generated: '2026-09-07' method: searched source: >- https://documentation.adaptive.live/ (the 295-page corpus), the live probes recorded in well-known/ and mcp/, and https://adaptive.live/security for the compliance claim. Nothing here is derived from a spec — Adaptive publishes no OpenAPI. description: >- Which cross-cutting and domain standards the Adaptive contract and platform actually conform to, each with evidence. Both directions are recorded: the standards Adaptive genuinely implements (OAuth 2.0 with RFC 7591 dynamic client registration, MCP, Prometheus exposition, SAML/OIDC federation, syslog export) and the ones its API conspicuously does NOT (RFC 9457 problem details, RFC 8594 sunset headers, RFC 9116 security.txt, RFC 8615 well-known discovery). A false is as much a finding as a true. conformance: - id: oauth2 name: OAuth 2.0 conforms: true scope: MCP server authorization evidence: >- https://documentation.adaptive.live/platform/organization/mcp-servers — "secured by OAuth so every agent acts as the signed-in user"; a browser consent screen issues the token, with selectable scopes and a configurable TTL, and per-token revocation. - id: rfc7591 name: 'RFC 7591 — OAuth 2.0 Dynamic Client Registration' conforms: true scope: MCP client onboarding evidence: >- https://documentation.adaptive.live/platform/organization/mcp-servers — "Registration follows RFC 7591 Dynamic Client Registration, so compliant clients register themselves automatically." The tab exposes Issuer, Authorization, Token and Registration endpoints. - id: rfc8414 name: 'RFC 8414 / RFC 9728 — Authorization Server and Protected Resource Metadata' conforms: false scope: anonymous discovery of the MCP authorization endpoints evidence: >- Probed 2026-09-07: /.well-known/oauth-authorization-server and /.well-known/oauth-protected-resource returned 404 on adaptive.live, www.adaptive.live, documentation.adaptive.live, docs.adaptive.live and cli.adaptive.live, and an HTML SPA soft-404 (HTTP 200, text/html) on app.adaptive.live. The endpoint URLs are published only inside the authenticated MCP Servers tab, so an MCP client cannot discover them without already being signed in. This is the single highest-leverage gap in Adaptive's agent posture: it implements the hard part (OAuth + DCR) and omits the two static JSON documents that would make it self-configuring. - id: mcp name: Model Context Protocol conforms: true scope: built-in remote MCP server evidence: >- https://documentation.adaptive.live/platform/organization/mcp-servers documents a standard mcpServers client configuration block and named client support (Claude, Cursor, VS Code). POST to https://app.adaptive.live/api/v3/client/mcp returned HTTP 401 JSON on 2026-09-07 — a live, auth-gated MCP endpoint. Protocol VERSION is not stated in the docs and tools/list is gated, so no revision is asserted. - id: rfc9457 name: 'RFC 9457 — Problem Details for HTTP APIs' conforms: false scope: Client API error envelope evidence: >- Errors are application/json objects of the shape {"error":""} with no type, title, status, detail or instance member and no application/problem+json media type. Observed live across all sixteen paths on 2026-09-07. - id: rfc8594 name: 'RFC 8594 — The Sunset HTTP Header Field' conforms: false scope: deprecation signalling evidence: >- No Sunset or Deprecation header is documented and no deprecation policy is published. See lifecycle/adaptive-automation-technologies-lifecycle.yml. - id: rfc9116 name: 'RFC 9116 — security.txt' conforms: false scope: vulnerability disclosure discovery evidence: >- /.well-known/security.txt returned 404 on every Adaptive host probed on 2026-09-07 (SPA soft-404 on app.adaptive.live). No bug bounty or disclosure page was found either. - id: rfc8615 name: 'RFC 8615 — Well-Known URIs' conforms: false scope: machine discovery evidence: >- Nine named /.well-known/ paths probed across six hosts; zero documents served. See well-known/adaptive-automation-technologies-well-known.yml. - id: pagination name: Paginated collection responses conforms: false scope: the nine list operations evidence: >- Every list operation returns a bare unbounded JSON array — no limit, cursor, offset, page or has_more field is documented. See conventions/. - id: idempotency name: