generated: '2026-08-25' method: searched source: >- https://trust.lemfi.com/ ; https://lemfi.com/en-us/security ; https://lemfi.com/en-us/legal/vulnerability-disclosure-policy note: >- LemFi publishes NO machine-readable API contract (see x-coverage in apis.yml), so every API-technical conformance below is asserted false on the basis of an absent contract rather than an inspected one. The organisational and regulatory conformances are read from LemFi's own published trust center and security page. Nothing here is inferred from a spec, because there is no spec. conformance: - id: soc2-type-ii conforms: true evidence: source: https://trust.lemfi.com/ detail: >- Trust center lists SOC 2 Type II with a certificate and a bridge letter, both released on request. - id: iso-27001 conforms: true evidence: source: https://trust.lemfi.com/ detail: Trust center lists ISO 27001 as a compliance framework. - id: pci-dss conforms: true level: '1' evidence: source: https://trust.lemfi.com/ detail: >- Trust center lists PCI DSS Level 1 with a certificate and an AOC report, both released on request. - id: gdpr conforms: true evidence: source: https://trust.lemfi.com/ detail: Trust center lists GDPR; privacy policy is public. - id: fincen-msb conforms: true evidence: source: https://lemfi.com/en-us/security detail: >- Pomelo Two US LLC (NMLS 2523778) is registered with FinCEN as a money services business, state registration 31000314492366. - id: rfc-9116-security-txt conforms: false evidence: source: https://lemfi.com/.well-known/security.txt http_status: 404 detail: >- A vulnerability disclosure policy exists as an HTML page but is not advertised at the RFC 9116 well-known location. - id: oauth2 conforms: false evidence: detail: No public OAuth surface; no authorization server metadata served on any host. - id: oidc conforms: false evidence: detail: /.well-known/openid-configuration returns 404 on every LemFi host. - id: openapi conforms: false evidence: detail: >- No OpenAPI/Swagger document found on lemfi.com, blog.lemfi.com, trust.lemfi.com, api.lemonade.finance or app.lemonade.finance. - id: rfc-9457-problem-details conforms: false evidence: detail: No published error contract to evaluate. - id: idempotency conforms: false evidence: detail: No published API conventions to evaluate. domain_standards: probed: - id: iso-20022 conforms: false rationale: >- LemFi is a cross-border payments provider, so ISO 20022 message types are the obvious domain standard to look for. No public contract exists in which such a declaration could appear, and LemFi makes no ISO 20022 claim on any public page. REWARD-ONLY check: recorded as not-found, not as a failure. - id: psd2-open-banking conforms: false rationale: >- LemFi is a UK/EU-regulated EMI, which puts PSD2 in its regime, but it is a payment initiator to consumers rather than an ASPSP publishing a PSD2 API. No PSD2/OBIE endpoint or conformance claim is published. note: >- No domain standard is declared in any LemFi contract, because LemFi publishes no contract. This is recorded as absence, not as non-conformance.