generated: '2026-08-09' method: derived source: openapi/rtcstats-api-openapi.yml + mcp/rtcstats-mcp-tools.json + https://rtcstats.com/api-docs.md description: Cross-cutting standards the rtcStats API does and does not conform to. Derived from the published OpenAPI 3.0.3, a live MCP initialize/tools/list handshake, and the API reference. rtcStats publishes no compliance certifications (no SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP claim appears anywhere on the site, in the Terms of Service or in the Privacy Policy), so no Compliance pointer is wired. standards: - id: openapi-3.0 conforms: true evidence: Machine-readable OpenAPI 3.0.3 served at https://rtcstats.com/api/openapi (HTTP 200, application/json, 9 operations, all with operationId, summary, description, tags and securitySchemes applied). - id: mcp-2025-06-18 conforms: true evidence: 'MCP initialize returned protocolVersion 2025-06-18, serverInfo {name: rtcstats, version: 1.9.0}, capabilities.tools.listChanged true, over Streamable HTTP at https://api.rtcstats.com/v1.0/mcp.' - id: json-rpc-2.0 conforms: true evidence: MCP transport speaks JSON-RPC 2.0; the OpenAPI declares McpStreamableHttpTransportError and McpJsonRpcSseDataLine schemas for the envelope. - id: llms-txt conforms: true evidence: https://rtcstats.com/llms.txt returns HTTP 200 text/plain with H1, blockquote summary and sectioned link lists, plus an inline analysis-output schema. - id: rfc6750-bearer conforms: true evidence: 'OpenAPI securityScheme BearerAuth: type http, scheme bearer, bearerFormat JWT; Authorization: Bearer header applied to every operation.' - id: oauth2 conforms: false evidence: No oauth2 securityScheme in the OpenAPI and no OAuth authorization-server or protected-resource metadata at either host (both 404). Auth is a static application JWT minted in the dashboard. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on both hosts. - id: rfc9457-problem-details conforms: false evidence: Errors use a custom {error, errorCode} JSON envelope, not application/problem+json. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on both hosts. - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog returns 404 on both hosts. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header support documented; no deprecation policy published. - id: a2a-agent-card conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json both 404 on rtcstats.com and api.rtcstats.com. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface — the word webhook does not appear in the API reference or llms.txt. Not applicable rather than missing. - id: idempotency-key conforms: false evidence: No idempotency key documented; the chunked-upload fileId is a de-duplication id, not a retry-safe idempotency key. - id: w3c-webrtc-stats conforms: true evidence: The analysis model is built on the W3C WebRTC Statistics API (getStats) identifiers; the knowledge base publishes a per-metric reference keyed to the W3C stats dictionary members (e.g. candidate-pair currentRoundTripTime, availableOutgoingBitrate). - id: openapi-3.2 conforms: true evidence: the document declares 3.2.0 - id: rfc9457 conforms: false evidence: no response declares application/problem+json - id: idempotency conforms: false evidence: no idempotency key parameter on mutating operations certifications_published: [] compliance_notes: - 'Terms of Service (effective 2025-09-02) state: "We do not offer service-level agreements for most of our Services."' - Privacy Policy (effective 2025-09-02) references EU/UK data protection authorities and acknowledges third-party subprocessors, but publishes no subprocessor list and no DPA. - All data infrastructure is located in the U.S.; Enterprise plans can store session data on the customer’s own servers or provider ("3rd party storage").