specification: API Commons Conformance specificationVersion: '0.1' generated: '2026-09-14' method: probed source: >- Live discovery documents (service.altusgroup.com and the ARGUS Intelligence Platform's Entra tenant) plus the Altus Group Trust Center at https://www.altusgroup.com/trust-center/ (HTTP 200). provider: ARGUS providerId: argus description: >- Standards conformance for the ARGUS platform (Altus Group). Every `conforms: true` entry below is backed by a document that was fetched and parsed. ARGUS publishes no API contract, so no conformance claim is made about pagination, idempotency, RFC 9457 problem details, or any other runtime convention — those are unknown, not absent. conformance: - id: oidc name: OpenID Connect Discovery 1.0 conforms: true evidence: >- https://login.microsoftonline.com/4299aec5-b3b8-413e-a612-88e3c0b4c972/v2.0/.well-known/openid-configuration (HTTP 200) and https://service.altusgroup.com/.well-known/openid-configuration (HTTP 200) — both parse as OIDC discovery documents with issuer, authorization, token and jwks endpoints. - id: oauth2 name: OAuth 2.0 Authorization Code conforms: true evidence: >- Both discovery documents advertise the authorization code grant; the Salesforce document lists refresh_token, introspection (RFC 7662) and revocation (RFC 7009) endpoints. - id: pkce name: RFC 7636 PKCE conforms: true evidence: >- code_challenge_methods_supported = ["S256"] in both discovery documents. - id: dpop name: RFC 9449 DPoP conforms: true scope: support community identity provider only evidence: >- dpop_signing_alg_values_supported = [RS256, RS384, RS512, ES256, ES384, ES512, EdDSA] at https://service.altusgroup.com/.well-known/openid-configuration. - id: iso-27001 name: ISO/IEC 27001 conforms: true evidence: >- Altus Group ISO 27001 certificate published on the Trust Center — https://assets.ctfassets.net/8jgyidtgyr4v/57zQIo2ZT1tjAYxNXMTeov/5119a5f2b118d51137ce93e46d4e4564/Altus_Group_-_ISO_27001_Certificate__1257796-1_.pdf (HTTP 200). - id: soc2-type-ii name: SOC 2 Type II conforms: true access: on request evidence: >- https://www.altusgroup.com/trust-center/ states the SOC 2 Type II report is available on request via https://www.altusgroup.com/contact-us/. The public artifacts are the SOC 3 Type 2 reports below. - id: soc3-type-2 name: SOC 3 Type 2 conforms: true evidence: >- ARGUS Cloud 2025 SOC 3 Type 2 — https://assets.ctfassets.net/8jgyidtgyr4v/62oPXodxLyc0k2zAHoV5fG/91830a2100eb1f0825dac12bc0282ecb/Altus__ARGUS_Cloud__-_2025_SOC_3_Type_2_-_Report.pdf (HTTP 200); ARGUS Intelligence Platform 2025 SOC 3 Type 2 — https://assets.ctfassets.net/8jgyidtgyr4v/2hPBrND9iRvGEs2VldL8yJ/9c159d96366dd479de6e7cbbc2ba4c7c/Altus__ARGUS_Intelligence__-_2025_SOC_3_Type_2_-_Report.pdf (HTTP 200). - id: gdpr name: EU GDPR conforms: true evidence: >- https://www.altusgroup.com/legal/gdpr/ (HTTP 200) and a published sub-processor list at https://www.altusgroup.com/legal/gdpr-subprocessors/ (HTTP 200). - id: eu-uk-operational-resilience name: EU/UK operational resilience (DORA/PRA-aligned disclosure) conforms: true evidence: >- https://assets.ctfassets.net/8jgyidtgyr4v/P6edTsHH9vYOUWRvQXyB1/aaedc98ba400a8cc3149f5a720fe44d6/Altus_Group_-_Operational_Resilience__EU_UK_.pdf linked from the Trust Center. - id: rfc9457 name: RFC 9457 Problem Details conforms: false evidence: >- Unknown — no ARGUS API contract or error reference is published, so no problem-details media type could be observed. Recorded as not established rather than absent. - id: rfc8594 name: RFC 8594 Sunset header conforms: false evidence: >- Altus Group publishes product end-of-support dates in prose (see lifecycle/), but no HTTP Sunset or Deprecation header could be observed on any reachable ARGUS endpoint. domain_standards: - id: none-declared name: Commercial real estate data standards conforms: false evidence: >- No contract is published, so no domain-standard signature (OSCRE, RESO, MISMO, RETS, XBRL, INREV/NCREIF reporting schemas) could be read out of one. The marketing pages name integrations with Yardi and MRI but declare no standard. Reward-only check — recorded as not established, not as a failure. maintainers: - FN: Kin Lane email: kin@apievangelist.com