generated: '2026-07-19' method: derived source: >- openapi/leadgenius-enrichment-api-openapi.yml plus the published reference at https://docs.leadgenius.com/ and the LeadGenius legal pages. description: >- Which cross-cutting and industry standards the LeadGenius Enrichment API conforms to. Derived from the captured OpenAPI and the documented conventions; privacy-regulation entries reflect the compliance posture LeadGenius states publicly on its site and legal pages, not an audited certification (LeadGenius publishes no trust center and names no SOC 2 / ISO 27001 certification). standards: - id: rest conforms: true evidence: JSON over HTTPS with resource paths and standard HTTP verbs (GET/POST/PATCH). - id: openapi conforms: false evidence: >- LeadGenius publishes no machine-readable OpenAPI definition; the spec in openapi/ was captured by API Evangelist from the published reference. - id: api-key-auth conforms: true evidence: 'Authorization: Token {apikey} header, modelled as an apiKey securityScheme.' - id: oauth2 conforms: false evidence: No OAuth flows documented; the API is key-authenticated only. - id: oidc conforms: false - id: rfc9457-problem-details conforms: false evidence: >- Errors use a field-keyed validation envelope ({"type": ["This field is required."]}), not application/problem+json. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header documented. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on www.leadgenius.com. - id: webhooks conforms: true evidence: >- Campaign webhook_url receives a POST with content-type application/json when records are finalized. No signature scheme is documented. - id: asyncapi conforms: false evidence: No AsyncAPI document is published; the event surface is webhook-only. - id: idempotency conforms: false evidence: No idempotency key header or parameter is documented. - id: pagination conforms: true evidence: Campaign record retrieval is paginated at 100 records with id and finalization-date filters. - id: rate-limiting conforms: true evidence: Published limit of 50 requests/minute, 200 records/request, HTTP 429 on breach. - id: json-api conforms: false - id: gdpr conforms: true evidence: >- LeadGenius states GDPR compliance for its data sourcing and publishes a privacy policy at https://www.leadgenius.com/legal/privacy. Self-asserted, not an audited certification. - id: ccpa conforms: true evidence: >- LeadGenius publishes a dedicated CCPA page at https://www.leadgenius.com/legal/ccpa and markets a privacy-compliance solution at https://www.leadgenius.com/solutions/privacy-compliance. Self-asserted, not an audited certification. - id: soc2 conforms: unknown evidence: No SOC 2 attestation is published on any LeadGenius property probed. - id: iso27001 conforms: unknown evidence: No ISO 27001 certification is published on any LeadGenius property probed.