generated: '2026-08-13' method: searched source: https://gud.resulticks.com/API-reference/ note: >- Assessed against the Resulticks public documentation portal only. Resulticks publishes no OpenAPI, AsyncAPI, or JSON Schema, so nothing could be verified mechanically against a machine-readable contract; each verdict below cites the documentation sentence it rests on. No Compliance pointer is emitted in apis.yml — Resulticks publishes no certification or compliance program page. standards: - id: rest conforms: true evidence: >- "All Resul APIs are organized around REST ... designed to have predictable, straightforward URLs and to use HTTP response codes." (/API-reference/API-management/web-API-controllers/) caveat: >- Partial in practice — success and failure both return HTTP 200 with an IsError body flag, which contradicts the stated use of HTTP response codes. - id: openapi conforms: false evidence: >- No OpenAPI or Swagger document is served. Probed /openapi.json, /openapi.yaml, /swagger.json, /swagger/v1/swagger.json, /api-docs on the docs host (all soft-404 HTML shells) and on apis.resu.io (TCP refused). - id: asyncapi conforms: false evidence: No AsyncAPI document and no documented webhook catalog. - id: graphql conforms: false evidence: No /graphql surface is documented or discoverable. - id: mcp conforms: false evidence: No MCP server is published; mcp.resulticks.com does not resolve. - id: a2a conforms: false evidence: >- No agent card at /.well-known/agent-card.json or /.well-known/agent.json on any host. See well-known/resulticks-well-known.yml. - id: oauth2 conforms: partial evidence: >- "The third-party systems utilize the OAuth protocol for authenticating REST API calls." (/API-reference/API-management/API-gateway/) No authorization endpoint, token endpoint, grant type, or scope list is published, so the claim cannot be exercised or verified. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 (or a soft-404 HTML shell) on every host. - id: rfc8414-oauth-authorization-server-metadata conforms: false evidence: /.well-known/oauth-authorization-server returns 404 or a soft-404 HTML shell on every host. - id: rfc9457-problem-details conforms: false evidence: >- Errors use a proprietary {"IsError","Message","RedirectUrl"} envelope, not application/problem+json. See errors/resulticks-problem-types.yml. - id: rfc9116-security-txt conforms: false evidence: No /.well-known/security.txt on any host. - id: rfc8594-sunset-header conforms: false evidence: No deprecation or sunset policy published. - id: idempotency conforms: false evidence: >- No idempotency key or retry-safety contract appears in the API reference. See conventions/resulticks-conventions.yml. - id: pagination conforms: partial evidence: >- Page-number pagination (page, CurrentPage, sortBy, sortDescending) is documented in list-view request bodies, but no total-count or next-page response field is published. - id: soap conforms: true evidence: >- "Both Resul and authorized third-party systems can access Resul data model and standard objects, leveraging SOAP-based web services using XML and JSON." (/API-reference/API-management/API-gateway/) - id: llmstxt conforms: false evidence: /llms.txt returns 404 on resulticks.com and a soft-404 HTML shell on the docs host. compliance_program: published: false certifications: [] evidence: >- No trust center, security page, or certification listing was found. www.resulticks.com/our-policies.html lists a Corporate Social Responsibility policy only; /security.html, /trust and /gdpr.html all return 404, and trust.resulticks.com does not resolve. No SOC 2, ISO 27001, PCI DSS, HIPAA, or FedRAMP claim appears on any public Resulticks page reached in this pass. x-evidence: - url: https://gud.resulticks.com/API-reference/API-management/API-gateway/ status: 200 - url: https://gud.resulticks.com/API-reference/API-management/web-API-controllers/ status: 200 - url: https://www.resulticks.com/our-policies.html status: 200 - url: https://www.resulticks.com/security.html status: 404 - url: https://gud.resulticks.com/openapi.json status: 200 note: soft-404 — identical 2917-byte HTML shell, not a spec