generated: '2026-07-20' method: searched source: https://www.qminder.com/security/ standards: - id: soc2-type2 conforms: true evidence: SOC 2 Type II audit report (AICPA) per the security page. - id: hipaa conforms: true evidence: PHI processing supported under Qminder's Business Associate Agreement. - id: tx-ramp-level-2 conforms: true evidence: TX-RAMP Level 2 certification per the security page. - id: gdpr conforms: true evidence: Privacy program aligned with GDPR and other international regulations. - id: oauth2 conforms: false evidence: REST API uses an apiKey header (X-Qminder-REST-API-Key), not OAuth2. - id: rfc9457-problem-details conforms: false evidence: Errors use a bespoke statusCode/message/developerMessage envelope, not application/problem+json. - id: iso-27001 conforms: false evidence: Not claimed on the security page. - id: pci-dss conforms: false evidence: Not claimed on the security page.