Idempotent write requests conforms: false scope: the six POST operations evidence: >- No Idempotency-Key header or client request id is documented anywhere in the reference. See conventions/adaptive-automation-technologies-conventions.yml (coverage: none). - id: prometheus-exposition name: Prometheus / OpenMetrics exposition format conforms: true scope: platform observability evidence: >- https://documentation.adaptive.live/platform/observability — metrics are exposed at /metrics on the deployment URL with a documented scrape_config and a named metric catalog (adaptive_endpoint_created, adaptive_endpoint_resume_failure, …). Note the endpoint is per-deployment: https://app.adaptive.live/metrics returned the SPA shell on 2026-09-07, so it is not exposed anonymously on the shared managed-cloud host. - id: saml-oidc-federation name: SAML 2.0 and OpenID Connect federation conforms: true scope: workforce identity for platform sign-in (relying party) evidence: >- Adaptive records authMethod values of password_mfa / saml / oidc / oauth on every admin login (https://documentation.adaptive.live/platform/access-management/admin-lock) and documents SSO integrations for Okta, Azure Active Directory, Google, JumpCloud, OneLogin and LDAP. - id: scim name: 'SCIM (RFC 7643 / 7644) — cross-domain identity provisioning' conforms: false scope: user and group provisioning evidence: >- Searched the full documentation corpus for "SCIM" on 2026-09-07: zero occurrences. Adaptive syncs directories through provider-specific paths instead (diff-based Azure AD SSO sync, LDAP), and the Team object carries syncId / ssoProviderId fields populated by that sync. This is the notable domain-standard MISS for an identity and access product: a buyer already speaking SCIM needs a bespoke connector here. - id: syslog name: Syslog event forwarding conforms: true scope: audit and session event export evidence: >- https://documentation.adaptive.live/integrations/syslog, with TLS-encrypted syslog added in release v1.1.8. No syslog RFC (3164 vs 5424) is named in the docs, so no specific revision is claimed. domain_standards: market: privileged access management / identity and data security assessment: >- Adaptive's market has no single dominant machine-readable interop standard the way SCIM covers provisioning or FHIR covers health data, and this is a reward-only dimension, so nothing is invented to fill it. The two standards that genuinely apply here are SCIM (identity provisioning — NOT implemented, recorded above as a real miss) and MCP (the emerging standard for agent-callable surfaces — implemented, and implemented well: OAuth-secured, scope-capped at the user's own role, and fully audited). Adaptive's strongest domain-standard signature is therefore MCP rather than anything in the traditional IAM stack. signature: mcp signature_evidence: >- A built-in MCP server with RFC 7591 dynamic client registration, a published mcpServers client configuration block, and a live auth-gated endpoint verified at https://app.adaptive.live/api/v3/client/mcp (HTTP 401, 2026-09-07). compliance_certifications: - name: SOC 2 Type II body: AICPA auditor: Prescient Assurance status: completed evidence: https://adaptive.live/security detail: security/adaptive-automation-technologies-trust-center.yml compliance_note: >- SOC 2 Type II is Adaptive's ONLY published attestation about itself. Adaptive's product separately helps CUSTOMERS score their own posture against SOC 2, ISO 27001, HIPAA, PCI-DSS and GDPR control sets (https://documentation.adaptive.live/platform/compliance) — those are product features and are deliberately NOT counted as Adaptive's certifications. The words HIPAA, GDPR and CSA STAR also appear on https://adaptive.live/security, but only inside the description of the auditor's other service lines. security_practices_published: - Third-party penetration testing and vulnerability scanning of all production and internet-facing systems - Static and dynamic application security testing including open-source libraries - Secure development lifecycle aligned to OWASP Top 10, with annual secure-coding training - Background checks and NDAs for all employees and contractors - Per-customer trust-zone isolation with unique encryption keys; encryption at rest and in transit