generated: '2026-08-13' method: searched source: openapi/youscan-openapi.yaml + developers.youscan.io docs + https://trust.youscan.io/ summary: >- Cross-cutting standards conformance for the YouScan API, derived from its OpenAPI 3.1 spec and documented behavior. YouScan is a plain REST + API-key data API; it does not implement OAuth/OIDC or domain profiles (FHIR/FAPI/SCIM/OData/PSD2). standards: - id: openapi-3.1 conforms: true evidence: Official machine-readable OpenAPI 3.1.0 spec published at developers.youscan.io/api/openapi.yaml. - id: oauth2 conforms: false evidence: Authentication is API-key only (X-API-KEY header or apiKey query param); no OAuth2 flows declared. - id: oidc conforms: false evidence: No OpenID Connect / openid-configuration endpoint (developers host is an SPA catch-all). - id: rfc9457 conforms: false evidence: Errors use a custom {errorCode, message, errors[]} JSON envelope, not application/problem+json. - id: rfc8594-deprecation conforms: false evidence: No Sunset/Deprecation headers documented; changes are communicated via the docs Version history. - id: pagination conforms: true evidence: Mention listing supports paginated retrieval (size/from-style parameters and continuation over large result sets). - id: idempotency conforms: false evidence: No Idempotency-Key header or idempotent-retry semantics documented. - id: webhooks conforms: true evidence: Outbound mention webhooks documented and modeled in the OpenAPI spec (Webhook tag, WebhookMention schema). - id: json-api conforms: false evidence: Responses are plain JSON, not JSON:API media type or envelope. - id: fhir conforms: false evidence: Not a healthcare API. - id: fapi conforms: false evidence: Not a financial-grade API; no OAuth/FAPI security profile. - id: scim conforms: false evidence: No SCIM user/group provisioning surface. - id: odata conforms: false evidence: No OData query conventions. - id: rfc9331-ratelimit-headers conforms: false evidence: >- Limits are published as prose guidance (5 parallel, 10 requests / 10 s) but no RateLimit-* or Retry-After header is documented, and none was observed on a live response. See rate-limits/youscan-rate-limits.yml. - id: soc2-type2 conforms: true evidence: SOC 2 Type 2 named on the public SafeBase trust center at https://trust.youscan.io/ (report gated behind an access request). - id: iso-27001 conforms: true evidence: ISO/IEC 27001:2022 certification named on https://trust.youscan.io/. - id: gdpr conforms: true evidence: >- GDPR listed under Certificates on https://trust.youscan.io/; a GDPR request form is published at https://youscan.io/gdpr-request/ and an Author Privacy Policy is maintained separately from the customer privacy policy. - id: pci-dss conforms: false evidence: Not named on the trust center; card payments are handled by Stripe, not YouScan. - id: hipaa conforms: false evidence: Not a healthcare API; not named on the trust center. - id: fedramp conforms: false evidence: Not named on the trust center. compliance: published: true source: https://trust.youscan.io/ ref: security/youscan-trust-center.yml certifications: - SOC 2 Type 2 - ISO/IEC 27001:2022 - GDPR