generated: '2026-08-09' method: derived source: openapi/whoisfreaks-openapi-original.yml searched: - https://whoisfreaks.com/privacy-policy - https://whoisfreaks.com/terms - https://whoisfreaks.com/documentation/errors - https://whoisfreaks.com/documentation/api-rate-limiting standards: - id: openapi-3.0 conforms: true evidence: 'OpenAPI 3.0.3 document with 57 paths / 60 operations / 78 component schemas, published at github.com/WhoisFreaks/wf-sdks-docs/spec/whoisfreaks-openapi.yaml' - id: api-key-auth conforms: true evidence: 'components.securitySchemes.ApiKeyAuth — type apiKey, in: query, name: apiKey; applied globally' - id: oauth2 conforms: false evidence: no oauth2 security scheme in the spec and no OAuth documented - id: oidc conforms: false evidence: '/.well-known/openid-configuration returns 404 on both hosts' - id: mutual-tls conforms: false - id: rfc9457-problem-details conforms: false evidence: 'errors are a vendor JSON envelope (timestamp/status/error/message/path) served as application/json; no application/problem+json and no type URIs' - id: rfc9116-security-txt conforms: false evidence: '/.well-known/security.txt returns 404 on whoisfreaks.com and api.whoisfreaks.com' - id: rfc9727-api-catalog conforms: false evidence: '/.well-known/api-catalog returns 404 on both hosts' - id: rfc8594-sunset-header conforms: false evidence: no Sunset/Deprecation header support documented and no deprecated operations in the spec - id: rfc6585-429 conforms: true evidence: '429 Too Many Requests returned on limit exhaustion, documented at /documentation/api-rate-limiting' - id: ratelimit-headers-draft conforms: partial evidence: >- Three rate-limit headers are returned (x-ratelimit-allowed-requests, x-ratelimit-remaining-requests, x-ratelimit-remaining-time) but they use vendor names and a nanosecond reset unit rather than the IETF RateLimit/RateLimit-Policy fields. - id: idempotency-key conforms: false evidence: no Idempotency-Key header or parameter anywhere in the spec or docs - id: pagination conforms: partial evidence: 'page-number pagination via a `page` query param on five operations; field naming inconsistent (total_pages/current_page vs totalPages/currentPage); no cursor option, no Link header' - id: json-api conforms: false - id: odata conforms: false - id: scim2 conforms: false - id: fhir-r4 conforms: false - id: fapi conforms: false - id: psd2 conforms: false - id: mcp conforms: true evidence: 'official open-source MCP server exposing 14 tools over stdio and HTTP/SSE — github.com/WhoisFreaks/whoisfreaks-mcp-server; see mcp/whoisfreaks-mcp.yml' - id: a2a conforms: false evidence: 'no agent card at /.well-known/agent-card.json or /.well-known/agent.json on either host (404)' - id: llms-txt conforms: true evidence: 'https://whoisfreaks.com/llms.txt returns 200 text/plain, 173 lines, generated 2026-08-07' - id: asyncapi conforms: false evidence: 'no AsyncAPI document; webhook alerts are advertised on the Brand Monitoring product page but carry no published payload schema' - id: dnssec conforms: true evidence: 'probed — whoisfreaks.com is DNSSEC-signed (security/whoisfreaks-domain-security.yml)' - id: hsts conforms: false evidence: 'probed — no Strict-Transport-Security header on whoisfreaks.com' - id: caa conforms: false evidence: 'probed — no CAA records on whoisfreaks.com' - id: spf conforms: true evidence: probed - id: dmarc conforms: true evidence: 'probed — policy: reject' compliance: published: partial claims: - regime: GDPR claimed: true evidence: >- "GDPR Compliance" is stated in the site-wide footer and GDPR is referenced in the privacy policy; a data-redaction request workflow is operated at https://billing.whoisfreaks.com/redaction/request (200). url: https://whoisfreaks.com/privacy-policy certifications: [] note: >- No third-party certification is published — SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP and CSA STAR appear nowhere on the site, and no trust center exists (trust.whoisfreaks.com does not resolve). GDPR is a self-asserted compliance claim backed by an operating redaction process, not an audit.