generated: '2026-08-13' method: searched source: >- openapi/nift-customers-api-openapi.yml + https://www.gonift.com/business/data-privacy-framework/ + https://www.gonift.com/business/vulnerability-disclosure-policy + Nift partner docs standards: - id: oauth2 conforms: true evidence: OAuth 2.0 client_credentials flow at https://www.gonift.com/oauth/token with read:customers / write:customers scopes source: https://github.com/nift-sdks/nift-flow-sdk-docs/blob/main/docs/sdk/customer-status-server.md - id: oauth2-bearer-tokens conforms: true evidence: RFC 6750 Bearer tokens; auth failures return an empty body with WWW-Authenticate (realm="Doorkeeper", error="invalid_token") carrying the error source: https://github.com/nift-sdks/nift-flow-sdk-docs/blob/main/docs/sdk/customer-deletion-api.md - id: rfc9457-problem-details conforms: false evidence: errors use the OAuth 2.0 error/error_description JSON envelope, not application/problem+json - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on www.gonift.com, gonift.com and nift.me; the VDP is an HTML page only - id: rfc8594-sunset-header conforms: false evidence: no Sunset/Deprecation headers and no published deprecation policy (see lifecycle/nift-lifecycle.yml) - id: eu-us-data-privacy-framework conforms: true certification: true evidence: >- Nift Networks, Inc. states it has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework Principles. Policy effective 2026-02-04. source: https://www.gonift.com/business/data-privacy-framework/ verification_note: >- Nift's own DPF policy points to https://www.dataprivacyframework.gov for the public certification record; the site's participant-search API endpoint returned 404 to this probe on 2026-08-13, so the certification is recorded as PROVIDER-ASSERTED and independently unverified by this pass. - id: gdpr conforms: true evidence: >- Dedicated customer deletion (anonymization) API for partner-initiated erasure requests, plus DPF/EEA-UK-Swiss transfer commitments and a documented supervisory-authority complaint route in the privacy policy. source: https://www.gonift.com/privacy/ - id: ccpa-cpra conforms: true evidence: '"Do Not Sell or Share My Personal Information" control published in the site footer' source: https://www.gonift.com/privacy/ - id: coordinated-vulnerability-disclosure conforms: true evidence: >- Published Vulnerability Disclosure Policy with scope, researcher guidelines, a security@gonift.com intake, a 5-business-day acknowledgement commitment and explicit CFAA safe harbor. source: https://www.gonift.com/business/vulnerability-disclosure-policy - id: soc2 conforms: false evidence: no SOC 2 report, attestation or trust center published; trust.gonift.com does not resolve - id: iso27001 conforms: false evidence: no ISO 27001 certification published - id: pci-dss conforms: false evidence: Nift is not a card acquirer; no PCI DSS claim published - id: fhir-r4 conforms: false - id: fapi conforms: false notes: >- Nift's published compliance posture is privacy-led, not security-certification-led: a real EU-U.S./UK/Swiss Data Privacy Framework certification claim and a real coordinated vulnerability disclosure policy, but no SOC 2, no ISO 27001 and no trust center. For a company whose product is built on processing consumer email addresses across partner platforms, the DPF certification plus the partner-facing deletion API are the load-bearing controls, and both are genuinely published.