generated: '2026-08-02' method: derived source: openapi/*.json, https://docs.aleph-alpha.com/ standards: - id: openapi-3.1 conforms: true evidence: 'PhariaSearch, PhariaStudio and Responses publish OpenAPI 3.1.0 documents.' - id: openapi-3.0 conforms: true evidence: 'PhariaData publishes OpenAPI 3.0.1; PhariaInference publishes OpenAPI 3.0.3.' - id: swagger-2.0 conforms: true evidence: 'PhariaOS Manager API is published as a Swagger 2.0 definition.' - id: oauth2 conforms: false evidence: 'No oauth2 securityScheme is declared in any of the six published specs. PhariaStudio ships an OAuth Gateway for connecting third-party services (Google Drive, SharePoint), but the Aleph Alpha APIs themselves authenticate with a bearer JWT.' - id: oidc conforms: partial evidence: 'PhariaAI authenticates end users through an OIDC identity provider — Dex (recommended) federating to Google/Microsoft/Okta, previously bundled Zitadel. This is a deployment-level identity integration, not an openIdConnect securityScheme in the API contracts.' docs: https://docs.aleph-alpha.com/phariaai-install-config-guide/latest/installation/installation-process.html - id: jwt-bearer conforms: true evidence: 'securityScheme "Bearer": type http, scheme bearer, bearerFormat JWT across five of six specs.' - id: rfc9457-problem-details conforms: false evidence: 'No response declares application/problem+json. Errors use an OpenAI-style {"error":{message,type,param,code}} envelope.' - id: openai-responses-api conforms: true evidence: 'The Stateful Responses API implements the OpenAI Responses API specification; the OpenAI Python SDK, PydanticAI and LangGraph work against it unmodified.' docs: https://docs.aleph-alpha.com/phariaai-dev-guide/latest/responses-api/index.html - id: openai-chat-completions conforms: true evidence: 'PhariaInference exposes POST /chat/completions and POST /embeddings; PhariaStudio exposes POST /models/chat/completions. External OpenAI-compatible API connectors can be plugged in behind the inference scheduler.' - id: model-context-protocol conforms: true evidence: 'PhariaAssistant Chat has native MCP client support and bundles first-party MCP servers (PhariaConductor, Document index, Code sandbox); the Responses API executes MCP tools server-side.' detail: mcp/aleph-alpha-mcp.yml - id: a2a conforms: partial evidence: 'A2A conversation context is referenced in the PhariaAI v1.260700.0 release notes (tool call history in A2A conversation context). No A2A agent card is served at /.well-known/agent-card.json or /.well-known/agent.json on any Aleph Alpha host (probed 2026-08-02).' - id: server-sent-events conforms: true evidence: 'SSE streaming across the Responses API, PhariaInference completion/chat, and PhariaData run-event streams.' - id: opentelemetry conforms: true evidence: 'PhariaStudio ingests OTLP traces (POST /projects/{project_id}/traces_v2) and models traces/spans/events as API resources.' - id: prometheus-metrics conforms: true evidence: 'Translation Service exposes /metrics with translation_service_http_requests_total (v1.260700.0); Grafana dashboards ship with PhariaOS.' - id: slsa-provenance conforms: true evidence: 'Every PhariaAI container image is signed with Cosign keyless signing (GitHub Actions OIDC) with verifiable SLSA provenance.' docs: https://docs.aleph-alpha.com/phariaai-install-config-guide/latest/installation/before-you-start/security-disclosure-v2.html - id: cyclonedx-sbom conforms: true evidence: 'CycloneDX SBOM attestations published per image, plus SPDX package/license metadata and Trivy vulnerability reports, all bound to the image digest.' - id: spdx conforms: true evidence: 'SPDX package and license data published as a Cosign attestation for compliance workflows.' - id: iso-27001 conforms: true evidence: 'Aleph Alpha GmbH holds ISO/IEC 27001:2022 (DQS certificate registration number 31625355) for research, development and commercialization of generative AI technology with focus on multimodal large language models.' source: https://www.dqsglobal.com/en/customer-database/aleph-alpha-gmbh - id: bsi-c5 conforms: partial evidence: 'The Pharia Government Assistant is operated on STACKIT GmbH cloud infrastructure in Germany, certified to BSI C5 and ISO 27001. This is the hosting provider''s certification, not Aleph Alpha''s own.' source: https://docs.aleph-alpha.com/verticals/pga-de/uebersicht.html - id: gdpr conforms: partial evidence: 'GDPR-relevant controls are published (hard delete for erasure requests, retention policies, incognito mode, salted SHA-256 hashing of analytics identifiers). Aleph Alpha states analytics GDPR compliance is still being improved, and on-premise customers self-manage GDPR compliance for usage analytics.' - id: eu-ai-act conforms: unknown evidence: 'No published conformity statement was found.' - id: dora conforms: n/a evidence: 'DORA appears as a customer use case (creance.ai, a joint venture with PwC Germany for DORA contract analysis), not as a regime Aleph Alpha''s own APIs are certified against.' - id: fhir-r4 conforms: false - id: scim conforms: false - id: odata conforms: false - id: json-api conforms: false