generated: '2026-08-13' method: searched source: >- openapi/_original/navistone-openapi-original.json (derived) plus the published https://www.navistone.com/privacy-policy and https://info.navistone.com/consumer-privacy pages (searched 2026-08-13). summary: >- Technical conformance is derived from the OpenAPI; the sector conformance rows are self-asserted claims quoted from NaviStone's own privacy policy. NaviStone publishes NO audited certification (no SOC 2, ISO 27001, HIPAA or FedRAMP), no trust center and no compliance page — trust.navistone.com and security.navistone.com do not resolve and /security, /trust and /compliance all return 404 — so no `Compliance` pointer is emitted. standards: - id: rest-crud conforms: true evidence: resource-oriented paths with GET/POST/PATCH/DELETE CRUD semantics - id: apikey-auth conforms: true evidence: securityScheme type apiKey in header (X-API-Key), applied to 33 of 36 operations - id: offset-pagination conforms: true evidence: page/limit query params on the clients list endpoint - id: health-check conforms: true evidence: /api/health, /api/health/live, /api/health/ready liveness/readiness probes - id: oauth2 conforms: false - id: oidc conforms: false - id: rfc9457-problem-details conforms: false evidence: error responses do not advertise application/problem+json - id: idempotency conforms: false evidence: no Idempotency-Key header or idempotent-retry contract in the spec or docs - id: json-api conforms: false - id: rfc8594-sunset conforms: false evidence: no Sunset/Deprecation header support and no deprecation policy published - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on every NaviStone host - id: pci-dss conforms: claimed self_asserted: true evidence: >- privacy policy: "Our Site is in compliance with Payment Card Industry vulnerability standards in order to create as secure an environment as possible for all Users." note: >- A boilerplate statement about the marketing website, not an attested certification and not a claim about the platform API. Not treated as published compliance. source: https://www.navistone.com/privacy-policy - id: dma-privacy-standards conforms: claimed self_asserted: true evidence: 'privacy policy: vendors whose "policies meet the Direct Marketing Association''s privacy standards"' source: https://www.navistone.com/privacy-policy - id: nai-opt-out conforms: true evidence: privacy policy directs consumers to http://www.networkadvertising.org/choices/ (Network Advertising Initiative) source: https://www.navistone.com/privacy-policy - id: daa-choices conforms: true evidence: privacy policy directs consumers to https://www.aboutads.info/choices/ (Digital Advertising Alliance) source: https://www.navistone.com/privacy-policy certifications: [] evidence: - {url: 'https://www.navistone.com/privacy-policy', status: 200} - {url: 'https://info.navistone.com/consumer-privacy', status: 200} - {url: 'https://www.navistone.com/compliance', status: 404} - {url: 'https://www.navistone.com/security', status: 404} - {url: 'https://www.navistone.com/trust', status: 404} - {url: 'https://trust.navistone.com/', status: null, note: DNS does not resolve}