generated: '2026-07-25' method: searched source: | Audatex Estimate Document Return API Integration Guide (PDF), Claim Image Document Return API Integration Guide (PDF), GIC - Image Capture API Integration Guide (DOCX), the ten harvested OpenAPI/Swagger documents in openapi/, and the anonymous OpenID Connect discovery documents in well-known/. standards: - id: cieca-bms-5.7 name: CIECA Business Message Suite 5.7 conforms: partial evidence: | "Audatex is a Corporate Technology member of Collision Industry Electronic Commerce Association ('CIECA') and is licensed to use CIECA standards in its products." Assignment and estimate payloads are carried as Base64-encoded CIECA BMS documents (AddAssignmentRequestBody.bmsVer = "5.7.0", content = Binary64 encoded BMS AssignmentAddRq). The guide is explicit that alignment is partial: "The Audatex system does not support all fields available in the CIECA BMS." docs: https://www.cieca.com/ - id: acord name: ACORD standards conforms: false evidence: | No occurrence of ACORD, AL3, ACORD XML, NGDS or IVANS in any Solera or Audatex public integration documentation, portal page, or harvested specification. CIECA is the standards body Solera names, not ACORD. - id: oauth2 name: OAuth 2.0 (RFC 6749) conforms: true evidence: | Every harvested spec declares an oauth2 securityScheme. The IdentityServer exposes /connect/token, /connect/authorize, /connect/introspect, /connect/revocation and /connect/deviceauthorization. grant_types_supported includes authorization_code, client_credentials, password, refresh_token, implicit and device_code. - id: oauth2-client-credentials name: OAuth 2.0 client credentials grant conforms: true evidence: The integration guides document grant_type=client_credentials with client_id b2b.fnol and scope b2b.fnol.documents for server-to-server document retrieval. - id: oidc-discovery name: OpenID Connect Discovery 1.0 conforms: true evidence: /.well-known/openid-configuration returns 200 anonymously on both dispatch-login.audatex.com and dispatch-login-demo.audatex.com; jwks_uri resolves. docs: https://dispatch-login.audatex.com/.well-known/openid-configuration - id: rfc7636-pkce name: PKCE (RFC 7636) conforms: true evidence: code_challenge_methods_supported includes S256 (and plain) in both discovery documents. - id: rfc8628-device-authorization name: OAuth 2.0 Device Authorization Grant (RFC 8628) conforms: true evidence: device_authorization_endpoint published; grant_types_supported includes urn:ietf:params:oauth:grant-type:device_code. - id: rfc7662-token-introspection name: OAuth 2.0 Token Introspection (RFC 7662) conforms: true evidence: introspection_endpoint https://dispatch-login.audatex.com/connect/introspect - id: rfc8414-oauth-authorization-server-metadata name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: false evidence: /.well-known/oauth-authorization-server returns 404 on both IdentityServer hosts; only the OIDC discovery path is served. - id: http-basic-auth name: HTTP Basic authentication (RFC 7617) conforms: true evidence: 'Both return-API integration guides list the supported client authentication methods as "Basic Authorization" and "OAuth", over SSL.' - id: openapi-3 name: OpenAPI 3.0 conforms: true evidence: Eight of the ten harvested documents are OpenAPI 3.0.1; two production documents are Swagger 2.0. - id: rfc9457-problem-details name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: No application/problem+json media type appears in any harvested spec. Errors are plain HTTP status codes with prose descriptions; success payloads use a bespoke header/body envelope with header.statusCode. - id: rfc9116-security-txt name: security.txt (RFC 9116) conforms: false evidence: /.well-known/security.txt returns 404 on solera.com, na.api.solera.com, api-demo.audatex.com and both IdentityServer hosts. - id: rfc8594-sunset-header name: Sunset HTTP header (RFC 8594) conforms: false evidence: No Sunset or Deprecation header, and no deprecation policy, is documented anywhere in the public integration guides. - id: asyncapi name: AsyncAPI conforms: false evidence: No AsyncAPI document is published. The callback/event surface is documented only in PDF/DOCX prose; asyncapi/solera-eapi-asyncapi.yml is an API Evangelist generation from that prose, not a provider artifact. - id: hateoas name: HATEOAS hypermedia links conforms: true evidence: | Both return integrations push a "HATEOAS message" whose Body.Links[] carry Rel, Method, Href and Type for each retrievable document — the guides use the term verbatim and the sample payloads implement it. - id: fhir-r4 conforms: false - id: fapi conforms: false - id: scim2 conforms: false - id: odata conforms: false - id: psd2 conforms: false - id: json-api conforms: false compliance_program: published: false note: | No trust center, no SOC 2 / ISO 27001 / PCI DSS / HIPAA / FedRAMP claim, and no security or compliance page was found on solera.com. /security/ and /trust/ return 404; trust.solera.com and security.solera.com do not resolve. The public policy surface at /policies-downloads/ carries a Code of Conduct and a Whistle Blower Policy only. No `Compliance` pointer is emitted, because none is published.