generated: '2026-07-20' method: searched source: >- https://purchaser.ai/api-and-integrations and https://purchaser.ai (public marketing + API overview) name: Purchaser Standards Conformance description: >- Industry and cross-cutting standards posture for Purchaser, asserted from public statements. Each entry records whether Purchaser conforms and the public evidence. standards: - id: openapi-3.1 conforms: true evidence: >- "OpenAPI 3.1 spec with interactive explorer. Every endpoint documented with examples." (API & Integrations page) - id: idempotency conforms: true evidence: >- "Idempotency keys for safe POST retries." (API & Integrations page) - id: uri-versioning conforms: true evidence: >- "Versioned endpoints (/api/v1/) with additive-only changes." (API & Integrations page) - id: soc2-type-ii conforms: true evidence: >- "SOC 2 Type II compliant with SSO, role-based access control, and ERP integration capabilities." (product infrastructure statement) - id: sso-saml-oidc conforms: true evidence: SSO with role-based access control stated across product pages. - id: oauth2 conforms: false evidence: >- Programmatic API uses API keys, not OAuth2; no OAuth2 flows documented publicly. - id: rfc9457 conforms: unknown evidence: Error envelope format not documented on the public overview. - id: json-api conforms: unknown evidence: Response envelope not documented publicly.