generated: '2026-07-19' method: derived source: >- openapi/langdock-openapi-original.yml, plus published compliance claims at https://www.langdock.com/security and https://trust.langdock.com/ description: >- Which cross-cutting and industry standards the Langdock API conforms to. Langdock's strongest conformance story is organizational (ISO 27001, SOC 2 Type II, GDPR, EU data residency) and protocol-level (Model Context Protocol). Its REST conventions are deliberately vendor-compatible rather than standards-based: it mirrors the OpenAI and Anthropic wire formats instead of adopting JSON:API or RFC 9457. standards: - id: openapi-3.0 conforms: true evidence: Publishes a 3.0.0 document at https://docs.langdock.com/openapi.yaml — 33 paths, 38 operations, 98 component schemas. - id: mcp name: Model Context Protocol conforms: true evidence: >- Operates an official hosted MCP server at https://api.langdock.com/mcp exposing find_agent / ask_agent / ask_custom_agent, and acts as an MCP host consuming external servers. Also implements the MCP Apps (MCP-UI) extension. detail: mcp/langdock-mcp.yml - id: llms-txt conforms: true evidence: Serves a complete documentation index at https://docs.langdock.com/llms.txt (200). - id: oauth2 conforms: false evidence: >- No oauth2 securityScheme in the OpenAPI and no /.well-known/oauth-authorization-server (404). The public API authenticates with bearer API keys. OAuth appears only as a client-side option for custom integrations against third-party APIs. - id: oidc conforms: false evidence: No /.well-known/openid-configuration (404) on any Langdock host. - id: rfc9457-problem-details conforms: false evidence: >- No application/problem+json media type anywhere in the spec. Errors use a vendor discriminated union ({"type":"error","error":{"type":...,"message":...}}). detail: errors/langdock-problem-types.yml - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on www, api, and docs hosts. A disclosure policy is published as an HTML page instead. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header contract is documented; deprecation is signalled only via OpenAPI deprecated:true and migration guides. - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog returns 404. - id: json-api conforms: false evidence: Responses are provider-shaped JSON, not JSON:API documents. - id: scim conforms: false partial: unverified evidence: >- No SCIM 2.0 /Users /Groups resources are exposed in the public API — user management is a bespoke surface (POST /user-management/v1/invite, /deactivate-user). Note that the AuditLog.actor_name description lists "SCIM" as a possible actor, implying SCIM provisioning exists somewhere in the product, but no SCIM documentation page is published in the docs index, so this is recorded as unverified rather than conforming. - id: cursor-pagination conforms: true partial: true evidence: 'GET /skills/v1 and GET /audit-logs/{workspace_id} declare cursor + limit parameters; other list endpoints declare no pagination.' - id: idempotency-keys conforms: false evidence: No Idempotency-Key header or parameter in the spec and no idempotency documentation. - id: gdpr conforms: true evidence: '"Fully aligned with GDPR for strong data privacy and user protection" — https://www.langdock.com/security. EU hosting on Microsoft Azure.' - id: iso-27001 conforms: true evidence: '"Certified to the global standard for information management" — https://www.langdock.com/security' - id: soc2-type-ii conforms: true evidence: '"Independently audited to ensure secure, reliable data handling" — https://www.langdock.com/security' - id: eu-data-residency conforms: true evidence: >- Application and most models (configurable) hosted entirely in the EU; the API exposes an explicit eu region on every model route. - id: hipaa conforms: false evidence: Not claimed on the security or trust surface. - id: fedramp conforms: false evidence: Not claimed on the security or trust surface. - id: pci-dss conforms: false evidence: Not claimed; Langdock is not a payments provider. - id: fhir-r4 conforms: false - id: fapi conforms: false - id: odata conforms: false compliance_program: published: true url: https://www.langdock.com/security trust_center: https://trust.langdock.com/ certifications: - ISO 27001 - SOC 2 Type II - GDPR detail: security/langdock-trust-center.yml