Security
API Security Standards for FACTS Integrations
Office of the U.S. Global AIDS Coordinator and Health Diplomacy, U.S. Department of State
Effective Date
Changes take effect October 1, 2026. Development and pre-production environments should adopt the standards during July–September.
Requirements
- TLS 1.2+ only; prefer TLS 1.3
- OAuth 2.0 client credentials with 90-day maximum token lifetime
- Structured audit logs retained ≥ 1 year
- IP allowlisting for production callbacks
Questions may be routed through the Contact support channel with subject line API-SEC-2026.
Who must comply
Agency and partner engineering teams integrating systems with FACTS Info APIs, including token-based machine interfaces.
Required controls (summary)
- TLS for all external connections
- Documented token rotation and secret storage
- Audit logging of API calls that touch program data
Effective guidance
Treat this update as the current baseline for new integrations. Existing connections should schedule remediation with your information-security package owners.