generated: '2026-08-14' method: probed source: >- live probes of https://mcp.backstory.ai/.well-known/* and https://mcp.people.ai/mcp, plus https://www.backstory.ai/platform/trust-security note: >- Backstory has no OpenAPI, so nothing here is derived from a spec. Each entry is either observed on the wire or stated by the provider on a named page. standards: - id: mcp name: Model Context Protocol conforms: true evidence: >- Hosted remote MCP server at https://mcp.people.ai/mcp answering JSON-RPC over Streamable HTTP; documented for Claude, ChatGPT, Microsoft Copilot, Gemini CLI and n8n. Anonymous tools/list returns a spec-shaped 401 with a Bearer challenge. Protocol version could not be read without credentials. - id: oauth2 name: OAuth 2.0 (RFC 6749) conforms: true evidence: >- authorization_code + refresh_token grants advertised at https://mcp.backstory.ai/.well-known/oauth-authorization-server (HTTP 200). - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata conforms: true evidence: /.well-known/oauth-authorization-server returns 200 with issuer, authorization_endpoint, token_endpoint, revocation_endpoint. - id: rfc9728 name: OAuth 2.0 Protected Resource Metadata conforms: true evidence: >- /.well-known/oauth-protected-resource/mcp returns 200 naming resource https://mcp.backstory.ai/mcp, its authorization server, and bearer_methods_supported [header]; the 401 WWW-Authenticate challenge references that metadata URL, as the RFC prescribes. - id: rfc7591 name: OAuth 2.0 Dynamic Client Registration conforms: true evidence: registration_endpoint https://mcp.backstory.ai/register advertised in AS metadata. - id: rfc7636 name: PKCE conforms: true evidence: code_challenge_methods_supported ["S256"]. - id: rfc6750 name: OAuth 2.0 Bearer Token Usage conforms: true evidence: >- 401 responses carry a conformant WWW-Authenticate Bearer challenge with error="invalid_token", error_description and resource_metadata. - id: oidc name: OpenID Connect Discovery conforms: false evidence: /.well-known/openid-configuration returns 404 on every Backstory host probed. - id: rfc9457 name: Problem Details for HTTP APIs conforms: false evidence: >- Errors use a custom JSON envelope (error / error_description / error_code / error_reason) with content-type application/json, not application/problem+json. - id: rfc9116 name: security.txt conforms: false evidence: >- /.well-known/security.txt 404s on www, app, api and mcp hosts. The 200 at status.backstory.ai is Atlassian's own Statuspage document, not Backstory's. - id: openapi name: OpenAPI conforms: false evidence: >- No spec at any probed path on api.backstory.ai, api.people.ai, mcp.* or the marketing host (all 404). The REST API is documented only as admin-panel key management. - id: asyncapi name: AsyncAPI conforms: false evidence: No event, streaming or webhook surface is published; nothing to describe. - id: a2a name: A2A Agent Card conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json 404 on every host probed. - id: rfc8594 name: Sunset / Deprecation headers conforms: unknown evidence: No deprecation policy is published and the endpoint could not be exercised anonymously. compliance_program: published: true url: https://www.backstory.ai/platform/trust-security certifications: [SOC 2 Type II, ISO 27001, ISO 27017, GDPR, CSA STAR] commitments: - Customer data is never used to train or fine-tune base models. - Model outputs are scoped to the tenant and never shared across accounts. - PII is stripped from activities before data reaches model providers, including Backstory's own models. - AI processing commitments are included in the standard DPA and covered under SOC 2 Type II scope. - AI subprocessors are listed in a public subprocessor registry. - AI features can be disabled at the tenant level. detail: security/backstory-trust-center.yml