generated: '2026-07-21' method: derived source: openapi/sequel-openapi-original.yml + well-known/sequel-oauth-authorization-server.json standards: - id: oauth2 conforms: true evidence: API auth is an OAuth 2.0 client-credentials flow issuing JWT access tokens (docs + token endpoint). - id: openid-connect conforms: true evidence: End-user login is Auth0 OIDC; /.well-known/oauth-authorization-server advertises issuer, authorize, token, userinfo, jwks. - id: jwt-rfc7519 conforms: true evidence: Access tokens are JWT (bearerFormat JWT in securitySchemes). - id: openapi-3.0 conforms: true evidence: Published OpenAPI 3.0.1 definition across the reference docs. - id: rfc9457-problem-details conforms: false evidence: Errors use a custom {hasError, errorMessage} envelope, not application/problem+json. - id: json-api conforms: false - id: webhooks conforms: true evidence: Documented webhook surface (Sequel webhooks getting-started, custom CMS/CRM webhooks). compliance_program: published: false notes: No public SOC 2 / ISO 27001 / trust center or named certifications were found for Sequel/Introvoke.