generated: '2026-07-26' method: searched source: - collections/re-max-eu-datahub-api.postman_collection.json - collections/re-max-eu-listings-api.postman_collection.json - live anonymous probes, 2026-07-26 - review.yml (RESO membership and certification directory evidence) note: >- Conformance is asserted only where evidence exists in a harvested artifact or a recorded probe. RE/MAX is a RESO Class D member with a seat on the RESO board and ships nothing RESO-shaped, which is the single most important line in this file. standards: - id: oauth2 conforms: true evidence: >- Both RE/MAX Europe collections declare auth type oauth2 with authorization and token endpoints; the production Datahub host enforces it (400 code 4007 without a token, 403 code 4004 with an invalid token). - id: rfc6750-bearer-token-usage conforms: false evidence: >- Tokens are passed as an access_token query parameter on every request rather than in an Authorization header. RFC 6750 permits the URI query form but marks it as NOT RECOMMENDED. - id: oidc-discovery conforms: false evidence: >- https://oauth.datahub.remax.eu/.well-known/openid-configuration returned 404 (2026-07-26). - id: rfc8414-authorization-server-metadata conforms: false evidence: >- https://oauth.datahub.remax.eu/.well-known/oauth-authorization-server returned 404 (2026-07-26). - id: openapi conforms: false evidence: >- No OpenAPI, Swagger, GraphQL or OData document exists anywhere in the estate; every candidate path on both API hosts and both docs hosts returned 404, 400 or an nginx 403 (probe log in review.yml and re-probed 2026-07-26). - id: reso-web-api conforms: false evidence: >- No RESO Web API endpoint, no $metadata document, zero occurrences of "RESO", "OData" or "Data Dictionary" in either harvested collection. RE/MAX does not appear in the RESO certification directory of 576 certified data providers. - id: reso-data-dictionary conforms: false evidence: >- The listing payload uses listingId / offerType / listingType / noOfBedrooms / buildingSize / energyRating / commissionRateBuyer where the Data Dictionary would use ListingKey / StandardStatus / PropertyType / BedroomsTotal / LivingArea. Proprietary schema throughout. - id: reso-universal-property-identifier conforms: false evidence: zero occurrences of "UPI" or "Universal Property Identifier" in either collection - id: odata-v4 conforms: false evidence: no $metadata, no OData query options, no OData media types - id: rfc9457-problem-details conforms: false evidence: >- Errors use a proprietary {"status":[{"code":..,"message":..}],"result":{}} envelope with application/json, not application/problem+json. - id: rfc9116-security-txt conforms: false evidence: >- /.well-known/security.txt returned 404 on www.remax.com, www.remax.eu and oauth.datahub.remax.eu; datahub.remax.eu returned a 200 SPA HTML shell rather than an RFC 9116 document. - id: rfc8594-sunset-header conforms: false evidence: no Sunset or Deprecation header support published - id: json-api conforms: false evidence: proprietary response envelope; no application/vnd.api+json - id: pagination conforms: true evidence: >- Page-number pagination on both APIs (page/size/sort on Datahub, page/limit on Listings) - though the two APIs use different parameter names. - id: idempotency conforms: false evidence: >- No Idempotency-Key header or client-supplied request id on any write operation, including the queued Listings writes where a retry is most likely to duplicate. - id: model-context-protocol conforms: partial evidence: >- An MCP JSON-RPC endpoint exists at https://www.remax.eu/wp-json/mcp/mcp-adapter-default-server (the WordPress MCP Adapter) and the /wp-json/mcp namespace descriptor returns 200, but tools/list returns 401 rest_forbidden to an anonymous caller, so the tool surface cannot be enumerated. It is a CMS plugin surface, not an API-program MCP server. See mcp/re-max-mcp.yml. - id: llms-txt conforms: true evidence: >- https://www.remax.eu/llms.txt returns 200 (39,691 bytes, generated by Rank Math SEO). It is a marketing-site index, not a developer index - saved verbatim at llms/re-max-eu-site-llms.txt. - id: soc2 conforms: unknown evidence: no trust center or certification page found; trust.remax.com is a wildcard DNS artifact - id: iso-27001 conforms: unknown evidence: no published certification - id: gdpr conforms: claimed evidence: >- RE/MAX Europe publishes a privacy policy (https://www.remax.eu/privacy-policy/, 200) and an EU cookie policy (https://www.remax.eu/cookie-policy/, 200) with a consent management layer. This is a published privacy posture, not a certification or an audited compliance program. reso_membership: member: true class: D (Brokers, Agents and Appraisers) board_seat: true certified_data_provider: false interpretation: >- Membership and governance participation without certification or implementation. RE/MAX sits on the board of the body that governs the only industry-mandated machine-readable contract in real estate and publishes none of it.