generated: '2026-08-13' method: derived source: openapi/persistiq-api-v1-openapi.json standards: - id: openapi-3.0 conforms: true evidence: >- PersistIQ publishes its own OpenAPI 3.0.1 document at https://api.persistiq.com/api-docs/v1/swagger.json (fetched 2026-08-13), served behind a Swagger UI at https://api.persistiq.com/api-docs. - id: openapi-operationids conforms: false evidence: >- None of the 21 operations in the published document declares an operationId, so generated clients and agent tools cannot get stable names from it. - id: webhooks conforms: true evidence: >- Five configurable webhook events exposed through GET/PUT /v1/webhook_plugin; catalogued in asyncapi/persistiq-webhooks.yml. - id: asyncapi conforms: false evidence: >- No AsyncAPI document is published, and no payload schemas are published for the webhook deliveries. - id: rfc8594-sunset conforms: false evidence: No Sunset/Deprecation header support and no deprecation policy. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on both hosts (2026-08-13). - id: a2a-agent-card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json both 404 on api.persistiq.com and persistiq.com (2026-08-13). - id: oauth2 conforms: false evidence: API uses a company-wide API key (x-api-key header), not OAuth 2.0. - id: oidc conforms: false - id: apikey-auth conforms: true evidence: openapi securityScheme type apiKey in header x-api-key - id: rfc9457-problem-details conforms: false evidence: errors use a custom JSON envelope, not application/problem+json - id: cursor-pagination conforms: false evidence: >- Corrected 2026-08-13. Pagination is a `page` integer query parameter, not an opaque cursor; the has_more + next_page envelope wraps page-number paging. See conventions/persistiq-conventions.yml. - id: page-number-pagination conforms: true evidence: >- `page` (integer) query parameter on every list operation in the official OpenAPI, plus has_more/next_page in the response envelope. - id: rate-limit-headers conforms: true evidence: X-RateLimit-Limit / X-RateLimit-Remaining / X-RateLimit-Reset returned - id: idempotency conforms: false evidence: no idempotency-key mechanism documented - id: json-api conforms: false - id: fhir-r4 conforms: false - id: scim conforms: false - id: odata conforms: false compliance_program: published: false certifications: [] trust_center: null vulnerability_disclosure: null method: probed checked: '2026-08-13' evidence: - {url: 'https://persistiq.com/.well-known/security.txt', status: 404} - {url: 'https://api.persistiq.com/.well-known/security.txt', status: 404} - probe: '0-working/probe-security-programs.py persistiq' result: 'vdp=none trust=none' notes: >- No trust centre, no security page, no bug-bounty programme and no named certification. The only compliance-adjacent public document is a GDPR overview article in the help centre (2018). No `Compliance`, `Security` or `TrustCenter` pointer is emitted. notes: >- Derived from the OpenAPI and published reference. No formal compliance certifications (SOC 2, ISO 27001, PCI DSS, HIPAA, etc.) were found published on the public developer surface, so no Compliance pointer is asserted. Re-derived 2026-08-13 against PersistIQ's own OpenAPI 3.0.1 document, which replaced the previously derived spec as the evidence base.