generated: '2026-08-02' method: searched source: https://trust.arist.co/ + https://arist.com/llms.txt + https://help.arist.co/ note: | Arist publishes no OpenAPI, so protocol-level conformance could not be derived from a spec. These assertions come from the anonymously published OIDC discovery document on auth.arist.app and from the certifications and claims Arist publishes on its trust center, marketing site and help center. Anything not evidenced is recorded conforms: false rather than left implied. standards: - id: openid-connect-discovery conforms: true evidence: https://auth.arist.app/.well-known/openid-configuration returns 200 application/json with a complete OIDC Discovery 1.0 document - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: https://auth.arist.app/.well-known/oauth-authorization-server returns 200 with an identical authorization-server metadata document - id: oauth2 conforms: true evidence: authorization_code, client_credentials, refresh_token, device_code, token-exchange and jwt-bearer grants advertised in the discovery document - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported includes S256 - id: rfc9449-dpop conforms: true evidence: dpop_signing_alg_values_supported = [ES256] - id: rfc7591-dynamic-client-registration conforms: true evidence: registration_endpoint https://auth.arist.app/oidc/register advertised - id: rfc7009-token-revocation conforms: true evidence: revocation_endpoint https://auth.arist.app/oauth/revoke advertised - id: rfc8628-device-authorization-grant conforms: true evidence: device_authorization_endpoint https://auth.arist.app/oauth/device/code advertised - id: saml-2.0 conforms: true evidence: help center SSO guide documents SAML SP-initiated and IdP-initiated login against Entra ID, Okta, Google Workspace, ADFS and PingFederate - id: iso-27001 conforms: true evidence: listed on https://trust.arist.co/ (certificate available on request) - id: iso-27701 conforms: true evidence: listed on https://trust.arist.co/ - id: iso-42001 conforms: true evidence: listed on https://trust.arist.co/ — AI management system standard - id: soc2-type2 conforms: true evidence: listed on https://trust.arist.co/ (report and bridge letter available on request) - id: wcag conforms: claimed evidence: 'https://arist.com/llms.txt Technical Details: "Security: SOC-2, ISO 27001, WCAG compliant" — conformance level (A/AA/AAA) and version not stated' - id: tcpa conforms: claimed evidence: 'https://arist.com/llms.txt: toll-free SMS with TCPA compliance for frontline workers; help center documents STOP keyword handling for SMS, WhatsApp and email' - id: gdpr conforms: unknown evidence: ISO 27701 PIMS certification and a published sub-processor list at https://arist.com/legal/sub-processors, but no explicit GDPR statement located - id: openapi conforms: false evidence: no OpenAPI/Swagger document found on any host; api.arist.app returns 403 MissingAuthenticationToken for /openapi.json, /swagger.json, /v1/openapi.json, /api-docs, /docs and /redoc - id: asyncapi conforms: false evidence: no AsyncAPI document and no public webhook catalog published - id: rfc9457-problem-details conforms: false evidence: no public API error reference; gated API returns Amazon API Gateway default JSON errors - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on arist.com, help.arist.co and trust.arist.co - id: a2a conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json probed on every host — only SPA HTML catch-all responses, no AgentCard - id: mcp conforms: false evidence: no hosted or published Model Context Protocol server located - id: fhir conforms: false - id: scim conforms: false evidence: SSO guide documents SAML/OIDC federation but no SCIM provisioning endpoint x-evidence: fetched: '2026-08-02' urls: - {url: 'https://trust.arist.co/', http_status: 200} - {url: 'https://arist.com/llms.txt', http_status: 200} - {url: 'https://auth.arist.app/.well-known/openid-configuration', http_status: 200} - {url: 'https://api.arist.app/openapi.json', http_status: 403} - {url: 'https://arist.com/.well-known/security.txt', http_status: 404}