generated: '2026-08-06' method: probed source: >- well-known/auditoria-openid-configuration.json, https://www.auditoria.ai/trust/, and the Auditoria help center (https://docs.auditoria.ai/hc/en-us) scope_note: >- Auditoria publishes no OpenAPI, GraphQL SDL, AsyncAPI or MCP manifest, so the usual spec-derived conformance signals cannot be computed. Every entry below is asserted from a live probe or from published documentation, and a `conforms: false` here means "not observed on any public Auditoria surface", not "known to be unsupported internally". standards: - id: oidc-discovery name: OpenID Connect Discovery 1.0 conforms: true evidence: >- https://auth.auditoria.ai/.well-known/openid-configuration returns 200 application/json with issuer, authorization_endpoint, token_endpoint, userinfo_endpoint and jwks_uri. - id: oauth2 name: OAuth 2.0 (RFC 6749) conforms: true evidence: >- authorization_code, client_credentials, refresh_token, implicit and password grants advertised in grant_types_supported. - id: rfc8414-oauth-authorization-server-metadata name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: true evidence: >- https://auth.auditoria.ai/.well-known/oauth-authorization-server returns 200 with the same metadata document. - id: rfc7636-pkce name: PKCE (RFC 7636) conforms: true evidence: 'code_challenge_methods_supported: [S256, plain]' - id: rfc8628-device-authorization-grant name: OAuth 2.0 Device Authorization Grant (RFC 8628) conforms: true evidence: device_authorization_endpoint published; urn:ietf:params:oauth:grant-type:device_code supported - id: rfc8693-token-exchange name: OAuth 2.0 Token Exchange (RFC 8693) conforms: true evidence: urn:ietf:params:oauth:grant-type:token-exchange in grant_types_supported - id: rfc7523-jwt-bearer name: JWT Profile for OAuth 2.0 Client Authentication and Authorization Grants (RFC 7523) conforms: true evidence: urn:ietf:params:oauth:grant-type:jwt-bearer supported; private_key_jwt client auth supported - id: rfc9449-dpop name: OAuth 2.0 Demonstrating Proof of Possession (RFC 9449) conforms: true evidence: 'dpop_signing_alg_values_supported: [ES256]' - id: rfc7591-dynamic-client-registration name: OAuth 2.0 Dynamic Client Registration (RFC 7591) conforms: true evidence: 'registration_endpoint: https://auth.auditoria.ai/oidc/register' - id: rfc7009-token-revocation name: OAuth 2.0 Token Revocation (RFC 7009) conforms: true evidence: 'revocation_endpoint: https://auth.auditoria.ai/oauth/revoke' - id: oidc-backchannel-logout name: OpenID Connect Back-Channel Logout 1.0 conforms: true evidence: backchannel_logout_supported true; backchannel_logout_session_supported true - id: ciba name: OpenID Connect Client-Initiated Backchannel Authentication (CIBA) conforms: true evidence: 'backchannel_authentication_endpoint published; backchannel_token_delivery_modes_supported: [poll]' - id: saml2 name: SAML 2.0 Web Browser SSO conforms: true evidence: >- Generic SAML 2.0 SSO guide plus Okta and Microsoft Entra ID integration guides in the help center (Auditoria.AI Integrations category). - id: soc2-type2 name: SOC 2 Type II conforms: true evidence: >- Annual SOC 2 Type II examination stated on https://www.auditoria.ai/trust/ covering the Security, Confidentiality and Availability trust service principles; report on request. - id: iso-27001 name: ISO/IEC 27001 conforms: false evidence: >- Trust page states the Information Security Management Framework is "based on ISO-27001". Alignment claim only - no certificate, certification body or scope statement is published. - id: gdpr name: GDPR conforms: unknown evidence: >- A privacy policy and a subprocessors page are published, but no DPA, transfer mechanism or GDPR statement was found on a public page. - id: rfc9116-security-txt name: security.txt (RFC 9116) conforms: false evidence: 404 on www.auditoria.ai, auth.auditoria.ai and (as an SPA shell) app.auditoria.ai - id: openapi name: OpenAPI conforms: false evidence: >- No OpenAPI/Swagger document at /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs or /redoc on www, app or auth. app.auditoria.ai answers 200 with an identical HTML SPA shell for all of them. - id: asyncapi name: AsyncAPI conforms: false evidence: No event or streaming spec; a help-center search for "webhook" returns 0 articles. - id: rfc9457-problem-details name: Problem Details for HTTP APIs (RFC 9457) conforms: false evidence: no public API surface to carry an error format - id: mcp name: Model Context Protocol conforms: false evidence: no hosted MCP server found on any Auditoria host or in any registry - id: a2a name: A2A Agent Card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json return 404 on www.auditoria.ai and auth.auditoria.ai; app.auditoria.ai returns the SPA HTML shell, which is rejected. - id: llmstxt name: llms.txt conforms: true evidence: >- https://www.auditoria.ai/llms.txt returns 200 text/plain (Yoast SEO generated); a control path at /llms-zzz-control.txt returns 404, confirming it is a real document. x-evidence: checked: '2026-08-06' probes: - {url: 'https://auth.auditoria.ai/.well-known/openid-configuration', status: 200} - {url: 'https://auth.auditoria.ai/.well-known/oauth-authorization-server', status: 200} - {url: 'https://www.auditoria.ai/trust/', status: 200} - {url: 'https://www.auditoria.ai/llms.txt', status: 200} - {url: 'https://www.auditoria.ai/openapi.json', status: 404} - {url: 'https://www.auditoria.ai/.well-known/agent-card.json', status: 404}