generated: '2026-08-13' method: derived source: openapi/trend-api-openapi.yml + live probes of https://api.trend.io note: >- Cross-cutting standards assertions for the Trend API. Trend publishes no compliance claims, no certifications and no standards conformance statements anywhere on trend.io, soona.co or the API host, so every entry below is derived from the contract or observed on the wire. No Compliance pointer is emitted in apis.yml because no compliance program is published. standards: - id: openapi conforms: true version: 3.0.0 evidence: >- https://api.trend.io/docs-json returns a parseable OpenAPI 3.0.0 document, 122 paths / 124 operations / 64 component schemas, generated by @nestjs/swagger. Served unauthenticated, HTTP 200, application/json. - id: oauth2 conforms: false evidence: >- No oauth2 securityScheme is declared. Authentication is a Firebase-issued JWT presented as an HTTP bearer token plus a static admin API key header; there is no authorization server, no /authorize or /token endpoint, and no /.well-known/oauth-authorization-server (404 on api.trend.io). - id: oidc conforms: false evidence: >- No openIdConnect securityScheme and no /.well-known/openid-configuration on any Trend host (404). Google sign-in is brokered by Firebase inside the application (POST /auth/login/google, POST /auth/brand/login/google); Trend is a relying party, not an OIDC provider. - id: rfc9457 conforms: false evidence: >- Errors are the NestJS default {"message","error","statusCode"} envelope in application/json. No application/problem+json, no type URI, no instance. Observed on a live 404 and a live 401. See errors/trend-problem-types.yml. - id: rfc8594 conforms: false evidence: No Sunset or Deprecation response headers declared or observed; no deprecation policy published. - id: idempotency conforms: false evidence: >- No Idempotency-Key header on any operation (no header parameters are declared at all), and the string "idempoten" is absent from the contract. Unsafe POSTs including Stripe checkout and credit grants have no replay protection. - id: pagination conforms: true style: page-number evidence: >- Consistent page / perPage / sortBy / returnAll / paginationFlags query parameters with a FindAllResponse envelope carrying documents, total, totalPages, page, perPage, sortBy, sortOrder. No cursor pagination and no RFC 8288 Link headers. - id: ratelimit-headers conforms: false evidence: >- No X-RateLimit-*, RateLimit-* or Retry-After headers observed on live 200 or 404 responses; no 429 declared in the spec. - id: json-schema conforms: partial evidence: >- Component schemas are OpenAPI 3.0 Schema Objects (JSON Schema Draft 4 dialect subset). Coverage is uneven — BrandSchema declares an empty properties object, and no Campaign or Partnership response schema exists, so significant parts of the model are unschematized. - id: asyncapi conforms: false evidence: >- No AsyncAPI document and no consumer-facing event surface. The two /events routes (POST /payment/stripe/events, POST /shipment/events) are INBOUND webhook receivers — Trend consuming Stripe and carrier callbacks — not webhooks Trend emits to customers. Trend publishes no webhook catalog and offers no subscription mechanism, so this is N/A rather than a failure. - id: mcp conforms: false evidence: >- No MCP server. https://mcp.trend.io/mcp does not resolve; https://api.trend.io/mcp returns 404. See mcp/trend-mcp.yml (mode: none, derived candidate). - id: a2a conforms: false evidence: >- No agent card. /.well-known/agent-card.json and /.well-known/agent.json return 404 on trend.io, api.trend.io and soona.co; app.trend.io answers 200 with the React SPA shell for every path, which is a catch-all and not a card. - id: llmstxt conforms: false evidence: /llms.txt returns 404 on trend.io and api.trend.io; app.trend.io returns the SPA shell. - id: security-txt conforms: false evidence: /.well-known/security.txt returns 404 on trend.io and api.trend.io (RFC 9116 not implemented). - id: tls conforms: true evidence: >- HTTPS enforced on both hosts. trend.io negotiates TLS 1.3 with HSTS (max-age 31536000); api.trend.io negotiates TLS 1.2 and sends NO HSTS header. See security/trend-domain-security.yml. - id: cors conforms: true evidence: 'access-control-allow-origin: * returned on 200 and 404 responses from api.trend.io.' regulatory: pci_dss: claimed: false detail: >- Card data is handled by Stripe — the API mints Stripe Checkout sessions (POST /payment/stripe/checkout/{productId}) and reads a session card (GET /payment/stripe/session/{id}/payment-card) rather than accepting PANs. No PCI attestation is published by Trend. gdpr_ccpa: claimed: partial detail: >- A privacy policy is published at soona.co/privacy-policy and the API exposes a user-deletion route (DELETE /auth/remove-my-user), which is a data-subject erasure mechanism. No DPA, subprocessor list or certification is published. soc2: claimed: false detail: No SOC 2, ISO 27001 or other certification is published on trend.io or soona.co. observations: - >- Auth enforcement is inconsistent with the declared contract: the spec sets a global `security: [access-token]` requirement, but GET /payment/stripe/packages and GET /creator/profile/id-list both answer HTTP 200 to anonymous callers. An integrator cannot rely on the spec's security block to predict enforcement. - >- The Swagger UI at https://api.trend.io/docs is protected (HTTP 401) while the machine-readable document behind it at /docs-json and /docs-yaml is fully open (HTTP 200). The human door is locked and the machine door is not — which is why this API is profilable at all.