generated: '2026-08-17' method: derived source: >- openapi/santeacademie-frontstage-openapi.json + openapi/santeacademie-connector-openapi.json + live probes of frontstage.santeacademie.com + https://www.santeacademie.com/formation/liberal (certification marks) + well-known/santeacademie-well-known.yml note: >- Two different kinds of conformance are recorded here and they must not be blurred. `standards` is what the APIs conform to technically — mostly `false`, derived from the specs and live responses. `sector_accreditations` is the regulated-training compliance Santé Académie genuinely holds and publishes as certification marks on its own site. There is NO published information-security or data-protection certification (no SOC 2, no ISO 27001, no HDS health-data hosting attestation, no trust center), and this file says so explicitly rather than letting the sector marks stand in for one. standards: - id: openapi conforms: true version_declared: frontstage: 3.1.0 connector: 3.0.0 evidence: >- Both documents parse as OpenAPI and are served publicly and anonymously — https://frontstage.santeacademie.com/api/docs.jsonopenapi (200, application/vnd.openapi+json, 35,397 bytes) and https://frontstage.santeacademie.com/connector/api/ (200, application/json, 63,774 bytes). Saved verbatim under openapi/. caveat: >- Valid but unpublicised and incomplete as contracts: Frontstage names no host (servers[] is "/") and ships an empty tags[]; Connector ships no servers[] at all and keeps the generator's placeholder title "api". Neither is linked from any human-facing page — both were found by direct path probing. - id: rfc9457 name: Problem Details for HTTP APIs conforms: partial evidence: >- Frontstage returns `application/problem+json` with type/title/detail — verified live on https://frontstage.santeacademie.com/api/topics/nonexistent-slug-xyz-99 (404). It is the correct media type and the correct member names. caveat: >- Substantively non-conformant. `type` is the API Platform default https://tools.ietf.org/html/rfc2616#section-10 on EVERY error, and `title` is the constant "An error occurred", so the document carries no per-problem identity — the whole purpose of the RFC. The sibling Connector API returns a bare JSON string ("Topic not found") and conforms not at all. detail_source: errors/santeacademie-problem-types.yml - id: oauth2 conforms: false evidence: >- Zero securitySchemes in either specification; /.well-known/oauth-authorization-server 404s on every host (www, frontstage, play, simulateur). Both APIs are open and unauthenticated. - id: oidc conforms: false evidence: /.well-known/openid-configuration returned 404 on www, frontstage, play and simulateur. - id: pagination conforms: partial evidence: >- Frontstage collections implement page-number pagination (page / itemsPerPage / pagination) with an elements/currentPage/lastPage/itemsPerPage/totalItems envelope, verified live on /api/resources-search?itemsPerPage=1 (totalItems 608). caveat: >- Not a standard shape — API Platform's Hydra collection has been replaced with a bespoke envelope — and the Connector API has no pagination at all, returning unbounded arrays. - id: idempotency conforms: false not_applicable: true evidence: >- All 24 published operations are GET, so idempotency is inherent and no Idempotency-Key mechanism is needed, documented or observed. Recorded as false rather than true because the provider publishes no idempotency support; it is simply not required by this surface. - id: json-api conforms: false evidence: Plain JSON. No application/vnd.api+json, no data/attributes/relationships envelope. - id: jsonld-hydra conforms: false evidence: >- API Platform ships JSON-LD/Hydra by default and it has been disabled here — /api/docs.jsonld returns 404 application/problem+json on frontstage. Responses are plain JSON with a custom collection envelope. - id: graphql conforms: false evidence: >- The Swagger UI shell at /api/docs.html mentions GraphiQL (an API Platform template default), but https://frontstage.santeacademie.com/api/graphql and /graphql both return 404. No GraphQL surface exists. - id: asyncapi conforms: false not_applicable: true evidence: No event, streaming or webhook surface of any kind was found. Nothing to describe. - id: mcp conforms: false evidence: No hosted MCP endpoint and no first-party MCP package. See mcp/santeacademie-mcp.yml. - id: a2a conforms: false evidence: >- /.well-known/agent-card.json and the legacy /.well-known/agent.json returned 404 on