generated: '2026-08-06' method: probed source: well-known/, security/aera-technology-trust-center.yml, live probes scope_note: >- Assertions cover only the publicly observable surface — Aera's MCP authorization metadata and its published compliance posture. The Aera Decision Cloud product API is behind a customer SSO login, so no claim is made about the product API's conformance in either direction. standards: - id: oauth2 conforms: true evidence: >- /.well-known/oauth-authorization-server advertises authorization_code + refresh_token grants with authorization, token and revocation endpoints - id: rfc8414-authorization-server-metadata conforms: true evidence: 200 JSON at /.well-known/oauth-authorization-server (control path 404s) - id: rfc9728-protected-resource-metadata conforms: true evidence: 200 JSON at /.well-known/oauth-protected-resource naming the MCP resource - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported = [S256] - id: oauth2.1-public-client conforms: true evidence: token_endpoint_auth_methods_supported = [none] with mandatory PKCE - id: rfc7009-token-revocation conforms: true evidence: revocation_endpoint published in authorization-server metadata - id: oauth-client-id-metadata-document conforms: true evidence: client_id_metadata_document_supported = true - id: mcp conforms: true evidence: >- JSON-RPC MCP endpoint at /wp-json/mcp/mcp-oauth-server responding with the MCP error envelope; tool set auth-gated (401) - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog returns 404 - id: a2a conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json both 404 - id: openid-connect-discovery conforms: false evidence: /.well-known/openid-configuration returns 404 on www; 403 on idp host - id: rfc9457-problem-details conforms: false evidence: >- errors are the WordPress REST envelope {code,message,data.status} as application/json, not application/problem+json - id: iso-27001 conforms: true evidence: 'trustcenter.aeratechnology.com lists "ISO 27001 Certified"' - id: soc2-type2 conforms: true evidence: 'trustcenter.aeratechnology.com lists "SOC 2 Certified" + a 2026 SOC 2 Type 2 Report' - id: iso-42001 conforms: true evidence: 'trustcenter.aeratechnology.com lists "ISO 42001 Certified"' - id: gdpr conforms: true evidence: 'trustcenter.aeratechnology.com lists "GDPR Compliant"' - id: ccpa-cpra conforms: true evidence: 'trustcenter.aeratechnology.com lists "CPRA (formerly CCPA) Compliant"' - id: nist-csf conforms: null evidence: >- aera-security-privacy-documentation claims practices "consistent with" ISO 27001 and the NIST Cybersecurity Framework — an alignment claim, not a certification - id: hipaa conforms: false evidence: not listed on the trust center - id: pci-dss conforms: false evidence: not listed on the trust center - id: fedramp conforms: false evidence: not listed on the trust center x-evidence: fetched: '2026-08-06'