generated: '2026-08-06' method: probed source: >- https://arundo.eu.auth0.com/.well-known/openid-configuration, https://arundo.eu.auth0.com/.well-known/oauth-authorization-server, https://status.arundo.com/api/v2/summary.json note: >- Arundo publishes no OpenAPI, AsyncAPI or JSON Schema for its Foundation APIs, so there is no contract to assert API-level conformance against. Everything asserted below was observed live on a public endpoint. Nothing is inferred from marketing copy. standards: - id: openid-connect-discovery-1.0 conforms: true evidence: https://arundo.eu.auth0.com/.well-known/openid-configuration returns 200 with issuer, authorization_endpoint, token_endpoint, jwks_uri - id: oauth2 conforms: true evidence: RFC 6749 authorization_code, client_credentials, refresh_token and implicit grants advertised by the tenant metadata - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: https://arundo.eu.auth0.com/.well-known/oauth-authorization-server returns 200 application/json - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported includes S256 - id: rfc8628-device-authorization-grant conforms: true evidence: device_authorization_endpoint present and urn:ietf:params:oauth:grant-type:device_code advertised - id: rfc8693-token-exchange conforms: true evidence: urn:ietf:params:oauth:grant-type:token-exchange advertised in grant_types_supported - id: rfc7591-dynamic-client-registration conforms: true evidence: registration_endpoint https://arundo.eu.auth0.com/oidc/register present - id: rfc9449-dpop conforms: true evidence: dpop_signing_alg_values_supported ES256 - id: rfc7009-token-revocation conforms: true evidence: revocation_endpoint https://arundo.eu.auth0.com/oauth/revoke present - id: openapi conforms: false evidence: no OpenAPI/Swagger document found on www.arundo.com, api.arundo.com, marathon.eu.arundo.com or carbonpath.arundo.com (all probes 404, or an HTML SPA shell) - id: asyncapi conforms: false evidence: no AsyncAPI document and no public event/webhook catalog published - id: rfc9457-problem-details conforms: false evidence: >- the only published Arundo error envelope (the Foundation compute plug-in contract, github.com/arundo/foundation-compute-example) uses a custom issues[] array of {code, message, path}, not application/problem+json - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on www.arundo.com and api.arundo.com - id: a2a conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json miss on every Arundo host compliance_program: published: false note: >- No trust center, no named certifications (SOC 2 / ISO 27001 / GDPR statement page) found on arundo.com; trust.arundo.com and security.arundo.com do not resolve, and /security, /trust and /compliance all return 404. No Compliance pointer is emitted. x-evidence: fetched: '2026-08-06' urls: - url: https://arundo.eu.auth0.com/.well-known/openid-configuration status: 200 - url: https://arundo.eu.auth0.com/.well-known/oauth-authorization-server status: 200 - url: https://www.arundo.com/.well-known/security.txt status: 404 - url: https://www.arundo.com/security status: 404