generated: '2026-07-17' method: searched source: >- well-known/allstacks-oauth-authorization-server.json, well-known/allstacks-oauth-protected-resource.json, https://www.allstacks.com/policy/security standards: - id: oauth2 conforms: true evidence: >- app.allstacks.com publishes OAuth 2.0 authorization-server metadata with authorization_code + refresh_token grants - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: /.well-known/oauth-authorization-server returns 200 with issuer + endpoints - id: rfc9728-oauth-protected-resource-metadata conforms: true evidence: /.well-known/oauth-protected-resource returns 200 with resource + authorization_servers - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported includes S256 - id: rfc7591-dynamic-client-registration conforms: true evidence: registration_endpoint advertised (https://app.allstacks.com/oauth/register/) - id: rfc6750-bearer-token conforms: true evidence: bearer_methods_supported ["header"] - id: soc2-type-ii conforms: true evidence: >- "proud to be SOC 2 Type II certified" (allstacks.com/policy/security); certifications published at trust.allstacks.com - id: gdpr conforms: true evidence: GDPR listed among certifications on trust.allstacks.com - id: openid-connect conforms: false evidence: /.well-known/openid-configuration returns 404 - id: rfc9457-problem-details conforms: false evidence: no public OpenAPI / error schema published