generated: '2026-08-09' method: searched source: >- https://www.mirrorfly.com/chat-security.php, https://www.mirrorfly.com/hipaa-compliant-chat-api.php, https://www.mirrorfly.com/docs/platformapi/ — read 2026-08-09 note: >- MirrorFly publishes no OpenAPI, so the technical standards below are asserted from the published human reference, not from a spec. The compliance regimes are marketing-page claims on MirrorFly's own security pages — MirrorFly does not operate a trust center and publishes no attestation reports, audit letters or certificate artifacts, so the claims are recorded as claimed, not verified. standards: - id: openapi conforms: false evidence: >- No OpenAPI/Swagger document served on the API host, docs host or console host (probed /openapi.json, /openapi.yaml, /swagger.json, /v3/api-docs, /v2/api-docs, /api-docs, /swagger-ui.html — all 404 on api-preprod-sandbox.mirrorfly.com). - id: asyncapi conforms: false evidence: No event/webhook surface and no AsyncAPI document published. - id: graphql conforms: false evidence: No /graphql endpoint documented or discovered. - id: oauth2 conforms: false evidence: >- Authentication is a username/password login that mints a 1-hour opaque token in the Authorization header. No OAuth 2.0 authorization server, no scopes. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on the API host. - id: rfc9457-problem-details conforms: false evidence: >- Errors use a custom '{status, message}' envelope; no application/problem+json. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt 404 on the API host, soft-404 HTML on the web host. - id: rfc8594-sunset-header conforms: false evidence: No deprecation policy or Sunset/Deprecation header support documented. - id: pagination conforms: true evidence: >- Page-number pagination documented with page/size request params (defaults 1/50) and totalPages/totalRecords response fields. - id: idempotency conforms: false evidence: No idempotency key, de-duplication or retry-safety contract documented. - id: rate-limit-headers conforms: false evidence: No rate-limit policy or response headers published. - id: json-api conforms: false evidence: Custom response envelope, not JSON:API. compliance_claims: verified: false source_pages: - https://www.mirrorfly.com/chat-security.php - https://www.mirrorfly.com/hipaa-compliant-chat-api.php claims: - {regime: HIPAA, status: claimed, quote: 'When it comes to sensitive health info, MirrorFly strictly operates by the HIPAA standards.'} - {regime: GDPR, status: claimed, quote: 'With secure messaging APIs and SDKs carefully built to adhere the EU''s privacy regulations.'} - {regime: SOC 2 Type 2, status: claimed, quote: 'regulatory environments including HIPAA, GDPR, SOC2 Type 2, and CCPA'} - {regime: CCPA, status: claimed} - {regime: OWASP, status: claimed, note: 'Cited as a secure-development standard, not a certification.'} gaps: - >- No trust center: trust.mirrorfly.com and security.mirrorfly.com do not resolve, and /trust and /compliance return the 381,212-byte soft-404 HTML page the web host serves for every unknown path. - No downloadable SOC 2 report, ISO 27001 certificate, or subprocessor list found. - No published penetration-test summary or vulnerability-disclosure policy.