generated: '2026-08-25' method: probed source: >- https://auth.leapfinance.com/.well-known/openid-configuration (HTTP 200) and live HTTP responses observed from https://api.leapscholar.com/* (HTTP 400 application/problem+json), probed 2026-08-25. name: Leap Finance conformance description: >- Cross-cutting standards conformance for Leap Finance Inc., asserted only where a live probe produced evidence. Leap Finance publishes no API contract, so most contract-level standards cannot be assessed at all; those are recorded as unknown rather than false, because "not assessable" and "does not conform" are different facts. standards: - id: oauth2 conforms: true evidence: >- RFC 8414 authorization server metadata served at https://auth.leapfinance.com/.well-known/oauth-authorization-server (HTTP 200), declaring authorization, token, revocation and device-code endpoints and 14 grant types. - id: oidc conforms: true evidence: >- OpenID Connect Discovery 1.0 document served at https://auth.leapfinance.com/.well-known/openid-configuration (HTTP 200) with issuer, jwks_uri, userinfo_endpoint, claims_supported and the openid scope. - id: rfc7636-pkce conforms: true evidence: >- code_challenge_methods_supported includes S256 in the discovery document. note: >- `plain` is also advertised. RFC 7636 permits it but S256 is required of any client that can compute it. - id: rfc9449-dpop conforms: true evidence: dpop_signing_alg_values_supported = [ES256] in the discovery document. - id: rfc7591-dynamic-client-registration conforms: true evidence: >- registration_endpoint https://auth.leapfinance.com/oidc/register advertised in the discovery document. Not exercised — this pipeline does not attempt client registration. - id: rfc8628-device-authorization conforms: true evidence: >- device_authorization_endpoint and the urn:ietf:params:oauth:grant-type:device_code grant type are advertised. - id: rfc8693-token-exchange conforms: true evidence: >- urn:ietf:params:oauth:grant-type:token-exchange present in grant_types_supported. - id: rfc9457 conforms: true evidence: >- https://api.leapscholar.com/docs returned HTTP 400 with Content-Type application/problem+json and body {"type":"about:blank","title":"Bad Request","status":400,"detail":"Failed to convert 'preUserId' with value ..."} — a conformant RFC 9457 problem detail object with type, title, status and detail members. Observed on an unauthenticated request 2026-08-25. note: >- This is the default Spring Boot problem-detail representation rather than a curated error catalogue; `type` is about:blank, so no error taxonomy is dereferenceable. Conformant in shape, not in substance. See errors/leap-finance-problem-types.yml. - id: rfc9116-security-txt conforms: false evidence: >- /.well-known/security.txt returns 404 on auth.leapfinance.com and leapscholar.com, and a soft-404 HTML shell (HTTP 200) on leapfinance.com. No security.txt is served on any host. - id: rfc8615-well-known-api-catalog conforms: false evidence: >- /.well-known/api-catalog returns 404 on auth.leapfinance.com and leapscholar.com and a soft-404 HTML shell on leapfinance.com. - id: fapi conforms: false evidence: >- The authorization server advertises the implicit and resource-owner-password grant types and HS256 ID-token signing, and does not advertise request_parameter_supported or PAR — all disqualifying for a FAPI profile. - id: openapi conforms: unknown evidence: >- No OpenAPI or Swagger document was found on any host. Probed /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs and /redoc against leapfinance.com (soft-404 HTML shell on all), leapscholar.com (404 on all), auth.leapfinance.com (404 on all) and api.leapscholar.com (400/403 on all). Not assessable. - id: asyncapi conforms: unknown evidence: No event, streaming or webhook surface is published. Not assessable. - id: graphql conforms: unknown evidence: >- graphql.leapscholar.com resolves in DNS (3.133.77.149) but accepts no connection on port 80 or 443 — both time out. leapscholar.com/graphql returns 404 and leapfinance.com/graphql returns the soft-404 shell. No GraphQL surface is reachable, so introspection could not be attempted. - id: pagination conforms: unknown evidence: No published contract or reference to assess. - id: idempotency conforms: unknown evidence: No published contract or reference to assess. domain_standards: assessed_regimes: - regime: banking_open_finance basis: >- Leap Finance originates and services consumer education loans, placing it in the consumer-lending/open-finance regime. shortlist_probed: [obie, uk-open-banking, cdr-banking, consumer-data-standards, fdx, berlin-group-nextgenpsd2, fapi, fapi-2] declared: false evidence: >- No contract exists in which such a declaration could appear, and no FDX, OBIE, CDR or Berlin Group signature, endpoint or schema URN appears anywhere on the company's public surface. Leap Finance is a direct lender rather than a data-sharing participant, so no open-finance standard is expected of it. - regime: education basis: >- The company's LeapScholar property operates in study-abroad admissions counselling, adjacent to the education regime. shortlist_probed: [scim, lti, oneroster, ed-fi, caliper, qti, oai-pmh, shibboleth, saml, orcid, datacite, crossref] declared: false evidence: >- No SCIM schema URN (urn:ietf:params:scim:schemas:*), LTI launch, OneRoster, Ed-Fi, Caliper or QTI shape appears on any host. The identity tenant advertises no SAML or Shibboleth metadata endpoint in its discovery document. LeapScholar is a consumer counselling brand, not a system of record that exchanges rostering or learning data. declared_domain_standard: null note: >- domain_standard_conformance is reward-only. Leap Finance is not penalised here — it operates in markets whose standards apply to institutional data-sharing participants, and it is neither. No conformance is invented to fill the slot. compliance_certifications: [] compliance_note: >- No trust center, compliance page or named certification (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP) was found. trust.leapfinance.com, security.leapfinance.com and trust.leapscholar.com do not resolve in DNS; leapfinance.com/security and /compliance return the site's soft-404 shell. No `Compliance` pointer is emitted, because none is published. transport_security: reference: security/leap-finance-domain-security.yml summary: >- leapfinance.com serves TLS 1.3 with HSTS (max-age 63072000). DNSSEC is not enabled, no CAA record is published, SPF is present, and DMARC is published at p=none with rua/ruf pointing at a personal gmail.com address rather than a company-controlled mailbox.