generated: '2026-08-04' method: derived source: >- openapi/malwarebytes-threatdown-nebula-openapi.json, openapi/malwarebytes-threatdown-oneview-openapi.json, https://www.threatdown.com/legal/trust-and-compliance/ summary: >- ThreatDown conforms to OpenAPI 3.0.0 and OAuth 2.0 client credentials, and the company holds SOC 2 Type II, ISO/IEC 27001 and PCI DSS attestations. It does NOT implement the HTTP API interoperability standards an agent or a generic client would look for: no RFC 9457 problem+JSON errors, no OpenID Connect, no RFC 8414 discovery, no standard rate-limit headers, no RFC 8594 Sunset, no idempotency keys, no conditional requests. conformance: - id: openapi name: OpenAPI Specification version: 3.0.0 conforms: true evidence: >- Both definitions declare openapi 3.0.0 and parse cleanly — 344 paths / 440 operations (Nebula) and 315 paths / 401 operations (OneView), every operation carrying a unique operationId, summary and description. source: openapi/malwarebytes-threatdown-nebula-openapi.json - id: oauth2 name: OAuth 2.0 (RFC 6749) client credentials grant conforms: true evidence: >- securitySchemes declares `client_credentials` as type oauth2 with a clientCredentials flow and three scopes (read, write, execute). Token endpoints are POST /oauth2/token (Nebula) and POST /oneview/oauth2/token (OneView), returning access_token, token_type, expires_in and scope. source: openapi/malwarebytes-threatdown-nebula-openapi.json - id: oauth2-bearer name: OAuth 2.0 Bearer Token Usage (RFC 6750) conforms: partial evidence: >- A bearer token is used, but the `authorization` header is declared as an ordinary required STRING parameter on 439 of 440 Nebula operations rather than being carried only by the securityScheme. Tooling that honours security requirements will emit the header twice. - id: oidc name: OpenID Connect conforms: false evidence: >- No openIdConnect securityScheme and no /.well-known/openid-configuration on any host. The token response schema lists an optional `id_token` field "with grant type authorization code", but no authorization-code flow is declared or documented for the public API. - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: false evidence: /.well-known/oauth-authorization-server is absent on every host (see well-known/). - id: rfc9457 name: Problem Details for HTTP APIs (RFC 9457) conforms: false evidence: >- Neither definition declares a single 4xx or 5xx response on any of its 841 operations, and no application/problem+json media type appears anywhere. The error envelope observed live on api.threatdown.com is a bespoke {message, error, statusCode} object. - id: rfc9116 name: security.txt conforms: true evidence: >- Valid security.txt served from www.malwarebytes.com and cloud.malwarebytes.com with Contact, Expires, Preferred-Languages, Policy and Hiring fields. Expires is set ~11 years out, against the RFC's under-one-year recommendation. source: well-known/malwarebytes-security.txt - id: rfc8594 name: Sunset HTTP Header conforms: false evidence: >- Six OneView operations are flagged `deprecated: true` in the spec, but no Sunset or Deprecation header and no removal date is published. - id: rate-limit-headers name: RateLimit header fields for HTTP conforms: false evidence: >- A 360 req/min leaky-bucket quota is documented in prose with a 429 on exhaustion, but no RateLimit-* or Retry-After headers are documented or declared. - id: idempotency name: Idempotency-Key HTTP header conforms: false evidence: >- No idempotency key header is defined on any operation. Job issuance (POST /nebula/v1/jobs, POST /nebula/v1/jobs/bulk) is not safely retryable. The only idempotency guidance in the docs is advice for the CONSUMER to make its own webhook handler idempotent. - id: pagination name: Cursor pagination conforms: true style: opaque cursor evidence: >- `next_cursor` (request parameter and required response field) with `page_size`, consistently applied across the search/list surface. A legacy `per_page` parameter survives on a small number of OneView operations. - id: webhooks-hmac name: HMAC-signed webhook delivery conforms: true evidence: >- Events are signed with HMAC_SHA256(secret_token, payload) and delivered in the X-MWB-Signature header, with exponential-backoff retry (default max 5 attempts). source: asyncapi/malwarebytes-threatdown-webhooks.yml - id: asyncapi name: AsyncAPI conforms: false evidence: >- A real event surface exists (18 webhook event types) but is documented only in prose inside the OpenAPI tag description. No AsyncAPI document is published. - id: cors name: CORS (W3C Cross-Origin Resource Sharing) conforms: true evidence: >- "This API features Cross-Origin Resource Sharing (CORS) implemented in compliance with W3C spec. ... All responses have a wildcard same-origin." caution: >- A wildcard origin on a security-management API that issues endpoint isolation and reboot jobs is a notable posture choice, self-described as making responses "completely public and accessible to everyone, including any code on any site." - id: scim name: SCIM conforms: false evidence: >- User provisioning exists (OneView Users operations) but on a bespoke resource model, not SCIM 2.0. - id: soc2 name: SOC 2 Type II conforms: true scope: organizational evidence: Audited by Schellman & Company against Security, Availability and Confidentiality TSC. source: security/malwarebytes-trust-center.yml - id: iso27001 name: ISO/IEC 27001 conforms: true scope: organizational evidence: Independently audited by Schellman Compliance. source: security/malwarebytes-trust-center.yml - id: pci-dss name: PCI DSS conforms: true scope: organizational evidence: Attestation of Compliance produced with a Qualified Security Assessor. source: security/malwarebytes-trust-center.yml - id: nist-csf name: NIST Cybersecurity Framework conforms: partial scope: organizational evidence: Stated as the foundation of the security program; a framework alignment, not a certification. - id: fhir name: HL7 FHIR conforms: false evidence: not applicable — endpoint security, not healthcare - id: psd2 name: PSD2 / Open Banking conforms: false evidence: not applicable - id: odata name: OData conforms: false - id: jsonapi name: JSON:API conforms: false evidence: bespoke JSON envelopes; no JSON:API media type or document structure