generated: '2026-08-04' method: searched source: >- https://passportglobal.com/security-measures/, https://passportglobal.com/gdpr/, https://passportglobal.com/privacy-policy/, openapi/passport-public-api-openapi.yml, live probes of api.passportshipping.com summary: >- Passport publishes a written security-measures statement and a GDPR page describing its data-protection posture, and it operates on AWS. It does NOT claim any independently audited certification — no SOC 2, ISO 27001, PCI DSS, HIPAA, or FedRAMP attestation appears on its public surface, and it has no trust center. On the API side it conforms to OpenAPI 3.0.1 and HTTPS-only transport, and to nothing else: no OAuth 2.0/OIDC, no RFC 9457, no RFC 8594, no RFC 9116, no standard pagination or idempotency contract. standards: - id: openapi-3.0 name: OpenAPI Specification 3.0.1 conforms: true evidence: >- https://docs.passportglobal.com/passport_public_api_v3_15.yml declares `openapi: 3.0.1` and parses cleanly; 11 operations across 8 tags with request/response schemas and error examples. - id: json name: JSON request/response media type conforms: true evidence: 'Docs preamble: "The API uses JSON formatting for requests and responses."' - id: https-only name: TLS-only transport conforms: true evidence: >- Docs preamble: "All methods must be called using HTTPS." Live probe of api.passportshipping.com returns TLSv1.3 with strict-transport-security max-age=86400; includeSubDomains; preload (2026-08-04). - id: iso-4217 name: ISO 4217 currency codes conforms: true evidence: Currency fields across Rate, Ship, Cart, ProductPrice and TaxAndDuty schemas are documented as "three-letter ISO 4217 codes". - id: hs-codes name: Harmonized System (HS) tariff classification conforms: true evidence: >- Item schemas carry HS/tariff classification for customs; https://passportglobal.com/product-release/ describes AI-powered HS code classification for customs documentation. - id: gdpr name: EU General Data Protection Regulation conforms: claimed evidence: https://passportglobal.com/gdpr/ (200) and https://passportglobal.com/privacy-policy/ (200) — self-declared program; no external attestation published. - id: eu-epr name: EU Extended Producer Responsibility / deforestation reporting conforms: claimed evidence: https://passportglobal.com/product-release/ — "EU EPR and deforestation reporting support" listed as a 2026 capability. - id: oauth2 name: OAuth 2.0 conforms: false evidence: No securitySchemes in the spec; auth is a static X-Access-Token header key. /.well-known/oauth-authorization-server 404 on every host probed. - id: oidc name: OpenID Connect conforms: false evidence: /.well-known/openid-configuration 404 on passportglobal.com, api.passportshipping.com, api-stg.passportshipping.com, docs.passportglobal.com (2026-08-04). - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: Errors are a flat application/json envelope { message, details?, code? }; no application/problem+json anywhere in the spec. - id: rfc8594 name: RFC 8594 Sunset HTTP header conforms: false evidence: No Sunset or Deprecation headers, and no deprecation policy published. - id: rfc9116 name: RFC 9116 security.txt conforms: false evidence: /.well-known/security.txt returned 404 on all four Passport hosts probed (2026-08-04). - id: rfc8615-api-catalog name: RFC 9727 /.well-known/api-catalog conforms: false evidence: /.well-known/api-catalog 404 on all hosts probed (2026-08-04). - id: asyncapi name: AsyncAPI conforms: false evidence: No first-party event, streaming, or webhook surface is published; the spec declares no callbacks. - id: idempotency-key name: Idempotency-Key (draft-ietf-httpapi-idempotency-key-header) conforms: false evidence: No idempotency header or replay-safety mechanism documented, including on the label-purchasing POST /ship. certifications: soc2: not claimed iso27001: not claimed pci_dss: not claimed hipaa: not applicable / not claimed fedramp: not claimed note: >- https://passportglobal.com/security-measures/ describes AES-256 encryption at rest and in transit, MFA for administrator access, least-privilege access controls, AWS-hosted infrastructure with firewalls and network controls, background checks and personnel training, audit trails on integration key generation, logical customer-data separation, failover redundancy, and an incident-notification commitment — but the only third-party attestation it references is AWS's own SOC reports, not an audit of Passport. cross_links: security: security/passport-domain-security.yml authentication: authentication/passport-authentication.yml errors: errors/passport-problem-types.yml