generated: '2026-07-21' method: derived source: openapi/soveren-object-api-openapi.yml standards: - id: http-bearer-auth conforms: true evidence: openapi securityScheme type http scheme bearer - id: oauth2 conforms: false - id: openid-connect conforms: false - id: rfc9457-problem-details conforms: false evidence: error responses are not documented as application/problem+json - id: pagination-offset-limit conforms: true evidence: list operations expose limit + offset query parameters - id: webhooks-hmac-signed conforms: true evidence: outbound webhooks signed with HMAC-SHA-256 in x-soveren-signature header - id: asyncapi conforms: true evidence: event surface captured as AsyncAPI 3.0.0 (asyncapi/soveren-events-asyncapi.yml) compliance_features: note: >- Soveren's product audits data-store compliance posture (PCI DSS, GDPR, CPRA) for its customers' environments. These are product detection capabilities, not published third-party certifications of Soveren itself; no Compliance pointer is emitted (no verified SOC 2 / ISO 27001 trust page was found). audits: [PCI DSS, GDPR, CPRA]