generated: '2026-07-19' method: searched sources: - openapi/lendapi-openapi.json - https://developer.lendapi.com/reference/introduction - https://www.lendapi.com/blog/lendapi-achieves-soc-2-type-2-compliance standards: - id: openapi-3.1 conforms: true evidence: Published definition declares openapi 3.1.0. - id: rest conforms: true evidence: >- Documentation states the API follows REST principles with a resource-oriented URL design, JSON request/response bodies, and standard HTTP verbs and codes. - id: oauth2 conforms: false evidence: Only an apiKey security scheme (AUTHORIZATION header) is declared. - id: oidc conforms: false - id: rfc9457-problem-details conforms: false evidence: Error responses are bare application/json with an empty object schema. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on all hosts. - id: rfc8594-sunset-header conforms: false evidence: No deprecation or sunset policy published. - id: idempotency-key conforms: false evidence: No idempotency key on any write operation. - id: pagination conforms: true evidence: Offset pagination via start/size query parameters on all list operations. - id: webhooks conforms: true evidence: >- Eight documented application lifecycle event types with a typed envelope (api_version, type, live_mode, data). - id: asyncapi conforms: false evidence: Webhooks are documented in prose only; no AsyncAPI document is published. - id: soc2-type2 conforms: true evidence: >- SOC 2 Type 2 audit completed and announced 2024-09-04; monitoring by Secureframe, audit by Johanson LLP. url: https://www.lendapi.com/blog/lendapi-achieves-soc-2-type-2-compliance - id: fcra-consumer-reporting conforms: unknown evidence: >- LendAPI brokers consumer credit-bureau data (Equifax, TransUnion) through its Credit Bureau Access product and marketplace, but publishes no explicit FCRA compliance statement in its developer documentation. compliance_program: published: true certifications: - SOC 2 Type 2 url: https://www.lendapi.com/blog/lendapi-achieves-soc-2-type-2-compliance trust_center: null trust_center_notes: >- No trust.lendapi.com and no /trust, /security or /compliance page exists; the SOC 2 attestation is announced in a blog post only. There is no self-serve portal for requesting the report.