generated: '2026-08-13' method: derived source: openapi/*.yml docs: https://api-docs.partnerize.com/brand/#section/Common-API-Conventions name: Partnerize Standards Conformance description: >- Which cross-cutting and industry standards the Partnerize API conforms to. Derived from the 104 OpenAPI documents in openapi/ and the published API conventions, and checked against the provider's own site and legal pages for compliance claims. Partnerize publishes no certifications and no trust centre, so no Compliance pointer is emitted in apis.yml — every entry below is a technical-standard assertion with its evidence, not a compliance program. standards: - id: openapi-3.0 conforms: true evidence: 'All 104 documents declare openapi: 3.0.1; both published source documents (Brands API, Partners API) are OpenAPI 3.0.1 rendered with Redoc 2.0.0-rc.47.' - id: openapi-3.1 conforms: false evidence: No 3.1 document is published. - id: rest conforms: true evidence: >- Resource-oriented URLs and standard HTTP verbs with documented semantics (GET/POST/ PUT/PATCH/DELETE, 405 on unsupported verb) across v2 and v3. - id: http-basic-rfc7617 conforms: true evidence: 'Authorization: Basic base64(application_key:user_api_key), documented in Common API Conventions → Access and Authentication.' - id: oauth2 conforms: false evidence: No oauth2 securityScheme in any spec and no OAuth documentation; no /.well-known/oauth-authorization-server (404 on every host). - id: oidc conforms: false evidence: No /.well-known/openid-configuration on any host (404). - id: rfc9457-problem-details conforms: false evidence: >- No operation declares application/problem+json. Partnerize ships a proprietary error envelope whose shape differs between v1, v2 and v3 — see errors/partnerize-problem-types.yml. - id: rfc9110-idempotent-methods conforms: true evidence: 'PUT documented as idempotent and replacing the resource; GET documented as always read-only.' - id: idempotency-key conforms: false evidence: >- No Idempotency-Key header or parameter anywhere in the specs or the documentation. Unsafe POST retries — including 100,000-item bulk conversion submissions — have no supported deduplication contract. - id: rfc8594-sunset-header conforms: false evidence: >- A three-month deprecation policy is published in prose and delivered by email, but no Sunset or Deprecation response header is emitted and no operation is flagged deprecated in the spec. - id: rate-limit-headers conforms: partial evidence: >- Partnerize returns X-RateLimit-Limit / -Remaining / -Reset / -Retry-After — the pre-standard X- prefixed family, not the IETF draft RateLimit / RateLimit-Policy fields. Thresholds themselves are not published. - id: pagination conforms: true evidence: >- Two documented styles: offset/limit with offset+limit+count, and cursor_id+limit (max 300) on the granular conversion reporting endpoint. - id: hypermedia conforms: partial evidence: >- Every paginated result set returns a hypermedia.pagination node with absolute-path first/last/next/previous links, and v3 job responses return hypermedia.links. This is link-level hypermedia, not a registered media type — not HAL, JSON:API or Siren. - id: json-api conforms: false evidence: 'Response envelopes are proprietary (execution_time/count in v1-v2, data+hypermedia in v3), not JSON:API.' - id: iso-8601 conforms: partial evidence: >- v2 endpoints are documented as ISO-8601. v1 query parameters use space-separated date-times (2018-03-01 00:00:00, URL-encoded) in the provider's own examples. - id: iso-4217-currency conforms: true evidence: 'Dedicated Currencies and Currency Countries resources; currency validation errors reference a currency-code constraint (69945ac1-2db4-405f-bec7-d2772f73df52).' - id: iso-3166-country conforms: true evidence: 'Dedicated Countries and US States resources; a country-code validation constraint is published (8f900c12-61bd-455d-9398-996cd040f7f0).' - id: iso-13616-iban conforms: true evidence: >- Payment details validation publishes IBAN constraint codes for country code, character set and checksum — an artefact of Partnerize paying partners across borders. - id: iso-9362-bic conforms: true evidence: 'Five published BIC validation constraints (length, characters, bank code, country code, uppercase).' - id: gzip-content-encoding conforms: true evidence: 'Accept-Encoding: gzip honoured, Content-Encoding: gzip returned (Version 1 API Conventions → Compression).' - id: asyncapi conforms: false evidence: >- No event, streaming or webhook surface is documented. "webhook", "postback" and "callback" appear zero times across both published specs. Not applicable rather than failed — a provider with no event surface is not penalised. - id: mcp conforms: false evidence: No Model Context Protocol server is published; see mcp/partnerize-mcp.yml. - id: a2a conforms: false evidence: 'No agent card at /.well-known/agent-card.json or /.well-known/agent.json on any host (404 on all four hosts probed).' - id: rfc9116-security-txt conforms: false evidence: '/.well-known/security.txt returns 404 on api.partnerize.com, partnerize.com, api-docs.partnerize.com and console.partnerize.com.' - id: rfc8615-well-known conforms: false evidence: 'No document served under /.well-known/ on any host — see well-known/partnerize-well-known.yml.' - id: llms-txt conforms: true evidence: 'https://partnerize.com/llms.txt returns 200 with a valid llms.txt (H1, blockquote summary, sectioned link lists); last updated 2025-10-20. Marketing-site scope only — it names no API surface.' compliance_program: published: false certifications: [] trust_center: null evidence: - {url: 'https://trust.partnerize.com', status: 403, note: 'CNAME to api.partnerize.com; no trust centre exists'} - {url: 'https://partnerize.com/security', status: 404} - {url: 'https://partnerize.com/legal/security-policy', status: 404} - {url: 'https://partnerize.com/legal/terms', status: 200, note: 'No SOC 2, ISO 27001, PCI, HIPAA, FedRAMP or GDPR compliance claim appears on the legal pages'} note: >- Partnerize handles partner payment details, bank identifiers and IBANs through this API and publishes no security certification, no trust centre, no vulnerability-disclosure policy and no security.txt. That is the most consequential gap in this profile. regulatory_context: - {regime: GDPR, applicability: 'UK/EU operator processing partner and consumer tracking data', published_position: 'Privacy Statement at https://partnerize.com/legal/privacy-policy; no DPA or GDPR page found at the conventional paths'} - {regime: 'Modern Slavery Act 2015', applicability: 'UK-incorporated group', published_position: 'https://partnerize.com/legal/modern-slavery-and-human-trafficking-statement'}