generated: '2026-08-13' method: derived source: openapi/ + https://docs.spindl.xyz/technical/api note: >- Derived from the three captured OpenAPI descriptions plus live probes. No published compliance program (SOC 2, ISO 27001, PCI, HIPAA, GDPR posture page, trust center) was found on any Spindl host, so NO Compliance pointer is emitted. Spindl's privacy page defers to a Substack essay and states that the "Data Processor Addendum and formal data use docs [are] available by request". standards: - id: oauth2 conforms: false evidence: All three surfaces use static API key headers; no OAuth2 flows declared. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 or 503 on every host. - id: rfc9457-problem-details conforms: false evidence: >- No surface returns application/problem+json. Three distinct envelopes are in use — {statusCode,message}, grpc-gateway {code,message,details}, and plain text. See errors/spindl-problem-types.yml. - id: api-key-header-auth conforms: true evidence: >- X-API-Key on the management and events surfaces; X-API-ACCESS-KEY on the Ads surface. Confirmed live by a 401 carrying `www-authenticate: API key is required`. - id: rest-json conforms: true evidence: Resource-oriented JSON over HTTPS with standard 2xx/4xx/5xx status codes. - id: grpc-gateway-error-model conforms: true evidence: >- The Ads host returns the Google API / grpc-gateway error object {code,message,details} with gRPC status codes (16 UNAUTHENTICATED, 5 NOT_FOUND), observed live 2026-08-13. - id: uri-path-versioning conforms: true evidence: >- Management API and Ads API are both versioned in the path (/v1/). The events ingestion endpoint (spindl.link/events/server) is not versioned. - id: idempotency-keys conforms: false evidence: No idempotency-key header documented for write operations on any surface. - id: pagination conforms: false evidence: >- listLinks returns the full set with no pagination parameters; the Ads render endpoint caps results with a `limit` parameter but exposes no cursor. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 or 503 on every Spindl host. - id: rfc8594-sunset-header conforms: false evidence: No deprecation or sunset policy published; no Sunset header documented. - id: subresource-integrity conforms: true evidence: >- Spindl publishes an SRI sha512 hash for its CDN-distributed browser SDK and documents pinning to an exact npm version as the recommended install, at docs.spindl.xyz/technical/javascript-sdk-html-script-guide/security. - id: asyncapi conforms: false evidence: >- No event, webhook or streaming surface is published. Bulk delivery is a daily S3 file dump, not an event contract. Not applicable rather than failed. - id: a2a-agent-card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json miss on every host; the 200s on spindl.link and app.spindl.xyz are SPA catch-alls serving HTML. See well-known/spindl-well-known.yml.