generated: '2026-07-20' method: searched source: https://www.meshpay.com/security + openapi/mesh-integration-api-openapi.json standards: - id: soc2-type-ii conforms: true evidence: "Mesh is SOC 2 Type II certified; undergoes regular audits and third-party penetration testing (https://www.meshpay.com/security)" - id: apikey-auth conforms: true evidence: "OpenAPI securitySchemes define two apiKey header schemes (X-Client-Id, X-Client-Secret)" - id: webhook-hmac-signing conforms: true evidence: "Transfer-status webhooks are signed HMAC-SHA256 over the raw body, delivered in the X-Mesh-Signature-256 header" - id: oauth2 conforms: false evidence: "Mesh's own API uses API-key auth, not OAuth2 (OAuth is used internally to connect end users to underlying integrations)" - id: openid-connect conforms: false - id: rfc9457-problem-details conforms: false evidence: "Error responses are plain JSON, not application/problem+json" - id: rfc9116-security-txt conforms: false evidence: "No /.well-known/security.txt published" - id: rfc8594-sunset-header conforms: false evidence: "No documented Sunset/Deprecation header policy for the API"