generated: '2026-07-21' method: derived source: docs.sequencemkts.com/api (no OpenAPI published; derived from documented conventions) standards: - id: oauth2 conforms: false evidence: Auth is a static Sequence-issued Bearer API key, not an OAuth2 flow. - id: oidc conforms: false - id: rfc9457-problem-details conforms: false evidence: Errors use a custom {error:{code,message,request_id,details}} envelope, not application/problem+json. - id: rfc6750-bearer-token conforms: true evidence: API key presented as Authorization Bearer token. - id: idempotency conforms: true evidence: graph_id provides idempotent order submission (duplicate returns original; mismatch returns 409). - id: uri-path-versioning conforms: true evidence: All endpoints under /v1/ prefix. - id: token-bucket-rate-limiting conforms: true evidence: Documented token-bucket limiter (capacity 2x qps, refill qps/sec), 429 RATE_LIMITED. - id: websocket-streaming conforms: true evidence: Multiplexed WebSocket at /v1/stream with channel subscribe/subscribed protocol. - id: fhir-r4 conforms: false - id: fapi conforms: false - id: scim conforms: false - id: odata conforms: false - id: json-api conforms: false compliance_program: published: false note: No SOC 2 / ISO 27001 / PCI / trust center found as of 2026-07-21 (early-stage YC W26 company).