generated: '2026-09-03' method: searched source: >- https://leadping.ai/docs (compliance + trust pages) cross-checked against openapi/_original/leadping-openapi.json and live /.well-known probes on 2026-09-03 standards: - id: openapi-3.1 name: OpenAPI 3.1 conforms: true evidence: >- openapi/_original/leadping-openapi.json declares "openapi": "3.1.1" with 119 paths, 144 operations, 234 component schemas, unique operationIds and declared securitySchemes. Served from https://api.leadping.ai/openapi/v1.json (HTTP 200, application/json). - id: rfc9457 name: 'RFC 9457 Problem Details for HTTP APIs' conforms: true evidence: >- A ProblemDetails schema with type/title/status/detail/instance is referenced by 4xx/5xx responses across the contract; 243 responses declare application/problem+json, including all 136 declared 429s and 99 403s. Live 401 from https://api.leadping.ai/mcp returned content-type: application/problem+json. caveat: >- Most 400/401/404/500 responses declare application/json rather than application/problem+json while carrying the same schema, and no registry of "type" URIs is published. - id: rfc9727 name: 'RFC 9727 API Catalog (/.well-known/api-catalog)' conforms: true evidence: >- https://leadping.ai/.well-known/api-catalog returned HTTP 200 with content-type: application/linkset+json; profile="https://www.rfc-editor.org/info/rfc9727", a linkset naming service-desc (the OpenAPI), service-doc, service-meta, status, and oauth-protected-resource. api.leadping.ai serves a second catalog that links back to it. - id: rfc9728 name: 'RFC 9728 OAuth 2.0 Protected Resource Metadata' conforms: true evidence: >- /.well-known/oauth-protected-resource returns 200 on both leadping.ai and api.leadping.ai naming the authorization server, bearer_methods_supported, scopes_supported and documentation URIs. The 401 from the MCP endpoint carries WWW-Authenticate: Bearer resource_metadata="…/.well-known/oauth-protected-resource". - id: rfc8414 name: 'RFC 8414 OAuth 2.0 Authorization Server Metadata' conforms: true evidence: >- https://leadping.ai/.well-known/oauth-authorization-server returns 200 with issuer, endpoints, grant_types_supported, code_challenge_methods_supported (S256) and scopes_supported. - id: oidc-discovery name: OpenID Connect Discovery 1.0 conforms: true evidence: >- https://leadping.ai/.well-known/openid-configuration returns 200 with issuer, jwks_uri, userinfo_endpoint, id_token_signing_alg_values_supported (RS256) and subject_types_supported. The issuer is Leadping's WorkOS AuthKit tenant. - id: oauth2 name: OAuth 2.0 conforms: true evidence: >- authorization_code, client_credentials, refresh_token and device_code grants with PKCE S256, per the authorization-server metadata. Applies to user and agent identities; organization API keys and source keys are static bearer credentials outside the OAuth flow. - id: rfc9116 name: 'RFC 9116 security.txt' conforms: true partial: true evidence: >- https://leadping.ai/.well-known/security.txt returns 200 text/plain with Contact and Expires. caveat: >- Contact and Expires only. No Policy, Encryption, Preferred-Languages, Canonical or Acknowledgments field, so the file does not point at the responsible-disclosure page Leadping actually publishes. - id: standard-webhooks name: Standard Webhooks conforms: true evidence: >- https://leadping.ai/docs/validating-webhooks documents webhook-id / webhook-timestamp / webhook-signature headers, the {id}.{timestamp}.{body} signed content, HMAC-SHA256, the whsec_ key format and v1 signature list, and directs consumers to the Standard Webhooks reference libraries rather than a Leadping verifier. - id: mcp name: 'Model Context Protocol (Streamable HTTP)' conforms: true evidence: >- https://leadping.ai/docs/mcp answered an anonymous initialize with protocolVersion 2025-06-18 and tools/list with 3 tools. https://api.leadping.ai/mcp is documented as stateless Streamable HTTP at protocol revision 2026-07-28 and returned a spec-shaped 401 with a resource_metadata challenge. - id: apis-json name: APIs.json conforms: true evidence: >- https://api.leadping.ai/apis.json returns 200, specificationVersion 0.22, with three api entries and a 39-entry common block. Mirrored at https://leadping.ai/apis.json. - id: llms-txt