generated: '2026-08-17' method: searched source: >- openapi/switstack-switcloud-openapi.yml, openapi/switstack-swittest-openapi.yml, https://docs.switstack.io/switcloud/certification_overview/, https://docs.switstack.io/switcloud/faq/, https://docs.switstack.io/moka/, https://docs.switstack.io/moka/security/, security/switstack-domain-security.yml standards: - id: openapi-3.1 conforms: true evidence: 'both published documents declare openapi: 3.1.0 (Switcloud 2.28.0, Swittest 0.13.0)' - id: oauth2 conforms: true evidence: >- components.securitySchemes.OAuth2PasswordBearer type oauth2 with a password flow (tokenUrl auth/token) in both documents; docs additionally document a client_credentials grant (Oauth2GrantType enum = [password, client_credentials]). Bearer tokens with refresh + revoke endpoints. - id: oauth2-scopes conforms: false evidence: 'flow scopes map is empty in both documents; authorization is role-based, not scope-based' - id: oidc conforms: false evidence: 'no openIdConnect scheme; /.well-known/openid-configuration 404 on every host' - id: rfc8414-oauth-authorization-server-metadata conforms: false evidence: '/.well-known/oauth-authorization-server 404 on www.switstack.io and docs.switstack.io' - id: rfc9728-oauth-protected-resource conforms: false evidence: '/.well-known/oauth-protected-resource 404 on every host' - id: rfc9457-problem-details conforms: false evidence: >- errors are the FastAPI HTTPValidationError envelope over application/json; no application/problem+json response in either document - id: rfc9116-security-txt conforms: false evidence: '/.well-known/security.txt 404 on www.switstack.io and docs.switstack.io' - id: rfc8594-sunset-header conforms: false evidence: 'no Sunset/Deprecation header support documented; 0 of 128 operations marked deprecated' - id: rfc9111-http-caching conforms: false evidence: no cache-control/etag/conditional-request semantics declared in either document - id: idempotency-key conforms: false evidence: 'no Idempotency-Key parameter in either document and no retry-safety docs, including on create_payment' - id: pagination conforms: true evidence: >- fastapi-pagination page/size query parameters on 16 Switcloud list operations with a Page_TypeVar_Customized_ReadSchema_ envelope carrying items/total/page/size/pages - id: json-schema-2020-12 conforms: true evidence: 'OpenAPI 3.1.0 dialect; 94 Switcloud + 61 Swittest component schemas' - id: sse-server-sent-events conforms: true evidence: >- Swittest run_tests declares a text/event-stream 200 response with an OpenAPI 3.1 itemSchema of data/event/id/retry - id: asyncapi conforms: false evidence: 'no AsyncAPI document published; the only event surface is the SSE stream above' - id: webhooks conforms: false evidence: no webhook catalog or callbacks documented - id: mcp conforms: false evidence: >- homepage advertises an "MCP-based Payment Workflow" but no server, endpoint or docs page exists; every candidate host is NXDOMAIN (see mcp/switstack-mcp.yml) - id: a2a conforms: false evidence: '/.well-known/agent-card.json and /.well-known/agent.json 404 on every host' - id: llms-txt conforms: false evidence: '/llms.txt 404 on www.switstack.io and docs.switstack.io' - id: graphql conforms: false evidence: no GraphQL surface published or discoverable - id: grpc conforms: false evidence: 'no .proto published in the GitHub org, docs or buf.build' - id: dnssec conforms: true evidence: 'switstack.io is DNSSEC-signed (security/switstack-domain-security.yml)' - id: hsts conforms: true evidence: 'HSTS present on www.switstack.io (max-age 31536000) and docs.switstack.io (max-age 31556952)' - id: dmarc conforms: true evidence: 'DMARC published with p=quarantine; SPF present' - id: caa conforms: false evidence: 'no CAA record on switstack.io' - id: tls-1.3 conforms: true evidence: TLSv1.3 negotiated on both reachable hosts domain_standards: note: >- Switstack's real conformance story is EMV and PCI, not web-API standards. These are the standards the product is built to implement, captured from the provider's own published documentation. They are IMPLEMENTATION scope statements, not certificates held by Switstack unless marked otherwise. entries: - id: emv-level-2 conforms: true kind: certified-component evidence: >- "switcloud includes moka, a pre-certified EMV Level 2 kernel with available Letters of Compliance (LoC) for major payment brands" — https://docs.switstack.io/switcloud/certification_overview/. The FAQ states LoCs are included for moka so integrators "do not need to repeat L2 certification", with the caveat that "some limited additional testing may be required with certain COTS devices". - id: pci-mpoc conforms: partial kind: certified-component evidence: >- Switstack supplies an MPoC Software Component (on-device SDK) and an MPoC Service Component (cloud orchestration plus attestation & monitoring) described as "certified under MPoC Service requirements"; the integrator still completes final MPoC certification for its own payment app. https://docs.switstack.io/switcloud/faq/ - id: pci-pts conforms: n/a kind: leveraged evidence: >- For PCI-PTS terminals Switstack integrates the vendor's certified kernel and "leverages the PTS security to ensure cardholder data security"; no new certification scope is introduced. - id: p2pe conforms: partial kind: platform-dependent evidence: >- "PCI-PTS devices: P2PE is device-specific and supported natively through the terminal integration. COTS devices: P2PE is not currently well supported across the COTS ecosystem; this is a SoftPOS market limitation." - id: gla-generic-level-2-api conforms: true kind: implemented evidence: >- moka exposes and switcloud-l2-kt adapts a GLA (Generic Level 2 API) interface; "Works with any GLA-compliant kernel natively" and non-GLA kernels are bridged by an adapter layer. https://docs.switstack.io/api/moka/moka/, https://docs.switstack.io/swittest/architecture/ - id: emvco-contact-books-1-4 conforms: true kind: implemented evidence: 'moka implements EMVCo Books 1-4 (application selection, security/key management, core, ecosystem)' - id: emvco-contactless-books-a-d conforms: true kind: implemented evidence: >- moka implements EMVCo Books A, B and D plus kernels C-2 (Mastercard), C-3 (Visa), C-4 (Amex), C-5 (JCB), C-6 (Discover) and C-7 (CUP), with regional debit kernels (Interac, eftpos, RuPay) noted - id: emv-oda conforms: true kind: implemented evidence: >- "ODA is an EMV mechanism used to authenticate cards offline. It includes SDA, DDA, CDA, and XDA" — moka implements ODA with RSA and ECC; https://docs.switstack.io/moka/security/ compliance_program: published: false certifications: [] note: >- No SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP or GDPR posture is published, and there is no trust center, security page, security.txt, vulnerability-disclosure page or bug-bounty program (probe-security-programs.py returned vdp=none trust=none). The EMV/MPoC statements above are product-certification scope, not an organizational compliance program — so NO `Compliance` and NO `TrustCenter` pointer is emitted. For a payments-infrastructure company handling cardholder-data-adjacent flows this is the single largest published gap.