www, frontstage, play, simulateur and support. No agent card exists, so none is authored here. - id: rfc9116 name: security.txt conforms: false evidence: >- 404 on www, frontstage, play and simulateur. The single 200 (support.santeacademie.com) is Intercom's own vendor file, whose Canonical is https://app.intercom.com/.well-known/security.txt — not Santé Académie's. - id: rfc8594 name: Sunset / Deprecation headers conforms: false evidence: >- No Sunset or Deprecation header on any observed response and no deprecation policy published. Both specs carry a `deprecated` flag on every schema and operation and every one is `false`. - id: llmstxt conforms: partial evidence: >- https://support.santeacademie.com/llms.txt returns 200 with a real index of 25 French help articles, saved at llms/santeacademie-support-llms.txt. caveat: >- Auto-generated by Intercom for every hosted help center rather than authored by Santé Académie, and it indexes support content only — it says nothing about the two public APIs. /llms.txt 404s on www and on the API host. - id: fhir conforms: false not_applicable: true evidence: >- Not a clinical-data provider. The APIs expose a training catalog (topics, courses, professions, funding schemes); no patient, observation or clinical resource appears in either specification. FHIR is not the relevant standard. - id: scim conforms: false evidence: >- No identity or provisioning surface. Learner accounts are managed through a first-party session login at play.santeacademie.com with no public provisioning API. - id: odata conforms: false evidence: Bracket-style API Platform filters, not $filter/$select/$expand. sector_accreditations: note: >- These are the compliance credentials Santé Académie actually publishes. They are French vocational-training and continuing-medical-education regulatory accreditations, verifiable in public national registries — NOT security or data-protection certifications. Scope matters: they say the company is authorised to deliver funded DPC training, not anything about how it protects data or runs its APIs. certifications: - name: Qualiopi kind: national quality certification for training providers (France, mandatory for public funding) published: true evidence: method: probed url: https://www.santeacademie.com/images/logos/logo-qualiopi.png http_status: 200 note: certification mark served from the company's own domain and displayed in the site footer - name: ODPC — Organisme agréé auprès de l'Agence Nationale du DPC kind: sector accreditation to deliver funded Développement Professionnel Continu programmes published: true evidence: method: probed url: https://www.santeacademie.com/images/logos/odpc.png http_status: 200 note: >- Corroborated by the product copy on https://www.santeacademie.com/formation/liberal ("formations agréées DPC") and by the enrollment flow, which finalises registration on the ANDPC's own agencedpc.fr. - name: France Compétences registration kind: national register of training providers published: true evidence: method: searched url: https://www.santeacademie.com/ note: >- Claimed in the company's own public marketing copy. Recorded as a provider claim; the registry entry itself was not retrieved during this pass. funding_regimes_operated: - ANDPC - FIF-PL - FAF-PM - ANFH - OPCO information_security_compliance: published: false soc2: false iso27001: false hds: false pci: false hipaa: false fedramp: false trust_center: false detail: >- Nothing. probe-security-programs.py returned vdp=none trust=none. No trust center, no bug bounty, no first-party security.txt, no named security certification anywhere public. This is notable for a company handling French healthcare professionals' identity and training records: HDS (Hébergeur de Données de Santé) is the certification a reader would look for and it is not claimed. privacy_policy: url: https://www.notion.so/santeacademie/Politique-de-confidentialit-af621df7e4be4f4182e0879851735568 http_status: 200 machine_readable: false note: >- Hosted on Notion and 307s to app.notion.com, where the content is JavaScript-rendered — a fetch returns the word "Notion" and nothing else. The policy may well name RGPD obligations, a DPO and sub-processors, but no machine and no agent can read it, so nothing from it is recorded here. The same is true of the CGU-V and the mentions légales, which are all Notion pages. summary: standards_evaluated: 18 conforms_true: 1 conforms_partial: 3 conforms_false: 14 sector_certifications_published: 3 security_certifications_published: 0