name: llms.txt conforms: true evidence: >- https://leadping.ai/llms.txt (200), https://leadping.ai/llms-full.txt (200) and a 44KB docs index at https://leadping.ai/docs/llms.txt (200) listing 170 markdown pages. - id: agent-skills-discovery name: 'agentskills.io discovery 0.2.0' conforms: true evidence: >- https://leadping.ai/.well-known/agent-skills/index.json returns 200 against $schema https://schemas.agentskills.io/discovery/0.2.0/schema.json with one sha256-digested skill. - id: a2a name: 'A2A 1.0.0 Agent Card' conforms: true grade: conformant evidence: >- https://api.leadping.ai/.well-known/agent-card.json returned HTTP 200, content-type application/json, 1505 bytes, on 2026-09-03 - a JSON object with real AgentCard shape. All three A2A 1.0.0 hard checks pass: capabilities is an OBJECT, protocolVersion is present ("1.0", on supportedInterfaces[0] where 1.0.0 carries it), and skills is an ARRAY with one fully-populated skill. defaultInputModes and defaultOutputModes are both declared. The declared interface https://api.leadping.ai/a2a returns 405 to a GET, confirming a callable JSONRPC endpoint rather than a documentation page. Saved verbatim to a2a/leadping-agent-card.json; graded in a2a/leadping-a2a.yml. changed: >- CHANGED since 2026-08-18, when this entry read conforms:false. At that time leadping.ai answered 200-with-SPA-shell for every /.well-known/* path (correctly rejected as a false positive) and api.leadping.ai returned 404 for agent-card.json. Both have changed: the apex now returns a real 404 and the API host now serves a real card. This is a new provider surface, not a corrected miss. caveat: >- The card exposes ONE read-only skill (lead-research) against a 144-operation REST contract and an authenticated MCP server, so the A2A surface is deliberately narrow and is not a projection of the whole API. - id: asyncapi name: AsyncAPI conforms: false evidence: >- No AsyncAPI document at any probed location, no top-level webhooks object and no callbacks in the OpenAPI. Webhooks are documented in prose only. See asyncapi/leadping-webhooks.yml. - id: graphql name: GraphQL conforms: false evidence: 'https://api.leadping.ai/graphql returned 404. No GraphQL surface.' - id: rfc8594 name: 'RFC 8594 Sunset header' conforms: false evidence: No Sunset or Deprecation header declared on any of the 137 operations; no deprecation policy page. - id: ratelimit-headers name: 'IETF RateLimit header fields' conforms: false evidence: >- Only Retry-After is returned on 429. No RateLimit-Limit / RateLimit-Remaining / RateLimit-Reset or X-RateLimit-* headers are documented or declared. compliance_programs: certifications: [] note: >- Leadping names no third-party certification or attestation (no SOC 2, ISO 27001, PCI DSS, HIPAA attestation or FedRAMP). What it publishes is an operational compliance program for responsible lead communication — see security/leadping-trust-center.yml. regimes_addressed: - id: a2p-10dlc name: A2P 10DLC carrier registration evidence: >- https://leadping.ai/docs/carrier-registration plus REST operations for phone-number provider status, warmup status and organization 10DLC notes. - id: consent-tcpa-shaped name: Consent, opt-out, DNC and suppression controls evidence: >- https://leadping.ai/docs/compliance documents a six-part source/consent/sender/channel/message/ timing alignment model; the REST contract exposes a Suppressions resource (suppress, release, check, list, get) and an Acceptable Use Policy plus Forbidden Message Categories page. - id: trustedform name: TrustedForm consent evidence evidence: https://leadping.ai/docs/requiring-trustedform — required for sources that need it. - id: hipaa-baa name: HIPAA Business Associate Agreement evidence: >- https://leadping.ai/docs/business-associate-agreement — BAA terms for expressly approved PHI use. A contractual offer, not an audited attestation. - id: data-subject-rights name: Data deletion and export evidence: >- https://leadping.ai/docs/data-deletion, https://leadping.ai/docs/account-deletion, plus the UserDataExports REST operations (request, get, download). - id: subprocessors name: Published subprocessor list evidence: https://leadping.ai/docs/subprocessors domain_standard_conformance: generated: '2026-09-03' method: