generated: '2026-08-13' method: searched source: https://www.lucidya.com/security-practices name: Lucidya Conformance & Compliance type: Conformance summary: >- Cross-cutting standards conformance, re-derived on 2026-08-13 against the five OpenAPI documents harvested from Lucidya's public Stoplight workspace. The 2026-07-20 assertion that Lucidya conforms to OAuth 2.0 was wrong and is corrected here. standards: - id: openapi conforms: true evidence: >- Five machine-readable OpenAPI documents published by Lucidya's own Stoplight workspace (docs.lucidya.com / workspace slug "lucdya"), covering 73 operations. Versions declared: 3.1.0 (AI), 3.0.3 (OmniServe), 3.0.1 (Social Listening), 3.0.0 (CDP, OmniChannel). Saved verbatim in openapi/_original/. - id: rest conforms: true evidence: >- "The Lucidya API employs a RESTful architecture, offering a straightforward interface with structured responses in JSON format." (Security Considerations article.) - id: oauth2 conforms: false evidence: >- CORRECTED 2026-08-13. Lucidya publishes no OAuth 2.0 authorization server, token endpoint, grant type or scope. Authentication is a single opaque API token in the custom `luc-authorization` header, declared as an apiKey securityScheme in the OmniServe spec and documented in prose on every other product. /.well-known/oauth-authorization-server returns 404 on all five hosts. The prior "conforms: true" was inferred from the word "Authorization" in the docs navigation and did not survive contact with the actual pages. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on every Lucidya host. - id: rfc9457 conforms: false evidence: >- Errors are returned as application/json with a custom envelope ({"error":{"status","detail"}}), not application/problem+json. Three different error shapes are in production across the five products. - id: rfc9116 conforms: false evidence: >- No security.txt is served at /.well-known/security.txt on any host, despite a real vulnerability disclosure programme existing as a web page. - id: rfc8594 conforms: false evidence: >- No Deprecation or Sunset headers, and no deprecation policy, are published. - id: rfc9727 conforms: false evidence: /.well-known/api-catalog returns 404 on every host. - id: pagination conforms: true evidence: >- A documented, cross-product page-number scheme — `page_id` query parameter, `page_number` + `count` in the response, fixed 10-item batches — published on the Social Listening, CDP and OmniChannel products. - id: idempotency conforms: false evidence: >- No idempotency key or replay-safe retry convention is documented, and none of the 73 operations declares one — including the fourteen POST job-creation operations where duplicate submission is costly. - id: rate-limiting conforms: partial evidence: >- Limits are published in prose per product (100 req/min baseline; 6 req/min for the AI API) and 429 is declared on 27 operations, but no RateLimit-*, X-RateLimit-* or Retry-After response header is published or declared. - id: webhooks conforms: true evidence: >- A documented outbound webhook surface with a published failure policy (a destination silent for 15 days is paused). - id: asyncapi conforms: false evidence: >- No AsyncAPI document is published for the webhook/alert surface. - id: tls conforms: true evidence: >- "API requests must use HTTPS, HTTP requests will not be allowed." TLS 1.3 observed live on lucidya.com; HSTS present with max-age 31536000. - id: soc2-type2 conforms: true evidence: >- "Lucidya has completed a SOC 2 Type 2 examination ... for the CXM platform." (security-practices). Full report available via Trust Center under NDA. - id: iso-27001 conforms: true evidence: >- "... achieved ISO 27001 certification for the CXM platform." (security-practices). - id: gdpr conforms: true evidence: Compliance with the EU General Data Protection Regulation (security-practices). - id: pdpl conforms: true evidence: >- Compliance with the Saudi Arabia Personal Data Protection Law (security-practices). Lucidya is headquartered in Saudi Arabia and the CDP API is the personal-data surface this regime governs. notes: >- Compliance claims are sourced from the public security-practices page; the underlying audit reports are gated behind a Trust Center NDA and were not read. The technical conformance entries are all first-hand: each was checked against the harvested specs or a live probe recorded in well-known/ and security/lucidya-ltd-domain-security.yml.