generated: '2026-08-13' method: probed source: >- https://www.actively.ai/security (compliance claims) + live OAuth/MCP discovery probes of api.actively.ai and auth.actively.ai description: >- Industry and cross-cutting conformance posture for Actively AI. The organizational compliance claims are asserted from the company security page; the protocol-level conformance below is asserted from LIVE anonymous probes of the discovery documents fronting Actively's hosted MCP server, not from marketing copy. Actively publishes no OpenAPI, so REST-shaped conformance (rfc9457, pagination, idempotency, json:api) cannot be asserted either way. standards: # --- Organizational compliance (from the published security page) --- - id: soc2-type-ii name: SOC 2 Type II conforms: true evidence: >- "Actively's SOC 2 Type II report covers the Security trust services category, and is audited annually." Report available on request. source: https://www.actively.ai/security - id: iso-27001 name: ISO 27001 conforms: true scope: data-center evidence: >- Referenced as a compliance standard for the underlying data center facilities (Google Cloud), not as an Actively corporate certification. source: https://www.actively.ai/security - id: hitrust name: HITRUST conforms: true scope: data-center evidence: >- Listed alongside ISO 27001 as a compliance standard met by the Google Cloud data center facilities hosting Actively's data. source: https://www.actively.ai/security - id: gdpr name: GDPR conforms: true evidence: >- "We comply with GDPR data retention requirements, and offer a data processing agreement (DPA) for customers in the EU." source: https://www.actively.ai/security - id: ccpa name: CCPA conforms: true evidence: >- "We ensure policies, processes, and controls comply with CCPA requirements." source: https://www.actively.ai/security # --- Protocol conformance (probed 2026-08-13) --- - id: oauth2 name: OAuth 2.0 / 2.1 Authorization Code + PKCE conforms: true evidence: >- auth.actively.ai publishes authorization_endpoint, token_endpoint, jwks_uri, grant_types_supported [authorization_code, refresh_token, device_code] and code_challenge_methods_supported ["S256"]. The MCP resource returns a Bearer challenge on unauthenticated POST. source: https://auth.actively.ai/.well-known/oauth-authorization-server probed: '2026-08-13' - id: rfc8414 name: 'RFC 8414: OAuth 2.0 Authorization Server Metadata' conforms: true evidence: >- Served at /.well-known/oauth-authorization-server on BOTH auth.actively.ai (HTTP 200, full document) and api.actively.ai (HTTP 200, MCP-client subset). source: https://auth.actively.ai/.well-known/oauth-authorization-server probed: '2026-08-13' - id: rfc9728 name: 'RFC 9728: OAuth 2.0 Protected Resource Metadata' conforms: true evidence: >- api.actively.ai serves /.well-known/oauth-protected-resource and the resource-scoped /.well-known/oauth-protected-resource/mcp (both HTTP 200), and the 401 WWW-Authenticate header carries the matching resource_metadata parameter. source: https://api.actively.ai/.well-known/oauth-protected-resource probed: '2026-08-13' - id: rfc7591 name: 'RFC 7591: OAuth 2.0 Dynamic Client Registration' conforms: true evidence: >- registration_endpoint https://auth.actively.ai/oauth2/register is advertised, with client_id_metadata_document_supported true — an MCP client can self-register with no prior contact. source: https://auth.actively.ai/.well-known/oauth-authorization-server probed: '2026-08-13' - id: rfc7636 name: 'RFC 7636: PKCE' conforms: true evidence: 'code_challenge_methods_supported: ["S256"] (plain not offered).' source: https://auth.actively.ai/.well-known/oauth-authorization-server probed: '2026-08-13' - id: rfc8628 name: 'RFC 8628: OAuth 2.0 Device Authorization Grant' conforms: true evidence: >- device_authorization_endpoint https://auth.actively.ai/oauth2/device_authorization advertised, and the device_code grant type is listed. source: https://auth.actively.ai/.well-known/oauth-authorization-server probed: '2026-08-13' - id: oidc name: OpenID Connect Core / Discovery conforms: true evidence: >- Full /.well-known/openid-configuration at auth.actively.ai (HTTP 200) with issuer, userinfo_endpoint, RS256 id_token signing, subject_types public. source: https://auth.actively.ai/.well-known/openid-configuration probed: '2026-08-13' - id: mcp-authorization name: MCP Authorization (spec revision 2025-06-18) conforms: true evidence: >- The complete chain required by the MCP authorization spec is present and anonymously resolvable: 401 + WWW-Authenticate naming resource_metadata -> RFC 9728 protected-resource document -> RFC 8414 authorization-server document -> RFC 7591 registration + PKCE. An MCP client can bootstrap from a cold start. source: https://api.actively.ai/mcp probed: '2026-08-13' - id: rfc9116 name: 'RFC 9116: security.txt' conforms: false evidence: >- /.well-known/security.txt returns 404 on www.actively.ai, api.actively.ai and auth.actively.ai, even though a written responsible-disclosure policy and a security@actively.ai contact exist. source: https://www.actively.ai/.well-known/security.txt probed: '2026-08-13' - id: a2a name: A2A Agent Card conforms: false evidence: >- No /.well-known/agent-card.json and no legacy /.well-known/agent.json on any of the four probed hosts (www, app, api, auth). probed: '2026-08-13' not_assessed: - id: rfc9457 reason: >- No public OpenAPI and no reachable REST surface, so the error-envelope format cannot be assessed. The two error shapes observed anonymously are ad-hoc JSON ({"detail":"Not Found"} and the OAuth-style {"error","error_description"}), neither of which is problem+json. - id: pagination reason: No public REST contract to inspect. - id: idempotency reason: No public REST contract or documented write semantics to inspect. - id: fhir reason: Not applicable — go-to-market revenue intelligence, not healthcare. - id: psd2 reason: Not applicable — not a financial services provider.