generated: '2026-07-20' method: derived source: >- openapi/maintainx-openapi-original.json + https://www.getmaintainx.com/security + https://trust.getmaintainx.com description: >- Standards conformance for the MaintainX REST API v1, derived from the OpenAPI and the provider's published security posture. standards: - id: oauth2 conforms: false evidence: Auth is HTTP Bearer (JWT API key), not oauth2. - id: openid-connect conforms: false - id: http-bearer-auth conforms: true evidence: securityScheme type http, scheme bearer, bearerFormat JWT - id: rfc9457-problem-details conforms: false evidence: Errors use a custom { error } / { errors } envelope, not application/problem+json. - id: cursor-pagination conforms: true evidence: List endpoints expose cursor + limit parameters. - id: rate-limit-headers conforms: true evidence: X-Rate-Limit-Limit / -Remaining / -Reset returned on every response; 429 on exhaustion. - id: webhooks conforms: true evidence: 46 event types via /subscriptions with HMAC signing secret. - id: soc2-type-ii conforms: true evidence: SOC 2 Type II attested (getmaintainx.com/security). - id: iso-27001 conforms: true evidence: ISO 27001:2022 certified by Insight Assurance (platform + Montreal office). - id: gdpr conforms: true evidence: GDPR-ready per published security page. compliance_programs: - SOC 2 Type II - ISO/IEC 27001:2022 - GDPR compliance_page: https://www.getmaintainx.com/security