generated: '2026-08-14' method: searched source: >- https://docs.altrata.com/errors-warnings-and-limits, https://docs.altrata.com/paging, https://docs.altrata.com/service-user-credentials, https://altrata.com/altratas-privacy-promise, https://mcp.altrata.com/.well-known/oauth-authorization-server (searched/probed); openapi/wealth-x-connect-openapi.yml (derived). description: >- Cross-cutting standards conformance across both Wealth-X surfaces — the legacy Wealth-X Connect REST API and the successor Altrata GraphQL platform — plus the published compliance posture. Round 1 assessed only the legacy REST API; several entries flip to true here because the successor platform was found. standards: - id: rest conforms: true surface: legacy evidence: Resource-oriented REST over HTTPS with JSON responses on connect.wealthx.com/rest/v1. - id: openapi-3 conforms: true surface: legacy evidence: >- Captured as OpenAPI 3.0.3 (generated faithfully from the provider's published Postman collection). The provider itself publishes no OpenAPI. - id: graphql conforms: true surface: successor evidence: >- Four GraphQL services (profile, relationships, events, matching) at /v1/graphql, each with a GraphiQL explorer at /v1/graphiql. Schema introspection is auth-gated (401/403 anonymously), so no SDL was captured. source: https://docs.altrata.com/urls - id: graphql-cursor-connections conforms: partial surface: successor evidence: >- Relay-style cursor pagination — pageInfo{after,before,first,last} on the request, pageInfoResponse{totalCount, pageInfo{hasNextPage, hasPreviousPage, startCursor, endCursor}} on the response. Deviates from the Relay spec in naming (`items` rather than `edges`/`node`) and requires `before` whenever `last` is used. source: https://docs.altrata.com/paging - id: graphql-fragments conforms: false surface: successor evidence: >- Named fragment spreads are explicitly unsupported, including on nested fields; a request using one fails with a GenericError. Only inline fragments for type selection work. This is a documented deviation from the GraphQL specification. source: https://docs.altrata.com/errors-warnings-and-limits - id: apikey-auth conforms: true surface: both evidence: >- Legacy: three apiKey header schemes (username, password, apikey). Successor: an `x-api-key` header alongside HTTP Basic service credentials on the token request. - id: oauth2 conforms: true surface: successor evidence: >- client_credentials grant at https://api.auth.altrata.com/oauth2/token for the GraphQL APIs, and authorization_code + PKCE (S256) for the MCP server with RFC 8414 authorization-server metadata published at HTTP 200. source: https://docs.altrata.com/service-user-credentials - id: oidc conforms: partial surface: successor evidence: >- The MCP authorization server advertises the `openid` scope and is backed by Amazon Cognito, but no /.well-known/openid-configuration document is served on any Altrata or Wealth-X host. - id: rfc8414-oauth-authorization-server-metadata conforms: true surface: successor evidence: https://mcp.altrata.com/.well-known/oauth-authorization-server returns HTTP 200 with valid metadata. - id: rfc9728-oauth-protected-resource-metadata conforms: true surface: successor evidence: >- https://mcp.altrata.com/.well-known/oauth-protected-resource returns HTTP 200, and the resource is advertised in the WWW-Authenticate challenge on 401 as the spec requires. - id: mcp conforms: true surface: successor evidence: >- A live remote MCP server at https://mcp.altrata.com/mcp, OAuth-protected, answering with the spec-conformant Bearer challenge. Tool list is gated. detail: mcp/wealth-x-mcp.yml - id: rfc9457-problem-details conforms: false surface: both evidence: No application/problem+json error envelope on either surface. - id: rfc8594-sunset-header conforms: false surface: both evidence: >- Deprecation is signalled in-band in the GraphQL response body (errorType `deprecated`), never as a Sunset or Deprecation HTTP header. - id: ietf-ratelimit-headers conforms: partial surface: successor evidence: >- RateLimit-Policy "500;w=60", RateLimit-Limit, RateLimit-Remaining and RateLimit-Reset observed on the MCP endpoint. The GraphQL APIs publish limits in prose only and document no response headers. method: probed - id: json-api conforms: false - id: odata conforms: false - id: pagination conforms: true surface: both evidence: >- Legacy: page/pageSize and fromIndex/toIndex/size. Successor: cursor pagination common to every GraphQL API. - id: idempotency conforms: false surface: both evidence: >- No idempotency-key contract on either surface. The Matching API's requestId is a job handle for polling, not an idempotency key. - id: webhooks conforms: false surface: both evidence: >- No event/webhook surface and no AsyncAPI. The Altrata "Events API" is a GraphQL QUERY API for corporate leadership announcements sorted by effective date — it is polled, not pushed. Bulk change is delivered out-of-band via sFTP / S3 / Snowflake / Delta Sharing. Correctly N/A for the asyncapi scoring family. - id: soc2 conforms: claimed surface: organization evidence: >- "We regularly invest in independent auditors to assess our security environment as part of our SOC2 attestation." Report available on request only; not independently verified by us. source: https://altrata.com/altratas-privacy-promise detail: security/wealth-x-trust-center.yml - id: gdpr conforms: claimed surface: organization evidence: >- Operates as a data controller relying on legitimate interests as its Article 6(1) lawful basis, with documented Legitimate Interest Assessments and Standard Contractual Clauses. source: https://altrata.com/altratas-privacy-promise - id: ccpa conforms: true surface: organization evidence: >- Independent CCPA Validation achieved, with a downloadable "Altrata Inc. CCPA Validation Findings Letter" published on the privacy promise page. source: https://altrata.com/altratas-privacy-promise - id: us-data-broker-registration conforms: true surface: organization evidence: Current data broker registrations in California, Oregon, Texas and Vermont. source: https://altrata.com/altratas-privacy-promise - id: iso-27001 conforms: false evidence: Not claimed anywhere on the Wealth-X or Altrata public surface. - id: hipaa conforms: false - id: pci-dss conforms: false - id: fedramp conforms: false