generated: '2026-08-06' method: searched source: https://www.armor.com/llms.txt, https://developer.armor.com/, derived from openapi/ standards: - id: oauth2 conforms: true evidence: nine of twelve v2 contracts declare oauth2 securitySchemes (clientCredentials against https://api.armor.com/auth/authorize; authorizationCode against https://auth.armor.com and https://api.armor.com/auth/token). The developer portal documents the ID-token + scoped-access-token model. - id: oidc conforms: partial evidence: The token flow issues a signed OIDC-style ID token and mandates the openid, email and profile scopes, and identity is federated through ADFS at https://sts.armor.com/adfs/oauth2/authorize. However no /.well-known/openid-configuration is served on any Armor host, so the provider is not OIDC-discoverable. - id: openapi-3 conforms: true evidence: twelve OpenAPI 3.0.3 documents published at https://developer.armor.com/swagger/ - id: swagger-2 conforms: true evidence: four Swagger 2.0 documents for the v1 Armor Services API - id: rfc9457-problem-details conforms: false evidence: no application/problem+json media type in any of the 16 contracts; six distinct proprietary error envelopes instead - id: rfc8594-sunset-header conforms: false evidence: no Sunset or Deprecation response headers declared; no deprecation policy published - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on www.armor.com and developer.armor.com - id: idempotency-key conforms: false evidence: no Idempotency-Key header or replay contract in 427 operations - id: json-api conforms: false evidence: plain application/json payloads, no JSON:API envelope - id: graphql conforms: partial evidence: POST /ti/graphql on mdr.api.secure-prod.services proxies OpenCTI. Anonymous introspection returns HTTP 403, so no SDL could be captured; the surface is documented in openapi/armor-mdr-public-openapi-original.yml only. - id: asyncapi conforms: false evidence: a real webhook subscription surface exists (openapi/armor-webhooks-openapi-original.yml) but no AsyncAPI document is published - id: mitre-attack conforms: true evidence: Detection Rules operations return Microsoft Sentinel rules enriched with MITRE ATT&CK mappings (openapi/armor-mdr-public-openapi-original.yml#getRulesForCustomer); Armor is a MITRE Partnership Network member certifications: source: https://www.armor.com/llms.txt (first-party, last updated April 2026) held: - AICPA SOC 2 Type II - HITRUST CSF - PCI DSS Level 1 Service Provider (PCI 4.0) - ISO 27001 - TX-RAMP Level 2 - HIPAA - Data Privacy Framework (DPF) memberships: - Microsoft Intelligent Security Association (MISA) - PCI Security Standards Council - MITRE Partnership Network - CIS SecureSuite trust_center: public: false note: Armor states it maintains a Trust Center for consolidated compliance-report administration, but it is reachable only through the customer-authenticated Nexus Portal. trust.armor.com does not resolve. There is no public trust page to point at. customer_frameworks: note: Frameworks Armor provides controls, consulting and audit support for (its services, not its own attestations) united_states: - HIPAA - SOX - GLBA - FISMA - CCPA/CPRA - NYDFS 23 NYCRR 500 - CMMC - NERC CIP united_kingdom: - UK GDPR - UK Data Protection Act 2018 european_union: - EU GDPR other: - PDPA (Singapore) - PDPA (Thailand)