Open standards as a starting point

Our default is open standards. Deviations are justified (explain) and minimized. This accelerates integrations, reduces lock-in, and simplifies audits.

Standards we apply (selection)

API & Data

JSON/REST, OpenAPI, CSV/Parquet where relevant

Identity & Access

OIDC, SAML, OAuth 2.0, JWT

Transport & Security

TLS 1.2+, HTTPS, HSTS

Email Security

SPF, DKIM, DMARC; optional DNSSEC

Documents & Archiving

PDF/A, CSV/ODS; machine-readable exports

Network & IP

IPv6-ready where applicable

'Apply or explain' policy

• We apply open standards if they are on the list or de facto industry standards.

• We document deviations with reason, impact, and mitigation.

• Annual review in the Open Standards Register (internal reference).

Exceptions & migration

Closed formats from third parties

If a third-party system requires closed formats, we provide an export layer (mapping, conversion).

Legacy integrations

For legacy integrations, we publish a migration path with timeline.