generated: '2026-08-13' method: searched source: >- openapi/ + https://www.wunderkind.co/privacy/ + https://developer.wunderkind.co + https://www.wunderkind.co/blog/article/wunderkinds-commitment-to-privacy-compliance/ + https://www.wunderkind.co/blog/article/soc-2-attestation/ notes: >- Technical/protocol standards below are derived from the harvested OpenAPI and live probes. The security and privacy compliance entries added 2026-08-13 are searched from Wunderkind's own first-party statements on wunderkind.co; the Vanta trust center itself is not machine-readable (its GraphQL backend requires a signed request). See security/wunderkind-trust-center.yml. standards: - id: oauth2 conforms: false evidence: No oauth2 securitySchemes in any harvested spec; auth is API keys, header pairs, and Bearer JWT. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404/500 on all hosts. - id: rfc9457-problem-details conforms: false evidence: No application/problem+json; per-API ad hoc error envelopes (see errors/wunderkind-problem-types.yml). - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt not published on any probed host. - id: rfc8594-sunset conforms: false evidence: No Sunset/Deprecation header support documented. - id: json-api conforms: false evidence: Plain JSON bodies; no JSON:API media type. - id: grpc-transcoding conforms: true evidence: >- Event Ingestion OpenAPI is grpc-gateway generated (protobufAny, rpcStatus components, Service_* operationIds), i.e. gRPC services transcoded to REST. - id: e164-phone-numbers conforms: true evidence: Text Message API requires E.164 formatted phone numbers. - id: sha256-hashed-identifiers conforms: true evidence: >- Identity surfaces exchange SHA-256 email hashes (Identity API responses, Signals webhook RecipientSha256 field, lowercased before hashing). - id: gdpr conforms: claimed evidence: GDPR addressed in the Wunderkind privacy policy (https://www.wunderkind.co/privacy/). - id: soc2-type2 conforms: claimed evidence: >- Wunderkind announces an AICPA SOC 2 Type 2 attestation for security and confidentiality, audited by A-LIGN, and states the certification was renewed in 2024 (https://www.wunderkind.co/blog/article/soc-2-attestation/). A trust center exists at https://trust.wunderkind.co/ (Vanta) but its report list is not machine-readable. - id: iso-27001 conforms: claimed evidence: >- "renewed both our SOC2 and ISO 27001 certifications" — Wunderkind, 2024 (https://www.wunderkind.co/blog/article/wunderkinds-commitment-to-privacy-compliance/). - id: ccpa conforms: claimed evidence: >- CCPA and similar US state privacy laws addressed in the Wunderkind privacy compliance post and privacy policy. - id: rfc9116-security-txt-recheck conforms: false evidence: >- Re-probed 2026-08-13 across www/developer/api/api.wknd.ai hosts; no /.well-known/security.txt served (404/500/503). See well-known/wunderkind-well-known.yml. - id: a2a-agent-card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json probed on every host 2026-08-13; no AgentCard served (platform.wunderkind.co returns an SPA HTML shell with HTTP 200 for every path and is not a document). - id: pagination conforms: not-applicable evidence: No list endpoints on the externally documented surface. - id: idempotency conforms: false evidence: No idempotency-key contract documented.