.io/security - id: gdpr conforms: true evidence: GDPR compliance stated; EU-hosted infrastructure - https://www.kota.io/security - id: pci-dss conforms: true evidence: Card processing delegated to Stripe (PCI Level 1); Kota stores no card data - https://www.kota.io/security - id: totp-rfc6238 conforms: true evidence: Authenticator app 2FA support (RFC 6238-compatible) - changelog v4.2.6, 2026-04-08 compliance_program: trust_center: https://trust.kota.io/ security_page: https://www.kota.io/security certifications: - ISO 27001:2022 - GDPR - PCI DSS (via Stripe) infrastructure_inherited: - SOC 1 - SOC 2 - SOC 3 - HIPAA infrastructure_notes: SOC 1/2/3 and HIPAA are held by Kota's hosting providers (Microsoft Azure, Google Cloud Platform), not by Kota directly. hosting: EU (Microsoft Azure, Google Cloud Platform)