generated: '2026-08-13' method: derived source: >- openapi/_original/localytics-campaigns-audiences-openapi.yml, openapi/_original/localytics-transactional-push-openapi.json, grpc/localytics-push.proto, json-schema/localytics-events-api-v1-schema.json, https://docs.localytics.com/dev/ note: >- Cross-cutting standards conformance for the Localytics API estate, derived from the harvested contracts and confirmed against the developer documentation. Localytics publishes no compliance certifications (no SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP claim appears on the site, the Security Overview or the docs), so no Compliance pointer is emitted. standards: - id: openapi-3.0 conforms: true evidence: >- Two OpenAPI 3.0.3 documents — Campaigns And Audience API (info.version 1.1.2, harvested) and Transactional Push API (info.version 2.0.0, served live at https://messaging.localytics.com/swagger.json). - id: swagger-ui conforms: true evidence: Interactive Swagger UI published at https://messaging.localytics.com/docs - id: protobuf-proto3 conforms: true evidence: >- push.proto declares syntax "proto3", package push, and imports google/protobuf/struct.proto. Published MIT-licensed at github.com/localytics/push-notification-protos. - id: grpc conforms: true evidence: >- service PushService { rpc StreamPush(stream PushStreamMessage) returns (stream PushStreamResponse); } — bidirectional streaming, with a documented gRPC status-code contract (UNAUTHENTICATED 16, PERMISSION_DENIED 7, RESOURCE_EXHAUSTED 8, FAILED_PRECONDITION 9, INVALID_ARGUMENT 3, DEADLINE_EXCEEDED 4). - id: json-schema-draft-04 conforms: true evidence: >- Versioned request schema published at https://localytics-files.s3.amazonaws.com/schemas/eventsApi/v1.json with $schema http://json-schema.org/schema#; docs direct developers to a draft-4 validator. - id: http-basic-auth conforms: true evidence: >- RFC 7617 HTTP Basic across every surface — securitySchemes BasicAuth in both OpenAPIs, and "authorization: Basic " carried in gRPC metadata for PushService. - id: hal-hypermedia conforms: true evidence: >- https://api.localytics.com/v1 returns application/vnd.localytics.v1+hal+json with _links and templated hrefs; error bodies carry type=Error on the same media type. - id: rest conforms: true evidence: Resource-oriented CRUD over orgs/apps/push/campaigns/audiences/profiles/exports/imports/places. - id: cors conforms: true evidence: 'Query API docs: "the Localytics API enables Cross-origin Resource Sharing", with a warning not to expose credentials client-side.' - id: content-negotiation conforms: true evidence: 'Query API returns 406 Not Acceptable when the Accept request header names an unsupported format.' - id: oauth2 conforms: false evidence: No oauth2 securityScheme declared and no OAuth flow documented on any surface; API key/secret only. - id: openid-connect conforms: false evidence: /.well-known/openid-configuration returns 404 on every host. - id: rfc9457-problem-details conforms: false evidence: No application/problem+json on any surface; errors are HTTP status plus an ad-hoc JSON message body. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on all six Localytics hosts. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header support and no deprecation policy published. - id: rfc8615-well-known conforms: false evidence: No /.well-known/ document is served on any host (see well-known/localytics-well-known.yml). - id: asyncapi conforms: false evidence: >- No AsyncAPI document and no webhook/callback surface is documented. Localytics' event surface is the gRPC bidirectional stream and S3 raw-log delivery, neither of which it describes in AsyncAPI. - id: a2a-agent-card conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json return 404 on all hosts. - id: mcp conforms: false evidence: No MCP server published; see mcp/localytics-mcp.yml (deployment.mode = none). - id: idempotency conforms: true evidence: >- request_id de-duplication on the Push API (24-hour window, app_id + customer_id level) and on the gRPC stream (StreamInit.request_id); uuid-based event de-duplication in the Events API JSON Schema. See conventions/localytics-conventions.yml. compliance_program: certifications_published: [] note: >- The Security Overview (2026-04-29) describes a risk-management program, annual risk assessments, penetration testing, patch SLAs and a Data Processing Addendum incorporated by reference, but names no third-party certification or audit report. There is no trust centre at trust.localytics.com (DNS does not resolve). security_overview: https://www.localytics.com/security