generated: '2026-08-13' method: derived source: openapi/_original/*.json + https://www.listrak.com/privacy-and-terms/privacy-policy notes: >- Which cross-cutting and industry standards Listrak's public API surface actually conforms to. Derived from the eight live specs plus SEARCH of the published legal/security pages. Listrak is a retail marketing platform, so the sector regimes that matter here are consent and privacy (CAN-SPAM, TCPA, CTIA, GDPR/CCPA) rather than financial or health regimes - the negative entries for FHIR/FAPI/PSD2 are recorded so the absence is explicit rather than unexamined. standards: - id: oauth2 conforms: true evidence: >- Every server-side API authenticates with OAuth 2.0 client_credentials against https://auth.listrak.com/OAuth2/Token; declared as a real oauth2 securityDefinition in the Email, SMS, Data Import and Privacy specs. - id: rfc6749-client-credentials conforms: true evidence: grant_type=client_credentials over application/x-www-form-urlencoded, bearer token in the Authorization header. - id: rfc6750-bearer-token conforms: true evidence: 'Tokens are presented as `Authorization: Bearer ` across all APIs except the device-side Mobile App Push API.' - id: rfc8414-oauth-authorization-server-metadata conforms: false evidence: /.well-known/oauth-authorization-server returns 404 on api.listrak.com, auth.listrak.com and www.listrak.com. The token endpoint is documented in prose only. - id: oidc conforms: false evidence: No OpenID Connect. /.well-known/openid-configuration 404s on every host. SAML SSO exists for the admin UI but is not part of the API surface. - id: openapi-3 conforms: partial evidence: >- Three of eight APIs publish OpenAPI 3.x (Cross Channel 3.0.4, Two-Way SMS 3.0.1, Mobile App Push 3.0.1, Media 3.1.1); four still publish Swagger 2.0 (Email, SMS, Data Import, Privacy). The surface is mid-migration. - id: swagger-2 conforms: true evidence: Email, SMS, Data Import and Privacy are served as Swagger 2.0 from //swagger/docs/v1. - id: rfc9457-problem-details conforms: false evidence: >- Errors are returned as application/json with a vendor envelope {status, error, message}, not application/problem+json. See errors/listrak-error-codes.yml. - id: stable-error-code-registry conforms: true evidence: >- 68 stable SCREAMING_SNAKE error codes published across the Email, SMS and Media specs, branchable from the `error` member. Not a formal standard, recorded because it is the substantive thing RFC 9457 is usually wanted for. - id: json-api conforms: false evidence: Responses use Listrak's own Collection/Resource envelopes, not the JSON:API media type or document structure. - id: odata conforms: false - id: scim2 conforms: false evidence: No /Users or /Groups provisioning surface; user administration is UI/SSO only. - id: fhir-r4 conforms: false - id: fapi conforms: false - id: psd2 conforms: false - id: cursor-pagination conforms: true evidence: 'CollectionPaged[T] returns nextPageCursor; requests take cursor + count (default 1000, max 5000).' - id: idempotency conforms: false evidence: No idempotency-key header or replay contract in any spec or doc. See conventions/listrak-conventions.yml. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header, and no deprecation policy. See lifecycle/listrak-lifecycle.yml. - id: ietf-ratelimit-headers conforms: false evidence: 429 is returned but no RateLimit-*, X-RateLimit-* or Retry-After header is documented. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt 404s on every host, though a disclosure policy IS published as an HTML page. - id: rfc8615-well-known conforms: false evidence: No /.well-known document of any kind is served. See well-known/listrak-well-known.yml. - id: asyncapi conforms: false evidence: No AsyncAPI document. One prose-documented webhook exists. See asyncapi/listrak-webhooks.yml. - id: mcp conforms: false evidence: No MCP server, first-party or community. - id: a2a conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json 404 on every Listrak host. - id: tls-1-2-minimum conforms: true evidence: >- Listrak's Security Policy states admin portal and API communications occur over TLS 1.2; probes of www.listrak.com and api.listrak.com negotiated TLS 1.3 with HSTS max-age 31536000. - id: dmarc-enforcement conforms: true evidence: listrak.com publishes SPF and DMARC with policy p=reject (security/listrak-domain-security.yml). - id: dnssec conforms: false evidence: listrak.com is not DNSSEC-signed. compliance: - id: eu-us-data-privacy-framework conforms: true evidence: Listrak states it complies with the EU-U.S. DPF, the UK Extension and the Swiss-U.S. DPF in its published Privacy Policy. source: https://www.listrak.com/privacy-and-terms/privacy-policy - id: gdpr conforms: true evidence: >- Data-subject deletion is automated through the Privacy REST API (Forget_PostForgetRequest / Forget_GetForgetRequest), which is the only Listrak API that exists purely to serve a regulatory obligation. source: https://api.listrak.com/privacy - id: ccpa-cpra conforms: true evidence: California consumer categories, sources and rights are enumerated in the Privacy Policy; deletion requests are served by the same Privacy REST API. source: https://www.listrak.com/privacy-and-terms/privacy-policy - id: soc2 conforms: unknown evidence: >- The Security Policy states security and privacy are audited annually by three separate third parties but names no framework. No SOC 2 claim appears publicly. Recorded as unknown, not false. - id: iso-27001 conforms: unknown evidence: Not claimed anywhere on the public site. - id: pci-dss conforms: unknown evidence: Not claimed; Listrak does not process card payments as part of its API surface. - id: hipaa conforms: unknown evidence: Not claimed. summary: standards_evaluated: 26 conforms: 9 partial: 1 does_not_conform: 16 compliance_programs_published: 3 cross_links: authentication: authentication/listrak-authentication.yml errors: errors/listrak-error-codes.yml security: security/listrak-trust-center.yml well_known: well-known/listrak-well-known.yml