generated: '2026-08-29' method: probed source: >- openapi/aarons-hpp-openapi.json + live probes of https://www.aarons.com/s/Aarons/dw/shop/v21_3/, https://login.aarons.com/.well-known/openid-configuration and https://api.aarons.com provider: Aaron's providerId: aarons summary: >- Aaron's publishes no conformance or compliance claims of its own. Everything asserted below was read out of a contract or a live response, never out of a marketing page. Two real standards conformances are demonstrable: OpenID Connect / OAuth 2.0 on the identity host, and Salesforce B2C Commerce OCAPI 21.3 on the storefront. No compliance certification (SOC 2, ISO 27001, PCI-DSS attestation) is published anywhere on the estate, so no Compliance pointer is emitted. conformance: - id: oauth2 label: OAuth 2.0 (RFC 6749) + RFC 8414 authorization-server metadata conforms: true evidence: - url: https://login.aarons.com/.well-known/oauth-authorization-server status: 200 note: RFC 8414 metadata document served anonymously. - file: well-known/aarons-login-oauth-authorization-server.json - id: oidc label: OpenID Connect Discovery 1.0 conforms: true evidence: - url: https://login.aarons.com/.well-known/openid-configuration status: 200 - url: https://login.aarons.com/oauth2/default/.well-known/openid-configuration status: 200 note: Custom authorization server used by the myaccount.aarons.com application. - id: pkce label: PKCE (RFC 7636) conforms: true evidence: - detail: 'code_challenge_methods_supported: ["S256"] in both discovery documents.' - id: ocapi label: Salesforce B2C Commerce Open Commerce API (OCAPI) 21.3 — Shop API conforms: true domain_standard: true market: retail / digital commerce evidence: - url: https://www.aarons.com/s/Aarons/dw/shop/v21_3/site status: 400 body: '{"_v":"21.3","fault":{"type":"MissingClientIdException","message":"The client ID is missing."}}' detail: >- The response is a well-formed OCAPI fault document that echoes the contract version in `_v` and names an OCAPI exception class. That is the OCAPI signature, returned by Aaron's own host. The surface is live and standards-shaped; it is gated on a client ID that Aaron's does not issue publicly. - url: https://www.aarons.com/robots.txt status: 200 detail: >- Independently corroborates the platform — robots.txt disallows /on/demandware.store/Sites-Aarons-Site/default/GiftCert-Purchase, a Demandware (Salesforce B2C Commerce) pipeline URL. note: >- This is a REWARD-ONLY observation about the market standard Aaron's retail surface speaks. Aaron's did not author OCAPI; it deploys it. A buyer who already speaks OCAPI needs no bespoke connector to Aaron's storefront — they need a client ID. - id: card-network-verification-semantics label: Card-network address/card verification semantics (AVS, CVV2, BIN, zero-dollar auth) conforms: true domain_standard: true market: payments evidence: - file: openapi/aarons-hpp-openapi.json detail: >- definitions.AVS declares StreetMatch, PostalCodeMatch and AssociationAvsResponse; definitions.ZeroDollarAuth declares CVV2 + AVS; definitions.Card declares BIN, Brand, Last4, Masked, Token and Exp. These are card-network verification primitives carried verbatim in Aaron's own published contract. note: >- Recorded as a domain-standard signature in the contract, not as a certification. Aaron's makes no PCI-DSS claim anywhere public and none is asserted here on its behalf. - id: rfc9457 label: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: - file: openapi/aarons-hpp-openapi.json detail: >- No application/problem+json anywhere; the error envelope is ServiceStack ResponseStatus. The contract declares no 4xx/5xx responses at all. - id: idempotency label: Idempotency keys on unsafe operations conforms: false evidence: - file: openapi/aarons-hpp-openapi.json detail: >- No Idempotency-Key header, no idempotency parameter, and no documented replay semantics on any of the 15 paths — including the payment-authorization and tokenization operations. - id: pagination label: Collection pagination conforms: na evidence: - detail: The published contract exposes no collection/list operations, so pagination does not apply. - id: pci-dss label: PCI-DSS attestation conforms: unknown evidence: - url: https://www.aarons.com/.well-known/security.txt status: 404 - detail: >- No trust centre, no compliance page, no certification list found on any Aaron's host. Aaron's handles card data (BIN/Last4/token/CVV2 appear in its own contract) so PCI-DSS almost certainly applies to it — but nothing is published, so nothing is asserted. compliance_certifications_published: [] maintainers: - FN: Kin Lane email: kin@apievangelist.com