derived derived_from: openapi/_original/leadping-openapi.json market: >- US lead generation and A2P (application-to-person) messaging. The governing regimes here are carrier-mandated 10DLC registration (CTIA / The Campaign Registry) and TCPA-driven written-consent evidence, with ActiveProspect TrustedForm as the de-facto consent-certificate standard the lead industry actually transacts on. summary: >- Leadping declares its market's standards IN THE CONTRACT, not only in marketing prose. The OpenAPI carries first-class 10DLC registration types and TrustedForm certificate types, and a lead-intake request has a dedicated trustedFormUrl field. A buyer who already runs TrustedForm and 10DLC integrates against named fields rather than a bespoke connector. standards: - id: trustedform name: 'ActiveProspect TrustedForm consent certificate' conforms: true signature: named schema + request field evidence: - 'components.schemas.TrustedFormCertificate — a dedicated certificate type in the contract.' - 'components.schemas.LeadIntakeRequest.trustedFormUrl — the certificate URL is a first-class field on the lead-intake payload.' - 'components.schemas.LeadMetadata.trustedFormUrl and LeadMetadata.trustedFormCheckedAt — the certificate and its verification timestamp are persisted on the lead.' - 'components.schemas.SourceRequest.requiresTrustedForm and SourceResponse.requiresTrustedForm — per-source enforcement is configurable through the API.' - 'components.schemas.OrganizationCompliancePolicy.requireTrustedFormForAutomations — organization-level enforcement for automated outreach.' - 'components.schemas.UserNotificationPreferences.smsConsentTrustedFormCertificate.' docs: https://leadping.ai/docs/requiring-trustedform - id: a2p-10dlc name: 'A2P 10DLC brand and campaign registration (The Campaign Registry / CTIA)' conforms: true signature: named schemas + registration status enums + campaign identifiers evidence: - 'components.schemas.TenDlcApplicationDraft, TenDlcApplicationStatus, TenDlcRegistrationStatus, TenDlcNotesRequest — four dedicated 10DLC types.' - 'components.schemas.OrganizationActivationState.tenDlcStatus / tenDlcApplicationId / tenDlcDraft — registration state is part of organization activation.' - 'components.schemas.PhoneNumberRoutingMetadata.tenDlcApplicationId and PhoneNumberTableRow.tenDlcCampaignStatus — registration is bound to the sending number.' - 'campaignId appears on EligibleOutgoingNumberResponse, InitiateCallRequest, OutgoingNumberSelectionRequest/Response, PhoneCallResponse and EventTableRow — the campaign identifier travels with every send decision.' docs: https://leadping.ai/docs/carrier-registration - id: consent-optout-suppression name: 'TCPA-shaped consent, opt-out and suppression handling' conforms: true partial: true signature: consent state fields + a first-class Suppressions resource + opt-out rate metrics evidence: - 'components.schemas.LeadMetadata.smsConsentStatus, smsConsentPhoneNumber, smsOptOutAt — consent state and opt-out timestamp are modelled per lead.' - 'Suppressions resource with Suppressions_Suppress (POST /suppressions), Suppressions_Release (POST /suppressions/release), Suppressions_Check (POST /suppressions/check), Suppressions_Get and Suppressions_GetAllForCurrentOrganization.' - 'components.schemas.PhoneNumberOptOutMetricsResponse.optOutCount and optOutRatePercent — opt-out rate is a measured, exposed metric, which is the number carriers actually police.' caveat: >- TCPA is a statute, not a wire standard, so there is no schema URN or message type to declare. This entry records that the CONTRACT models the obligations, not that a conformance body has certified anything. No third-party attestation is claimed anywhere by Leadping. docs: https://leadping.ai/docs/compliance not_applicable: - id: scim note: No user-provisioning surface; no urn:ietf:params:scim:schemas:* URN anywhere in the contract. - id: odata note: No $metadata endpoint and no OData query conventions. - id: openrtb note: Leadping is not an ad-exchange participant; no bid endpoint. - id: hl7-x12-edifact-iso20022 note: >- No healthcare, EDI or payments message types, despite the HIPAA BAA offer — the BAA governs PHI that may travel through ordinary lead fields, not an HL7 or X12 interchange.