generated: '2026-07-19' method: searched source: https://www.leal.health/privacy-policy note: >- Leal Health publishes no OpenAPI, no API reference, and no certification or trust-center page, so most cross-cutting API standards cannot be asserted either way. The only published conformance claim found on the company's public surface is its GDPR/UK-DPA data-controller declaration in the privacy policy. No SOC 2, ISO 27001, HIPAA, HITRUST, PCI DSS, or FedRAMP claim appears anywhere on leal.health -- notable for an oncology platform that ingests patient-reported clinical data. No `Compliance` pointer is wired into apis.yml because no compliance program is published. standards: - id: gdpr conforms: true evidence: >- Privacy policy states Leal Health is a data controller under the EU General Data Protection Regulation and the UK Data Protection Law 2018 for patient personal data. source: https://www.leal.health/privacy-policy - id: hipaa conforms: unknown evidence: no HIPAA claim found on any public leal.health page probed 2026-07-19 - id: soc2 conforms: unknown evidence: no SOC 2 claim or trust center found (trust./security. subdomains do not resolve) - id: iso-27001 conforms: unknown evidence: no ISO 27001 claim found on any public page - id: oauth2 conforms: unknown evidence: no OpenAPI and no auth documentation; api.leal.health returns 401 with no WWW-Authenticate header - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 (marketing hosts) / 401 (api host) - id: rfc9457-problem-details conforms: unknown evidence: no OpenAPI or error reference published; 401 responses carry an empty body - id: rfc9116-security-txt conforms: false evidence: no /.well-known/security.txt on any host (see well-known/leal-health-fka-trialjectory-well-known.yml) - id: fhir-r4 conforms: unknown evidence: no published data model; platform is documented as connecting to ClinicalTrials.gov, not FHIR