generated: '2026-07-19' method: derived source: >- openapi/legendtrade-info-openapi.yml + asyncapi/legendtrade-ws-asyncapi.yml + live probes + https://docs.legend.trade description: >- Which cross-cutting standards Legend's API conforms to. DERIVED from the generated specs and live probes; Legend publishes no compliance or certification claims of any kind, so no `Compliance` pointer is wired into apis.yml. `conforms: false` here means "not observed / not published", not "verified non-compliant". standards: - id: openapi conforms: false evidence: >- Legend links an openapi.json from its llms.txt, but that file is the unmodified Mintlify "OpenAPI Plant Store" sample scaffold and does not describe the Legend API. The spec in openapi/ was generated by API Evangelist from the API's self-describing root, not published by Legend. - id: asyncapi conforms: false evidence: >- Legend operates a WebSocket event surface but publishes no AsyncAPI document. The spec in asyncapi/ was generated by API Evangelist from the channel list in the API's self-describing root. - id: hyperliquid-info-api conforms: true evidence: >- The service self-identifies as a "Hyperliquid-compatible info API" and implements the Hyperliquid POST /info request-type convention and WebSocket subscription channel names verbatim. - id: oauth2 conforms: false evidence: No oauth2 security scheme; no OAuth documented. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on all hosts. - id: rfc9457-problem-details conforms: false evidence: >- Errors use a bare `{"error": ""}` JSON envelope, not application/problem+json. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on all hosts. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header support documented or observed. - id: rfc8615-well-known conforms: false evidence: No /.well-known/ documents served; see well-known/legendtrade-well-known.yml. - id: json-api conforms: false evidence: Plain JSON responses; no JSON:API document structure. - id: idempotency conforms: false evidence: No idempotency key header or replay contract documented. - id: pagination conforms: false evidence: No pagination convention documented or observed. - id: hsts conforms: partial evidence: >- HSTS enabled with max-age 63072000 on www.legend.trade and docs.legend.trade, but NOT on the API host api.legend.trade. See security/legendtrade-domain-security.yml. - id: tls13 conforms: true evidence: TLSv1.3 negotiated on all three probed hosts. - id: dnssec conforms: false evidence: DNSSEC not enabled on legend.trade. - id: caa conforms: true evidence: >- CAA records present on legend.trade restricting issuance to pki.goog, sectigo.com, amazon.com, letsencrypt.org. - id: spf conforms: false evidence: No SPF record on legend.trade. - id: dmarc conforms: false evidence: No DMARC record on legend.trade. compliance_program: published: false certifications: [] detail: >- No trust center, no SOC 2 / ISO 27001 / PCI DSS claims, and no security or compliance page were found. trust.legend.trade and /security both 404.