generated: '2026-07-21' method: derived source: https://docs.stairwell.com/reference standards: - id: oauth2 conforms: false evidence: Auth is opaque bearer API tokens, not OAuth2. - id: openidconnect conforms: false - id: rfc9457-problem-details conforms: false evidence: Errors use the google.rpc.Status model (gRPC/HTTP transcoding), not application/problem+json. - id: google-aip-resource-names conforms: true evidence: Hierarchical resource names + page_size/page_token pagination (AIP-158 style). - id: pagination conforms: true evidence: List operations return next_page_token cursors. - id: yara conforms: true evidence: First-class YARA rule management, ad-hoc scanning, and rule feeds. - id: mitre-attack conforms: true evidence: Object detonation results include MITRE ATT&CK TTPs. - id: webhooks conforms: true evidence: Outbound event-notification webhooks (av_scan_match, yara_rule_match). - id: mcp conforms: true evidence: Official hosted MCP server at mcp.api.stairwell.com. notes: >- Derived from documented API behavior. Stairwell publishes a Trust Center (https://trust.stairwell.com/) but specific certifications (SOC 2, ISO 27001, etc.) could not be machine-verified from public pages, so no Compliance pointer is emitted.