generated: '2026-08-25' method: searched source: >- https://trust.league.com/ ; https://league.com/league-trust-centre/ ; https://league.com/blog/industry-leading-engagement-built-off-of-leagues-fhir-native-platform/ ; https://api.league.com/ (probed 2026-08-25) name: League standards and compliance conformance provider: League summary: >- League publishes an unusually deep compliance surface for a private company — a SafeBase trust center naming a dozen-plus frameworks with downloadable audit reports — and states that its data platform is FHIR-native. What it does NOT publish is a machine-readable contract, so the contract-level conformance entries below are graded on live probe evidence only, and the domain standard (FHIR) is recorded as a first-party documented claim rather than a contract signature. conformance: - id: json:api name: JSON:API v1.x conforms: true method: probed evidence: detail: >- The gateway serves the registered JSON:API media type and returns the JSON:API top-level `errors` member with the spec's `id`/`code`/`title`/`detail` error-object fields. media_type: application/vnd.api+json body: '{"errors":[{"code":"not_found","detail":"Not found","id":"...","title":"Something Went Wrong"}]}' url: https://api.league.com/ observed: '2026-08-25' scope: >- Error documents only. Resource-document conformance (data/type/id, relationships, included, pagination links) could not be verified — no successful response is reachable anonymously. - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false method: probed evidence: detail: >- Errors are JSON:API documents, not application/problem+json. No `type`/`title`/`status`/ `detail`/`instance` problem object is returned. url: https://api.league.com/ observed: '2026-08-25' - id: oauth2 name: OAuth 2.0 conforms: false method: probed evidence: detail: >- No authorization server metadata served. /.well-known/oauth-authorization-server and /.well-known/oauth-protected-resource both 404 on api.league.com. Access is by provisioned API Key per the Developer Program Terms. observed: '2026-08-25' - id: oidc name: OpenID Connect conforms: false method: probed evidence: detail: >- /.well-known/openid-configuration 404s on api.league.com and app.league.com. League's own docs portal is fronted by Auth0, but that is an internal IdP for documentation access, not an API authorization surface offered to integrators. observed: '2026-08-25' - id: hsts name: HTTP Strict Transport Security conforms: true method: probed evidence: detail: 'strict-transport-security: max-age=31536000; includeSubDomains; preload' url: https://api.league.com/ observed: '2026-08-25' domain_standard: - id: fhir name: HL7 FHIR market: healthcare / health information exchange conforms: claimed method: searched evidence: detail: >- League states in first-party material that "At the center of our capability to integrate across data silos and personalize the consumer experience is our data platform, based on the Fast Healthcare Interoperability Resources (FHIR) standard", and that it uses "FHIR as the data model to support the integration of healthcare data on our platform and to model data that is generated by members as they interact with the platform." resources_named: [QuestionnaireResponse, CarePlan] version_named: null url: https://league.com/blog/industry-leading-engagement-built-off-of-leagues-fhir-native-platform/ contract_signature: false contract_signature_note: >- IMPORTANT — this is a DOCUMENTED CLAIM, not a contract signature. The 0.12.0 domain_standard_conformance check reads the contract (a FHIR CapabilityStatement, a /metadata endpoint, FHIR resource schemas in an OpenAPI, a fhir+json media type), and League publishes no contract at all. No FHIR CapabilityStatement or /metadata surface was found on api.league.com. The claim is recorded so the FHIR posture is not lost, and explicitly flagged so it is never scored as a verified contract-level conformance. probed: - url: https://api.league.com/metadata status: 404 - url: https://api.league.com/fhir/metadata status: 404 compliance: method: searched source: https://trust.league.com/ portal: https://trust.league.com/ portal_vendor: SafeBase (trust.league.com CNAMEs to league.portals.safebase.io) summary_page: https://league.com/league-trust-centre/ certifications: - {name: SOC 2 Type 2, report_available: true} - {name: HITRUST, report_available: true} - {name: ISO/IEC 27001, report_available: false} - {name: HIPAA, report_available: true, note: HIPAA SRA Report published in the trust center} - {name: NIST 800-53 Rev. 5, report_available: false} - {name: NIST 800-171 Rev. 3, report_available: false} - {name: NIST CSF, report_available: false} - {name: NIST AI RMF, report_available: false} - {name: FIPS 140-2, report_available: false} - {name: 21 CFR Part 11, report_available: false} - {name: 23 NYCRR 500, report_available: false} - {name: CPCSC Level 1, report_available: false} - {name: Canada PBMM, report_available: false} - {name: WCAG, report_available: false} privacy_regimes: [GDPR, EU-US DPF, UK Extension to EU-US DPF, Swiss-US DPF, PIPEDA, CCPA, CPRA, LGPD, NZ Privacy Act 2020] documents_published: [HIPAA SRA Report, HITRUST Report, Network Diagram, Pentest Report, Security and Compliance Whitepaper, SOC 2 Type 2 Report, Product Architecture, Certificate of Insurance] subprocessors: [Validic, Salesforce, Antavo, MongoDB, Google Cloud] note: >- Documents are listed on the SafeBase portal; most require an NDA/access request to download. The named frameworks and document titles are public on the portal landing page.