generated: '2026-07-26' method: derived source: review.yml + live probes of LJ Hooker brand hosts and api01.ljx.com.au, 2026-07-26 name: LJ Hooker standards conformance posture summary: >- LJ Hooker conforms to no published API or data standard. It publishes no machine-readable contract of any kind, so every cross-cutting API standard below is asserted false on evidence rather than assumed. The single industry-specific standard that would apply to a brokerage - RESO (the Real Estate Standards Organization Web API and Data Dictionary) - is a North American, NAR-driven regime with no Australian footprint, and LJ Hooker is absent from the RESO certificates directory. No compliance programme, trust centre or certification (SOC 2, ISO 27001, PCI DSS) is published on any brand domain, so this file deliberately carries no `type: Compliance` pointer. standards: - id: reso-web-api name: RESO Web API conforms: false evidence: >- https://www.reso.org/certificates/ fetched 2026-07-26 (HTTP 200, 416,233 bytes) and full-text searched: zero occurrences of "ljhooker", "lj hooker", "hooker", "australia" or "new zealand" against 825 occurrences of "mls". LJ Hooker is genuinely absent from the certified-organization directory. applicable: false note: RESO is a North American (NAR-driven) regime; Australia has no MLS institution. - id: reso-data-dictionary name: RESO Data Dictionary conforms: false evidence: Not referenced on any LJ Hooker domain; no certification in the RESO directory. applicable: false - id: reso-upi name: RESO Universal Property Identifier conforms: false evidence: Not referenced anywhere on LJ Hooker properties. applicable: false - id: odata-v4 name: OData 4.0 conforms: false evidence: >- https://api01.ljx.com.au/$metadata returns HTTP 403 (AWS API Gateway default for an unrouted path) and https://www.ljhooker.com.au/$metadata returns HTTP 404. The vendor backend serves plain JSON over REST, not OData. - id: openapi name: OpenAPI Specification conforms: false evidence: >- No OpenAPI or Swagger document is served on any brand host or on api01.ljx.com.au (/openapi.json, /openapi.yaml, /v1/openapi.json, /swagger.json, /swagger/v1/swagger.json, /api-docs, /docs, /redoc all 403 or 404). An OpenAPI document demonstrably exists upstream - the website search client is OpenAPI-Generator output - but it is not published. - id: asyncapi name: AsyncAPI conforms: false evidence: No event, streaming or webhook surface is documented anywhere. - id: graphql name: GraphQL conforms: false evidence: https://api01.ljx.com.au/graphql returns HTTP 403 (unrouted); no GraphQL surface documented. - id: oauth2 name: OAuth 2.0 conforms: false evidence: >- The generated website client initialises with an empty authentications map and presents no credential; /.well-known/oauth-authorization-server and /.well-known/oauth-protected-resource are not served on any host. - id: oidc name: OpenID Connect Discovery conforms: false evidence: /.well-known/openid-configuration returns 404 on all five brand hosts and 403 on api01.ljx.com.au. - id: rfc9457-problem-details name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: No error contract is published; the gateway returns bare {"message":"Forbidden"} JSON. - id: rfc9116-security-txt name: RFC 9116 security.txt conforms: false evidence: /.well-known/security.txt returns 404 on all five brand hosts (see well-known/lj-hooker-well-known.yml). - id: rfc8594-sunset-header name: RFC 8594 Sunset HTTP Header conforms: false evidence: No versioning or deprecation policy is published; there is no versioned public API to deprecate. - id: llms-txt name: llms.txt conforms: false evidence: /llms.txt returns 404 on all five brand hosts; the file in llms/ is generated by API Evangelist, not published by LJ Hooker. compliance_programme: published: false trust_center: false certifications: [] evidence: >- No trust centre, compliance page or named certification (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP, CSA STAR) was located on any LJ Hooker domain by the security-programme probe on 2026-07-26. regulatory_context: - name: Australian Privacy Act 1988 / Australian Privacy Principles note: Addressed via the published privacy policy and personal information collection statement; not an API standard. - name: AML/CTF Act 2006 (Australia) note: LJ Hooker publishes an anti-money-laundering and counter-terrorism-financing statement; not an API standard.