generated: '2026-07-20' method: derived source: openapi/ + https://qwilt.com/compliance/ standards: - id: oauth2 conforms: false evidence: No oauth2 security scheme; auth is API key (X-API-KEY) or username/password bearer. - id: oidc conforms: false evidence: >- SSO login supports custom IdP integration (Feb 2025 release), but no OIDC discovery is published for the management APIs. - id: rfc9457-problem-details conforms: false evidence: No application/problem+json error envelope is published. - id: rest-json conforms: true evidence: JSON over HTTPS REST resources (sites, configurations, certificates). - id: soc2 conforms: true evidence: 'SOC 2 listed on https://qwilt.com/compliance/' - id: iso-27001 conforms: true evidence: 'ISO/IEC 27001 listed on https://qwilt.com/compliance/' - id: iso-27017 conforms: true evidence: 'ISO/IEC 27017 listed on https://qwilt.com/compliance/' - id: iso-27018 conforms: true evidence: 'ISO/IEC 27018 listed on https://qwilt.com/compliance/' compliance_program: url: https://qwilt.com/compliance/ certifications: [SOC 2, ISO 27001, ISO 27017, ISO 27018]