generated: '2026-07-26' method: derived source: openapi/sprift-openapi.json + https://sprift.com/data-and-api + https://sprift.com/partnerships summary: >- Sprift conforms to almost no cross-cutting API standard. It publishes a Swagger 2.0 contract (not OpenAPI 3.x), authenticates with a custom header outside the securityDefinitions mechanism, uses a proprietary error envelope, and asserts no industry data standard in the contract itself. The only standards affiliation it claims is associational: accredited membership of the Open Property Data Association, whose Property Data Trust Framework the contract does not implement. standards: - id: swagger-2.0 conforms: true evidence: >- openapi/sprift-openapi.json declares swagger 2.0, host sprift.com, basePath /dashboard/api/v1, 27 paths, 76 definitions; served anonymously at https://sprift.com/dashboard/api-doc/sprift.json - id: openapi-3 conforms: false evidence: no OpenAPI 3.x document is published on any Sprift host - id: oauth2 conforms: false evidence: no oauth2 securityScheme; no OAuth documentation on any Sprift surface - id: oidc conforms: false evidence: https://sprift.com/.well-known/openid-configuration returns HTTP 404 - id: rfc8414-oauth-authorization-server-metadata conforms: false evidence: https://sprift.com/.well-known/oauth-authorization-server returns HTTP 404 - id: rfc9457-problem-details conforms: false evidence: >- errors use a proprietary {status, error} envelope with content-type application/json; no application/problem+json appears in the contract - id: rfc9116-security-txt conforms: false evidence: https://sprift.com/.well-known/security.txt returns HTTP 404 - id: rfc8594-sunset-header conforms: false evidence: no Sunset or Deprecation header support documented; no deprecation policy published - id: json-api conforms: false evidence: responses are ad-hoc objects, not JSON:API documents - id: odata conforms: false evidence: >- no service root and no $metadata document; https://api.sprift.com/$metadata returns HTTP 403 MissingAuthenticationTokenException from AWS API Gateway - id: idempotency-key conforms: false evidence: no Idempotency-Key parameter or header on either write operation - id: pagination conforms: partial evidence: >- page-number pagination (page, limit, sort with total_reports / has_next_page / total) on SearchMyProperties and the two Insider operations only; the property family returns whole objects with no paging envelope - id: reso-web-api conforms: false evidence: >- no RESO Web API surface and no RESO certification. RESO is a North American, NAR-driven construct; the UK has no MLS to certify against. Sprift is in the NAR REACH UK cohort (Second Century Ventures), which is a commercial affiliation and not a certification. - id: reso-data-dictionary conforms: false evidence: >- field names in the contract are Sprift-proprietary (property_id, uprn, epc_current_energy_rating, council_tax_band); no RESO Data Dictionary resource or field naming appears anywhere - id: upi-universal-property-identifier conforms: false evidence: >- no Universal Property Identifier appears in the contract or on the site; Sprift's identifier is the UK UPRN - id: uprn conforms: true evidence: >- UPRN is the primary key of the whole product — path parameter on eight operations (uprn), a field on the comparables, insider and property schemas, and the join key Sprift markets as "UPRN-first architecture" on https://sprift.com/data-and-api - id: pdtf-property-data-trust-framework conforms: false claims_membership: true evidence: >- https://sprift.com/partnerships states Sprift was "originally a founding member" and is now "an accredited member" of the Open Property Data Association, which publishes the Property Data Trust Framework (https://github.com/Property-Data-Trust-Framework). The membership is associational: no PDTF schema, claim structure, or conformance statement appears anywhere in the harvested contract. Affiliation is not conformance, and both are recorded separately here. - id: uk-gdpr conforms: claimed evidence: >- https://sprift.com/terms-and-conditions binds both parties to EU GDPR, UK GDPR as onshored by the European Union (Withdrawal) Act 2018, and defines "End User Data" as personal data under applicable data protection law; https://sprift.com/privacy-policy names a data protection officer reachable at customer.success@sprift.com and cites the Information Commissioner's Office as the complaint route note: >- A contractual and statutory data-protection commitment, not an audited certification. certifications: published: [] note: >- No SOC 2, ISO 27001, ISO 27017/27018, PCI DSS, HIPAA, FedRAMP, CSA STAR or Cyber Essentials claim was found on sprift.com, its terms, its privacy policy or any trust/security subdomain. trust.sprift.com does not resolve; https://sprift.com/security returns HTTP 404. No `Compliance` pointer is wired for this repo, because Sprift publishes no compliance program.