generated: '2026-08-14' method: searched source: >- https://www.reform.app/legal/security-and-compliance, https://www.reform.app/legal/dpf-statement, https://docs.reform.app/article/7-webhooks, https://docs.reform.app/article/15-using-your-own-html-form, plus live probes of every Reform host recorded in well-known/reform-well-known.yml. No OpenAPI, AsyncAPI, GraphQL SDL or JSON Schema exists in this repo to derive from — Reform publishes none. description: >- Which industry and cross-cutting standards Reform's public surface actually conforms to. Reform's compliance posture is organisational (SOC 2, ISO 27001, GDPR, DPF) and its technical conformance is close to nil, because it ships no API contract. Both facts are recorded here. standards: - id: soc2 conforms: true evidence: >- "compliant with and regularly audited against ... SOC2" (https://www.reform.app/legal/security-and-compliance). Self-asserted; no report, auditor or Type I/II designation is published. - id: iso27001 conforms: true evidence: >- Named on https://www.reform.app/legal/security-and-compliance. Self- asserted; no certificate number or certification body published. - id: gdpr conforms: true evidence: >- Named on the security and compliance page; Reform maintains an Information Security and Privacy program. - id: eu-us-data-privacy-framework conforms: true evidence: Dedicated statement at https://www.reform.app/legal/dpf-statement (HTTP 200). - id: encryption-in-transit-and-at-rest conforms: true evidence: Stated on the security and compliance page; TLS 1.3 with HSTS (max-age 31536000) observed on www.reform.app. - id: openapi conforms: false evidence: >- No OpenAPI/Swagger document at any of /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs or /redoc on www.reform.app, docs.reform.app, dashboard.reform.app, forms.reform.app or embed.reform.app (all 404). api.reform.app is NXDOMAIN. - id: asyncapi conforms: false evidence: >- Webhooks are documented in prose in a Help Scout article; no AsyncAPI document is published. See asyncapi/reform-webhooks.yml. - id: json-schema conforms: false evidence: No schema is published for the webhook payload or for form definitions. - id: graphql conforms: false evidence: /graphql returns 404 on dashboard.reform.app; no GraphQL surface is documented. - id: mcp conforms: false evidence: No MCP server, endpoint or package is published by Reform or by FunnelEnvy for Reform. - id: a2a conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json return 404 or 403 on every Reform host. - id: oauth2 conforms: false evidence: >- Reform issues no API credentials and runs no authorization server; /.well-known/oauth-authorization-server 404/403 on every host. - id: oidc conforms: false evidence: No /.well-known/openid-configuration on any host. - id: rfc9457 conforms: false evidence: >- No application/problem+json anywhere. Headless-form validation failures are handled by REDIRECTING the browser to the hosted form; event-handler errors use a bespoke {type:'error', errors:{...}} JavaScript shape. - id: rfc8594-sunset-deprecation conforms: false evidence: No deprecation policy, Sunset header or changelog is published. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt 404 on www.reform.app and docs.reform.app, 403 on the Cloudflare-fronted hosts. - id: llms-txt conforms: true evidence: >- https://www.reform.app/llms.txt returns HTTP 200 with a well-formed llms.txt (15,055 bytes) — sectioned, annotated links, an "Optional" section. Saved verbatim to llms/reform-llms.txt. - id: webhook-signature-verification conforms: true evidence: >- HMAC-SHA256 over the raw body in a `Signature` header, with a per-webhook secret and a published verification recipe (https://docs.reform.app/article/7-webhooks). Note it is a bare hex digest with no timestamp binding, so it carries no replay protection. - id: idempotency conforms: false evidence: No idempotency key or request-deduplication mechanism on any surface. - id: pagination conforms: false evidence: No listing endpoint exists. - id: wcag-accessibility conforms: partial evidence: >- Reform markets "Accessible Forms" as a product feature and writes extensively about ADA/WCAG in its blog, but publishes no VPAT, no conformance level claim, and no accessibility statement page.