generated: '2026-08-05' method: derived source: >- github.com/Deltakit/deltakit (client library + docs), plus live probes of the Deltakit Cloud API notes: >- No OpenAPI or vocabulary artifact exists to derive from, so every assertion below is grounded in either Riverlane's published documentation/source or an observed HTTP response. Riverlane publishes no certifications or compliance programme (no trust centre, no SOC 2 / ISO 27001 / GDPR compliance page was found), so no `Compliance` pointer is wired in apis.yml. standards: - id: oauth2 conforms: false evidence: >- Single opaque bearer token, no authorization/token endpoints; /.well-known/oauth-authorization-server returns 404 - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 - id: rfc6750-bearer-token-usage conforms: partial evidence: >- Uses the RFC 6750 Authorization: Bearer header form, but the 401 carries a JSON body rather than the RFC 6750 WWW-Authenticate challenge - id: rfc9457-problem-details conforms: false evidence: >- Errors are {"message":..., "error_code":...} with content-type application/json, not application/problem+json - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on every Riverlane host - id: rfc8615-well-known conforms: false evidence: No /.well-known/ document is served on any host - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header support is documented - id: openapi conforms: false evidence: >- /openapi.json, /openapi.yaml, /swagger.json, /api-docs, /docs, /redoc and /api/v2/schema/ were probed on the API host and docs host; none returned a spec - id: graphql conforms: true evidence: >- POST https://deltakit.riverlane.com/proxy/api/graphql is the API v1 transport; introspection is auth-gated (401 error_code 6000) so the SDL could not be captured - id: asyncapi conforms: false evidence: No event, streaming or webhook surface is published - id: mcp conforms: false evidence: /mcp and /proxy/mcp probed; no MCP server responded to tools/list - id: a2a conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json return 404 on every host - id: semver-2.0.0 conforms: true evidence: Declared in the SDK README badges and enforced by python-semantic-release - id: spec-0 conforms: true evidence: >- Scientific Python SPEC 0 support window declared in the SDK README badges; Python >=3.10,<3.15 - id: apache-2.0 conforms: true evidence: license = "Apache-2.0" in pyproject.toml; LICENSE file present - id: pep-561-typing conforms: true evidence: Typing badge / py.typed marker declared on the PyPI packages - id: stim-interop conforms: true evidence: >- Circuits round-trip to and from quantumlib/Stim (circuit.as_stim_circuit()); deltakit-stim is a published Stim extension for leakage errors compliance_program: published: false trust_center: null certifications: [] probes: - {url: 'https://trust.riverlane.com/', status: 'no DNS resolution'} - {url: 'https://security.riverlane.com/', status: 'no DNS resolution'} - {url: 'https://www.riverlane.com/', status: 403, note: 'Cloudflare bot challenge — site not readable by a non-browser client'}