generated: '2026-08-28' method: derived source: >- openapi/soothe-help-center-mirror-openapi.json, security/soothe-domain-security.yml, well-known/soothe-well-known.yml, https://www.soothe.com/trust-and-safety/ standards: - id: openapi-3.1 conforms: true evidence: >- openapi/soothe-help-center-mirror-openapi.json declares openapi 3.1.0 and parses as a valid OpenAPI document with 4 paths and 6 operations. - id: json-schema-2020-12 conforms: true evidence: >- OpenAPI 3.1.0 uses JSON Schema 2020-12 dialect; components.schemas defines HTTPValidationError and ValidationError. - id: oauth2 conforms: false evidence: No oauth2 securityScheme in any spec and no OAuth documentation on soothe.com. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns a catch-all HTML shell on every host. - id: rfc9457-problem-details conforms: false evidence: >- Errors use the FastAPI default {"detail": ...} envelope with application/json, not application/problem+json. - id: rfc9116-security-txt conforms: false evidence: No /.well-known/security.txt served on any host (see well-known probe). - id: rfc8414-oauth-authorization-server-metadata conforms: false evidence: No authorization-server metadata document served. - id: idempotency conforms: false evidence: No idempotency key header or parameter in the spec or in any published docs. - id: pagination conforms: false evidence: No collection endpoint in the published contract, so no pagination contract. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface published. domain_standards: [] domain_standards_note: >- Consumer wellness / local-services marketplaces have no established machine-readable domain standard analogous to FHIR, SCIM or OpenRTB, and Soothe declares none in its contract. Reward-only check — recorded as not applicable rather than as a failure. compliance: published_program: false certifications: [] note: >- No trust centre, no SOC 2 / ISO 27001 / PCI / HIPAA claim, and no compliance page. trust.soothe.com and security.soothe.com do not resolve; https://www.soothe.com/security returns 404. https://www.soothe.com/trust-and-safety/ is a consumer safety page about background checks and provider vetting, not an information-security compliance program. No Compliance or TrustCenter pointer is emitted.