generated: '2026-09-14' method: probed source: >- Live discovery documents saved under well-known/ (fetched 2026-09-14), the 401 challenge returned by https://mcp.aidentified.com/mcp, the Terms & Conditions at https://www.aidentified.com/terms-conditions, and the Vanta-hosted trust center at https://trust.aidentified.com. summary: >- Aidentified's conformance is concentrated entirely in its identity and agent layer, which is standards-correct and independently verifiable. Everything else — the REST contract, errors, events, pagination — conforms to nothing published. conformance: - id: oauth2 name: OAuth 2.0 / 2.1 authorization code with PKCE conforms: true evidence: https://login.aidentified.com/.well-known/oauth-authorization-server detail: >- code_challenge_methods_supported is ["S256"] and response_types_supported includes "code". PKCE is the only challenge method offered. - id: rfc8414 name: 'RFC 8414: OAuth 2.0 Authorization Server Metadata' conforms: true evidence: https://login.aidentified.com/.well-known/oauth-authorization-server detail: HTTP 200, application/json, issuer/token_endpoint/jwks_uri all present. - id: rfc9728 name: 'RFC 9728: OAuth 2.0 Protected Resource Metadata' conforms: true evidence: https://mcp.aidentified.com/.well-known/oauth-protected-resource/mcp detail: >- HTTP 200 carrying resource, authorization_servers and bearer_methods_supported, and the MCP server's 401 emits a WWW-Authenticate header pointing at exactly that document — the full RFC 9728 discovery loop, correctly wired. - id: rfc7591 name: 'RFC 7591: OAuth 2.0 Dynamic Client Registration' conforms: true evidence: https://login.aidentified.com/.well-known/oauth-authorization-server detail: registration_endpoint https://login.aidentified.com/v1/oauth2/register is advertised. - id: oidc name: OpenID Connect Discovery 1.0 conforms: true evidence: https://login.aidentified.com/.well-known/openid-configuration detail: >- HTTP 200 with issuer, authorization_endpoint, token_endpoint, userinfo_endpoint, jwks_uri, subject_types_supported ["public"] and id_token_signing_alg_values_supported ["RS256"]. - id: rfc7517 name: 'RFC 7517: JSON Web Key Set' conforms: true evidence: https://login.aidentified.com/.well-known/jwks.json detail: HTTP 200 RSA signing key with kid, alg RS256, use sig and an x5c chain. - id: mcp name: Model Context Protocol conforms: true version: '2026-06-18' evidence: https://mcp.aidentified.com/mcp detail: >- A JSON-RPC initialize POST returns an mcp-session-id header and the RFC 9728 challenge, negotiating protocol version 2026-06-18. Streamable HTTP transport. - id: rfc9116 name: 'RFC 9116: security.txt' conforms: false evidence: >- 404 on /.well-known/security.txt across www.aidentified.com, aidentified.com, api.aidentified.com, matching-api.aidentified.com, mcp.aidentified.com, login.aidentified.com and support.aidentified.com (2026-09-14). - id: rfc9457 name: 'RFC 9457: Problem Details for HTTP APIs' conforms: false evidence: >- No published error contract. The first-party client surfaces the raw decoded JSON body with no type/title/detail envelope. - id: openapi name: OpenAPI conforms: false evidence: >- No OpenAPI or Swagger document at any probed location on aidentified.com, api.aidentified.com or matching-api.aidentified.com (2026-09-14). api.aidentified.com/docs redirects to /accounts/login/. - id: asyncapi name: AsyncAPI conforms: false evidence: >- No event/streaming spec. The event surface is a nightly polled CSV (trigger-file), not a push channel — see data-model/aidentified-data-model.yml. - id: idempotency name: HTTP idempotency keys conforms: false evidence: conventions/aidentified-conventions.yml (idempotency.coverage = none) - id: a2a name: A2A Agent Card conforms: false evidence: >- 404 or SPA-shell on /.well-known/agent-card.json and /.well-known/agent.json across every host probed (2026-09-14). No card is published, so no AgentCard pointer is emitted. domain_standards: market: Wealth management / financial advisory data and prospecting probed: - id: fdx name: Financial Data Exchange (FDX) conforms: false note: >- FDX is the domain standard for consumer financial data sharing in this market. Aidentified's contract declares nothing FDX-shaped — no FDX entity names, no FDX endpoints. - id: fix name: FIX / FIXML conforms: false note: Not a trading or order-routing surface; the standard does not apply. - id: scim name: 'SCIM (urn:ietf:params:scim:schemas:*)' conforms: false note: >- SSO is offered on the Enterprise tier but no SCIM provisioning schema URN is published. finding: >- No domain standard is declared by Aidentified's contract. This is REWARD-ONLY in the rubric and is recorded as an observation, not a penalty — a contact-enrichment and relationship-graph API is not squarely inside FDX's scope, and there is no widely-adopted wire standard for wealth-signal enrichment to conform to. compliance: claims: - framework: SOC 2 claimed: true source: https://www.aidentified.com/terms-conditions quote: >- "...to protect the Personal Information from and against a Security Incident in line with the Aidentified's security policies, which are SOC2 compliant." report_available: not published publicly - framework: CCPA / CPRA claimed: true source: https://www.aidentified.com/terms-conditions detail: >- The Terms carry a dedicated California section addressing CCPA, CPRA and CPPA obligations, and the site publishes See My Data / Delete My Data consumer-rights flows plus a Virginia privacy-rights page. trust_center: https://trust.aidentified.com detail: security/aidentified-trust-center.yml note: >- SOC 2 is asserted in a contract document the company serves publicly, and a Vanta trust center exists at a first-party subdomain. The specific certifications listed inside the trust center could not be read — it is a client-rendered Vanta SPA whose served HTML carries only the title and description.