generated: '2026-08-17' method: derived source: >- Derived from openapi/lokki-external-api-openapi.json and openapi/lokki-dashboard-api-openapi.json (securitySchemes, parameters, response envelopes), a2a/lokki-agent-card.json, mcp/lokki-mcp-tools.json, security/lokki-domain-security.yml and well-known/lokki-well-known.yml, cross-checked against the published documentation (docs.getlokki.com) and the legal pages at solutions.lokki.rent/legals/*. description: >- Which cross-cutting industry standards the Lokki surface actually conforms to. Every entry carries evidence; a false conformance with evidence is as useful as a true one. standards: - id: openapi-3.1 conforms: true evidence: >- The published partner spec at https://docs.getlokki.com/api-reference/openapi.json declares openapi 3.1.0, 7 paths, 94 component schemas, and parses cleanly. - id: openapi-3.0 conforms: true evidence: >- The internal Swagger document at https://prod.api.eu-west-3.lokki.rent/v2/api-json declares openapi 3.0.0 with 834 paths / 896 operations / 1,567 schemas and parses cleanly. - id: api-key-header-auth conforms: true evidence: >- securitySchemes declares an apiKey in a request header on both specs; the docs specify x-api-key for the partner surface. - id: oauth2 conforms: false evidence: >- No oauth2 securityScheme in either published spec; no /.well-known/oauth-authorization-server on any host (all 404); no OAuth flow documented. Key issuance is a manual partnership step. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on all six probed hosts. - id: rfc9728-oauth-protected-resource conforms: false evidence: /.well-known/oauth-protected-resource returns 404 on the docs host and both API hosts; the MCP server is unauthenticated. - id: mcp conforms: true evidence: >- A remote MCP server at https://docs.getlokki.com/mcp answered tools/list anonymously with HTTP 200 (streamable HTTP, text/event-stream) and returned 3 tools with valid draft-07 inputSchemas. Scope is documentation only — see mcp/lokki-tool-crosswalk.yml. - id: a2a conforms: true grade: conformant evidence: >- /.well-known/agent-card.json on docs.getlokki.com returns a valid AgentCard (capabilities object, protocolVersion 0.3, skills array). Deviations recorded in a2a/lokki-a2a.yml. - id: agent-skills conforms: true evidence: >- Lokki publishes an Agent Skill with valid frontmatter (name, description, metadata) at /.well-known/agent-skills/lokki/skill.md, saved verbatim to skills/lokki-provider-skill.md. - id: llms-txt conforms: true evidence: https://docs.getlokki.com/llms.txt returns 200 text/plain and follows the llms.txt convention, including an "OpenAPI Specs" section that links the spec. - id: rfc9457-problem-details conforms: false evidence: >- Errors use the NestJS envelope {"statusCode","message","error"} with content-type application/json, not application/problem+json. Observed live on a 403 from /v2/external/verticales. - id: pagination conforms: true style: offset evidence: skip / limit / sort query parameters with a {total, docs} response envelope on all list operations. - id: idempotency conforms: false evidence: >- No Idempotency-Key header, no idempotency documentation, zero occurrences of "idempoten" in either published spec. (The partner surface is read-only, so the absence has no practical effect there.) - id: rfc8594-sunset-deprecation-headers conforms: false evidence: >- Deprecation is published as a prose migration guide with a field mapping table and marked deprecated:true on 21 spec properties, but no Deprecation or Sunset response header is emitted and no removal date is stated. - id: webhooks conforms: false evidence: >- No outbound webhook surface for consumers. The only hook in either spec is an INBOUND receiver, POST /v2/webhook/hyperline (Lokki's own billing provider calling Lokki). - id: asyncapi conforms: false evidence: No AsyncAPI document, no event catalog, no streaming or subscription surface on any host. - id: graphql conforms: false evidence: No /graphql endpoint on any Lokki host; no mention in docs or either spec. - id: json-schema-2020-12 conforms: true evidence: The 3.1.0 partner spec's component schemas are JSON Schema 2020-12 by virtue of the OpenAPI 3.1 dialect. - id: gdpr conforms: true evidence: >- Published privacy policy at solutions.lokki.rent/legals/politique-de-confidentialite naming Lokki as data controller under GDPR, a data-protection contact at dpo@getlokki.com, and the CNIL as the supervisory authority. Legal notice names AWS EMEA (Luxembourg) as host. note: A regulatory obligation for an EU SaaS, not a certification. - id: soc2 conforms: false evidence: No SOC 2 claim anywhere on lokki.rent, getlokki.com or docs.getlokki.com; no trust center. - id: iso-27001 conforms: false evidence: No ISO 27001 claim on any public page. - id: pci-dss conforms: false evidence: >- Lokki takes online payments for its merchants (Stripe Connect appears throughout the internal spec) but publishes no PCI DSS statement, attestation or compliance page. - id: security-txt-rfc9116 conforms: false evidence: /.well-known/security.txt returns 404 on every probed host; no vulnerability disclosure policy or bug bounty found. - id: dnssec conforms: false evidence: security/lokki-domain-security.yml — DNSSEC not enabled on lokki.rent or getlokki.com. - id: dmarc conforms: true evidence: >- DMARC published on both domains: lokki.rent p=none, getlokki.com p=quarantine. SPF present on getlokki.com, absent on lokki.rent. - id: hsts conforms: partial evidence: >- HSTS present on solutions.lokki.rent (max-age 31536000) and docs.getlokki.com (max-age 63072000); absent on www.lokki.rent. - id: fhir conforms: false - id: fapi conforms: false - id: scim conforms: false - id: odata conforms: false - id: psd2 conforms: false