generated: '2026-07-19' method: derived source: openapi/laserdata-core-openapi.json, openapi/laserdata-audit-openapi.json, openapi/laserdata-notifier-openapi.json, https://docs.laserdata.cloud/api notes: >- Standards conformance derived from the three published OpenAPI 3.1 documents and the API overview docs. LaserData publishes no third-party certification or compliance program (no SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP or GDPR attestation was found on the site, the docs, or a trust center), so no Compliance pointer is emitted. standards: - id: openapi-3.1 conforms: true evidence: All three public services publish openapi 3.1.0 documents at api.laserdata.cloud/openapi/{core,audit,notifier}.json - id: rfc7807-problem-details conforms: true evidence: Every non-2xx response is served as application/problem+json and the docs explicitly model the envelope on RFC 7807. - id: rfc9457-problem-details conforms: partial evidence: The envelope is RFC 7807-shaped (type/title/status/instance) and adds code, reason, field, field_issues and retryable, but the docs cite RFC 7807 rather than its RFC 9457 successor. - id: rfc8288-web-linking conforms: true evidence: Paginated list responses carry a Link response header with rel first, prev, next and last. - id: idempotency-key conforms: true evidence: POST/PUT/PATCH accept an idempotency-key request header cached 10 minutes per (api_key, idempotency-key) pair, with an idempotent-replayed response header. - id: rfc6585-429-retry-after conforms: true evidence: Per-key rate limiting returns 429 Too Many Requests with a Retry-After header; also sent on transient 5xx. - id: api-key-auth conforms: true evidence: apiKey securityScheme ld_api_key, in header, name ld-api-key, declared across all three specs. - id: oauth2 conforms: false evidence: 'Docs state explicitly: "There are no sessions, cookies, or OAuth flows for API access." No oauth2 securityScheme in any spec.' - id: oidc conforms: false - id: rfc8594-sunset conforms: false evidence: No Sunset or Deprecation header support documented; no deprecated operations in spec. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on every LaserData host. - id: json-api conforms: false - id: odata conforms: false - id: scim2 conforms: false - id: fhir-r4 conforms: false - id: fapi conforms: false - id: psd2 conforms: false