generated: '2026-08-06' method: searched source: https://alice.io/llms.txt + https://alice.io/ + openapi/activefence-alice-api-openapi.yml summary: >- Alice (formerly ActiveFence) publishes two audited security certifications and claims alignment with a set of AI-governance frameworks that are the subject matter of its own products. The cross-cutting API standards picture is thin: OpenAPI 3.0.0 and TLS are the only technical standards the surface conforms to. No OAuth, no OIDC, no RFC 9457, no RFC 8594, no RFC 9116 security.txt, no RFC 8615 well-known documents. certifications: - id: soc2 name: SOC 2 status: certified detail: SOC 2 Type II evidence: - {source: 'https://alice.io/', kind: certification-badge, alt_text: 'SOC 2 Certified security compliance badge'} - {source: 'https://alice.io/llms.txt', kind: first-party-statement, quote: 'Alice is SOC 2 certified and ISO 27001 certified.'} - id: iso-27001 name: ISO/IEC 27001 status: certified detail: Information security management evidence: - {source: 'https://alice.io/', kind: certification-badge, alt_text: 'ISO 27001 Information Security certification badge'} - {source: 'https://alice.io/llms.txt', kind: first-party-statement, quote: 'Alice is SOC 2 certified and ISO 27001 certified.'} compliance_report_access: >- No trust center, no self-serve compliance portal, and no security page were found. trust.alice.io and security.alice.io do not resolve; alice.io/security, /trust and /compliance all return 404. Obtaining the SOC 2 report or ISO certificate appears to require contacting the company. frameworks_referenced: note: >- Alice states its content and product materials reference alignment with these frameworks. This is a stated alignment for a product that helps customers meet the frameworks — it is NOT an audited certification of Alice against them, and is recorded as such. source: https://alice.io/llms.txt frameworks: - {id: eu-ai-act, name: EU AI Act, relationship: product-alignment} - {id: iso-42001, name: ISO/IEC 42001, relationship: product-alignment} - {id: nist-ai-rmf, name: NIST AI Risk Management Framework, relationship: product-alignment} - {id: owasp-llm-top-10, name: OWASP Top 10 for LLM Applications, relationship: product-alignment} - {id: mitre-atlas, name: MITRE ATLAS, relationship: product-alignment} regulatory_domains_served: source: https://alice.io/llms.txt domains: [child-safety, financial-services, healthcare, insurance] note: >- Alice sells into HIPAA-scoped clinical workloads and regulated financial-services AI. It publishes no HIPAA BAA availability, PCI DSS, FedRAMP or GDPR certification page. standards: - id: openapi-3.0 conforms: true evidence: OpenAPI 3.0.0 document served at https://docs.activefence.com/openapi.json, 18 operations, 17 paths - id: tls-1.3 conforms: true evidence: 'api.alice.io, alice.io and docs.activefence.com all negotiate TLSv1.3 (security/activefence-domain-security.yml)' - id: rest conforms: true evidence: 'info.description: "All APIs use a standard REST design"' - id: api-key-auth conforms: true evidence: 'components.securitySchemes."API Key" — apiKey in header, name af-api-key' - id: oauth2 conforms: false evidence: no oauth2 securityScheme in the spec and no OAuth documentation - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on api.alice.io, alice.io and app.alice.io - id: rfc9457-problem-details conforms: false evidence: errors use application/json with a vendor {statusCode,error,message,params} envelope, not application/problem+json - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on every host probed - id: rfc8615-well-known conforms: false evidence: no /.well-known/ document is served on any host (well-known/activefence-well-known.yml) - id: rfc8594-sunset-header conforms: false evidence: no deprecation policy or Sunset/Deprecation header support documented - id: asyncapi conforms: false evidence: >- A real event surface exists (async callbacks + action webhooks) but no AsyncAPI document is published. Captured as a webhook catalog instead — asyncapi/activefence-webhooks.yml - id: a2a-agent-card conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json miss on every host - id: mcp conforms: false evidence: no hosted MCP server found; mcp.alice.io NXDOMAIN, api.alice.io/mcp 404 - id: llms-txt conforms: true evidence: https://alice.io/llms.txt returns 200 text/plain, 13,980 bytes, well-formed llms.txt structure - id: pagination conforms: false evidence: no pagination parameters on any collection-returning operation - id: idempotency conforms: false evidence: zero matches for /idempoten/i across the 120KB OpenAPI document