generated: '2026-09-04' method: searched source: >- Aflac Enterprise Connect developer portal, https://docs.enterprise-connect.aflac.com — read from its public content index /assets/ng-doc/indexes.json (HTTP 200, application/json, 3,007,250 bytes, 7,160 indexed content sections, fetched 2026-09-04). Every claim below is either quoted from that index or backed by a probe recorded in this repository. Negative findings are term counts across the same index. docs: https://docs.enterprise-connect.aflac.com/docs/platform-overview/architecture/architecture-overview provider: aflac regime: insurance conformance: - id: oauth2 conforms: true evidence: >- "OAuth 2.0 is the only supported method for authenticating requests to AEC." Client-credentials grant, Bearer prefix on the Authorization header, client authentication sent as a Basic auth header. https://docs.enterprise-connect.aflac.com/docs/developer-guide/how-to-guides/how-to-make-a-request-to-aec-using-postman - id: openapi conforms: true evidence: >- OpenAPI is the mandatory deployment contract for every AEC service — AWS API Gateway is configured from the spec, unreferenced components fail CI, and an IC4E architect must approve the spec before the first deploy. info.title + info.version form the application identity and the HTTP path. https://docs.enterprise-connect.aflac.com/docs/developer-guide/app-team-controls/openapi-specification note: >- Aflac mandates OpenAPI internally but does not publish the resulting documents anonymously — the Swagger console is behind PingIdentity login. - id: pagination conforms: true evidence: >- A published, uniform page-number scheme carried in metadata.pagination-info with fields page-number, page-size, total-item-count, has-more-pages and last-item-id. https://docs.enterprise-connect.aflac.com/docs/developer-guide/enterprise-data-structures/v2020/support-libraries/api-specific/non-eds-api-specific-models/pagination-info - id: mutual-tls conforms: partial evidence: >- mTLS is supported for egress to third parties that enforce it, with certificates managed through Venafi and injected into service keystores; it is explicitly NOT required for calls INTO AEC ("in AEC, you no longer need to use Mutual TLS (mTLS) to make requests to the running service"). https://docs.enterprise-connect.aflac.com/docs/developer-guide/how-to-guides/how-to-use-certificates - id: oidc conforms: partial evidence: >- PingIdentity is the identity provider for the portal and its environments, and an `aflac-openid-token` request header is documented alongside the OAuth 2.0 header on the a-cipher service. No OpenID Provider metadata document is served anonymously: probes of /.well-known/openid-configuration on every known host returned 403, 404 or an SPA shell — see well-known/aflac-well-known.yml. - id: rfc9457 conforms: false evidence: >- Zero occurrences of "RFC 9457" or "problem+json" in the portal index. AEC uses its own general-response envelope with metadata.descriptions[] instead. See errors/aflac-problem-types.yml. - id: idempotency conforms: false evidence: >- Zero occurrences of "idempoten" across 7,160 indexed content sections (checked 2026-09-04). No idempotency key, no request de-duplication, no retry-safety guidance on the REST surface. - id: rfc8594 conforms: false evidence: >- No Sunset or Deprecation response headers and no time-bound deprecation policy are published; deprecation is marked in place on individual EDS fields. See lifecycle/aflac-lifecycle.yml. - id: json-api conforms: false evidence: Zero occurrences of "json:api" in the portal index; AEC defines its own envelope. - id: odata conforms: false evidence: Zero occurrences of "odata" in the portal index. - id: scim conforms: false evidence: Zero occurrences of "scim" or a urn:ietf:params:scim schema URN in the portal index. - id: asyncapi conforms: false evidence: >- Zero occurrences of "asyncapi" in the portal index. An event platform DOES exist — AES (Aflac Enterprise Stream) on Kafka/AWS MSK, with four named retry strategies — but no AsyncAPI document is published for it. - id: cloudevents conforms: false evidence: Zero occurrences of "cloudevents" in the portal index despite a Kafka event platform. domain_standard: declared: false regime: insurance probed: - standard: acord occurrences: 0 - standard: acord-al3 occurrences: 0 - standard: acord-xml occurrences: 0 - standard: ngds occurrences: 0 - standard: grlc occurrences: 0 - standard: cieca-bms occurrences: 0 - standard: csio occurrences: 0 - standard: market-reform-contract occurrences: 0 - standard: x12 / EDI 834 occurrences: 0 - standard: hl7 / fhir occurrences: 0 finding: >- Aflac declares NO industry data standard in its contract layer. It ships something unusual instead: a complete, publicly documented PROPRIETARY canonical model — EDS (Enterprise Data Structures) v2020, ~90 canonicals across 20 libraries — that is mandatory across every API layer and governs what a REST collection may even be named. That is real interoperability discipline, but it is Aflac-internal, so a partner who already speaks ACORD still needs a bilateral mapping. Recorded as a fact, not scored as a domain-standard conformance: domain_standard_conformance is reward-only and nothing here earns it. see: data-model/aflac-data-model.yml compliance_certifications: published: false probed: - term: SOC 2 occurrences: 0 - term: ISO 27001 occurrences: 0 - term: PCI occurrences: 0 - term: HIPAA occurrences: 0 - term: FedRAMP occurrences: 0 note: >- No trust center, certification list or compliance attestation is reachable on the developer portal or via probe (probe-security-programs.py returned vdp=none trust=none, 2026-09-04). No Compliance pointer is wired, because there is nothing published to point at.