generated: '2026-07-19' method: searched source: https://www.dell.com/support/manuals/en-us/avamar-server/avamar_administration_guide_19.10/avamar-rest-api additional_sources: - https://www.dell.com/support/contents/en-us/article/product-support/self-support-knowledgebase/security-antivirus/alerts-vulnerabilities/dell-vulnerability-response-policy - https://www.dell.com/en-us/dt/about-us/security-and-trust-center/compliance-service-organization-control-overlay.htm standards: - id: oauth2 conforms: true evidence: >- Documented OAuth 2.0 client registration (POST /api/v1/oauth2/clients) and token endpoint (POST /api/oauth/token) with password and client_credentials grants, bearer tokens and refresh tokens. source: https://www.dell.com/support/manuals/en-us/avamar-server/avamar_administration_guide_19.10/avamar-rest-api - id: rfc6749-oauth2-password-grant conforms: true evidence: grant_type=password with client credentials sent as HTTP Basic on the token endpoint. - id: oidc conforms: true evidence: >- OIDC single sign-on for the Avamar Web UI validated against Keycloak realms, with an OIDC client registration carrying token_endpoint_auth_method client_secret_basic, id_token_signed_response_alg RS256, and the openid/profile scopes. - id: rfc7519-jwt conforms: true evidence: Access tokens are returned as RS256-signed JWTs with a jti claim. - id: openapi-swagger-2.0 conforms: partial evidence: >- A Swagger UI describing the complete Avamar REST API operation and object-model surface is served from the appliance at /api/swagger-ui.html, and the sibling OpenStack Data Protection Extension API is defined by a YAML file following OpenAPI Specification 2.0. Dell does not publish a downloadable Avamar specification document, so the definition is only reachable per-deployment. - id: rfc9457-problem-details conforms: false evidence: >- Error responses use a proprietary `message` element and numeric Avamar event codes; no application/problem+json contract is documented. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation response headers documented; deprecation is published as EOL/EOSL notices. - id: json-api conforms: false evidence: Representations are plain JSON or XML with href links, not the JSON:API media type. - id: rest-hateoas conforms: true evidence: Every resource representation carries an absolute `href`, and inter-resource references are href-bearing nested elements. - id: iso-iec-29147-vulnerability-disclosure conforms: true evidence: >- Dell states its PSIRT processes and procedures align with ISO/IEC 29147:2018 as well as the FIRST PSIRT Services Framework. source: https://www.dell.com/support/contents/en-us/article/product-support/self-support-knowledgebase/security-antivirus/alerts-vulnerabilities/dell-vulnerability-response-policy - id: iso-iec-30111-vulnerability-handling conforms: true evidence: Dell states its PSIRT processes and procedures align with ISO/IEC 30111:2019. source: https://www.dell.com/support/contents/en-us/article/product-support/self-support-knowledgebase/security-antivirus/alerts-vulnerabilities/dell-vulnerability-response-policy - id: iso-iec-27001 conforms: true scope: organization evidence: >- Dell Technologies Inc. holds an ISO 27001:2022 multi-site certificate covering Dell Technology Services, Sales, Dell Financial Services, Infrastructure Solutions Group and supporting functions. Certification is at the Dell organizational level, not scoped to the Avamar product. source: https://www.dell.com/en-us/dt/about-us/security-and-trust-center/compliance-service-organization-control-overlay.htm - id: soc2-type-ii conforms: true scope: organization evidence: >- Dell operates a centrally governed SOC program with SOC reports specific to Dell's offers and services, independently assessed by PwC and Schellman Compliance. Scoped to Dell offers/services generally rather than to Avamar specifically. source: https://www.dell.com/en-us/dt/about-us/security-and-trust-center/compliance-service-organization-control-overlay.htm - id: first-psirt-services-framework conforms: true evidence: Dell participates in FIRST and aligns its PSIRT processes with the FIRST PSIRT Services Framework. - id: scim conforms: false - id: odata conforms: false - id: fhir conforms: false - id: fapi conforms: false - id: psd2 conforms: false - id: idempotency-key conforms: false evidence: No idempotency-key contract documented. See conventions/avamar-conventions.yml. - id: pagination conforms: false evidence: No cursor/page/limit/offset parameters documented for collection endpoints.