generated: '2026-08-02' method: derived source: >- well-known/bishop-fox-openid-configuration.json, well-known/bishop-fox-security.txt, authentication/bishop-fox-authentication.yml, errors/bishop-fox-problem-types.yml api: Bishop Fox Cosmos API (v5) note: >- Derived from artifacts already harvested into this repo plus live probes. No OpenAPI is published, so spec-level conformance could not be assessed; unknowns are recorded as unknown, not as failures. standards: - id: oauth2 conforms: true evidence: >- Client-credentials grant against https://bishopfox.auth0.com/oauth/token; grant_types_supported in the RFC 8414 metadata includes client_credentials. - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: 'https://bishopfox.auth0.com/.well-known/oauth-authorization-server returns 200 application/json' - id: oidc-discovery conforms: true evidence: 'https://bishopfox.auth0.com/.well-known/openid-configuration returns 200 with issuer, jwks_uri, userinfo_endpoint' - id: rfc7519-jwt conforms: true evidence: Bearer access tokens issued by the Auth0 tenant; jwks_uri published for verification. - id: rfc9116-security-txt conforms: partial evidence: >- https://bishopfox.com/.well-known/security.txt returns 200 with Contact, Expiration and Policy fields, but the Expiration date (2025-12-31) is in the past as of 2026-08-02 and Policy points at the privacy statement rather than the disclosure policy. - id: rfc9457-problem-details conforms: false evidence: 'Observed error envelope is {"message":"..."} with content-type application/json, not application/problem+json.' - id: openapi conforms: false evidence: >- No OpenAPI/Swagger document at any probed location on api.cosmos.bishopfox.com, cosmos.bishopfox.com or bishopfox.com; see well-known/bishop-fox-well-known.yml for the full probe table. - id: asyncapi conforms: false evidence: No event/streaming surface or AsyncAPI document is published. - id: a2a-agent-card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json return 404 on bishopfox.com and api.cosmos.bishopfox.com; the cosmos.bishopfox.com SPA returns an HTML catch-all 200 which was rejected. - id: mcp conforms: false evidence: No first-party hosted or packaged MCP server for the Cosmos API was found. - id: llmstxt conforms: true evidence: 'https://bishopfox.com/llms.txt returns 200 text/plain; harvested verbatim to llms/bishop-fox-llms.txt' - id: dnssec conforms: true evidence: security/bishop-fox-domain-security.yml — bishopfox.com is DNSSEC signed with a CAA record set. - id: dmarc conforms: true evidence: security/bishop-fox-domain-security.yml — DMARC published with p=reject. - id: hsts conforms: partial evidence: >- cosmos.bishopfox.com sets HSTS with max-age 31536000; bishopfox.com does not set HSTS and no HSTS header was observed on api.cosmos.bishopfox.com. - id: scim conforms: unknown - id: odata conforms: false - id: json-api conforms: false compliance_program: published: false note: >- Bishop Fox markets compliance-driven testing services (PCI DSS, SOC 2, HIPAA, ISO 27001) to customers and is a PCI DSS Approved Scanning Vendor, but publishes no trust center and no certifications of its own platform. No Compliance or TrustCenter pointer is wired — those checks read a published compliance posture for the provider's own service, which does not exist here.