generated: '2026-08-14' method: searched source: >- openapi/_original/quotapath-openapi-original.json, https://trust.quotapath.com/ (SOC 2 / ISO 27001, captured 2026-07-20), and live probes of https://api.quotapath.com/v1/user/ (2026-08-14) standards: - id: openapi-3.0 conforms: true evidence: openapi 3.0.0 definition published at api.quotapath.com/docs/ (18 operations, 13 component schemas) - id: api-key-auth conforms: true evidence: >- securityScheme token_auth (apiKey, Authorization header, 'Token '); confirmed live by the WWW-Authenticate header value "Token" on a 401 - id: oauth2 conforms: false evidence: no oauth2 securityScheme in the spec; /.well-known/oauth-authorization-server returned 404 on every host - id: oidc conforms: false evidence: /.well-known/openid-configuration returned 404 on api.quotapath.com - id: rfc9457-problem-details conforms: false evidence: >- errors return application/json with a bare `detail` string, not application/problem+json; no error responses are declared in the spec - id: pagination-limit-offset conforms: true evidence: list endpoints use limit/offset with a count/next/previous/results envelope (DRF LimitOffsetPagination) - id: idempotency conforms: false evidence: no Idempotency-Key header or parameter documented; bulk endpoints de-duplicate on external integration_id only - id: rfc6585-rate-limiting conforms: false evidence: no RateLimit-*/X-RateLimit-*/Retry-After headers observed on live responses; no published quota - id: rfc8594-sunset conforms: false evidence: no Sunset or Deprecation header and no published deprecation policy - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returned 404 on api.quotapath.com, www.quotapath.com and quotapath.com - id: hsts conforms: true evidence: 'api.quotapath.com returns Strict-Transport-Security: max-age=31536000; includeSubDomains' - id: llms-txt conforms: true evidence: help.quotapath.com/llms.txt returns HTTP 200 text/plain (36,548 bytes), saved verbatim to llms/quotapath-llms.txt - id: a2a-agent-card conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json returned 404 on api., www. and app.quotapath.com - id: mcp conforms: false evidence: no hosted or packaged MCP server found; api.quotapath.com/mcp and mcp.quotapath.com return the SPA HTML shell, not a JSON-RPC endpoint - id: soc2 conforms: true evidence: SOC 2 certification published at trust.quotapath.com (captured 2026-07-20; the host now sits behind a Cloudflare bot challenge and returned 403 on 2026-08-14) - id: iso27001 conforms: true evidence: ISO 27001 certification published at trust.quotapath.com (captured 2026-07-20; 403 to automated re-probe on 2026-08-14) - id: asc-606 conforms: true evidence: ASC 606 revenue-recognition ledger support is a published product capability on both the Growth and Premium tiers (quotapath.com/pricing)