generated: '2026-07-25' method: searched source: https://github.com/adunaglobal/nv2-asp-server-java-aduna-sdk note: >- Aduna's whole product thesis is conformance: it exists to expose CAMARA-standardised network APIs from many operators through one commercial contract. The CAMARA and OAuth/OIDC assertions below are evidenced from Aduna's own source-available SDK and its release-compatibility table. Aduna publishes NO security or privacy certification (no SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP claim appears on adunaglobal.com or in its repositories), and no trust centre exists, so no Compliance pointer is emitted for this provider. standards: - id: camara-number-verification conforms: true version: v2.1 (release r3.2) evidence: >- SDK README "Aduna/Camara Release Compatibility" table binds the SDK to CAMARA Number Verification r3.2 / v2.1; Feign client declares /number-verification/v2/verify and /number-verification/v2/device-phone-number. reference: https://github.com/camaraproject/NumberVerification/blob/r3.2/code/API_definitions/number-verification.yaml - id: camara-sim-swap conforms: claimed evidence: Listed as live or in development on https://adunaglobal.com/work-with-us/availability/ ; no public artifact. reference: https://github.com/camaraproject/SimSwap - id: camara-kyc-match conforms: claimed evidence: Listed as live or in development on https://adunaglobal.com/work-with-us/availability/ ; no public artifact. - id: gsma-open-gateway conforms: aligned evidence: >- Aduna's GitHub organisation profile names GSMA Open Gateway as an ecosystem it builds upon, and all twelve CSP shareholders are Open Gateway operators. Aduna is not itself an operator and is not an Open Gateway signatory — it is the commercial aggregation channel FOR Open Gateway. - id: oauth2 conforms: true evidence: /auth/token with authorization-code, JWT-Bearer and CIBA grants; Authorization bearer tokens on all resource calls. - id: oidc conforms: true evidence: openid scope required on every Number Verification request; Auth0 OIDC provider guards the developer portal. - id: oidc-ciba conforms: true evidence: POST /auth/bc-authorize returns CibaResponse{authReqId, interval, expiresIn}; README lists CIBA as a supported SIM-based flow. - id: rfc7523-jwt-bearer conforms: true evidence: >- JWT-Bearer Token flow is the recommended SIM-based mode; the integrator publishes a JWKS URL and the SDK rotates signing keys (default P90D interval, P91D validity). - id: rfc9116-security-txt conforms: false evidence: https://adunaglobal.com/.well-known/security.txt returns 404. - id: rfc9457-problem-details conforms: false evidence: Errors use the CAMARA {status, code, message} envelope and OAuth {error, error_description}, not application/problem+json. - id: w3c-dpv-purpose-scopes conforms: true evidence: dpv:FraudPreventionAndDetection is required alongside every Number Verification API scope. - id: openapi conforms: false evidence: No OpenAPI definition is published on any Aduna host; probes of adunaglobal.com, docs.adunaglobal.com and portal.adunaglobal.com all miss. - id: asyncapi conforms: false evidence: No event, webhook or streaming contract is published; the four CAMARA subscription APIs are roadmap only. - id: tmforum-open-api conforms: false evidence: No TM Forum Open API conformance certification is claimed on adunaglobal.com or in Aduna's repositories. - id: fapi conforms: false evidence: No FAPI profile claim; the portal Auth0 tenant supports private_key_jwt and S256 PKCE but no FAPI conformance is asserted. - id: soc2 conforms: unknown evidence: No certification claim published; no trust centre found at trust.adunaglobal.com (DNS does not resolve). - id: iso-27001 conforms: unknown evidence: No certification claim published. - id: gdpr conforms: claimed evidence: >- Privacy notice at https://adunaglobal.com/privacy-notice/ and gated sub-processor pages (docs.adunaglobal.com/legal/sub-processors-and-affiliates-csp and .../-op) indicate a GDPR-shaped data-processing posture; no certification or DPA is public.