generated: '2026-09-05' method: searched source: >- openapi/*.yml, json-schema/*-crd.yaml (published CRDs), https://www.tigera.io/tigera-products/calico-cloud-trust-center/, https://docs.tigera.io/calico/latest/release-notes/, https://github.com/projectcalico/calico/blob/master/SECURITY.md description: >- Standards Calico's own contracts declare, plus the compliance programme Tigera publishes for the hosted edition. Evidence points at a spec location or a quoted provider page in every row. Rows the provider only CLAIMS are marked as such and separated from rows the contract DECLARES. conformance: - id: kubernetes-api-conventions name: Kubernetes API conventions conforms: true evidence: >- openapi/_original/calico-openapi.yml declares the Kubernetes machinery shapes directly: a components.schemas.Status object with kind defaulted to "Status", metadata.resourceVersion, and labelSelector/fieldSelector query parameters on every list operation. Those are the metav1.Status / metav1.ListOptions / metav1.ObjectMeta contracts, not Calico inventions. category: platform - id: kubernetes-crd-openapiv3 name: CustomResourceDefinition with structural openAPIV3Schema (apiextensions.k8s.io/v1) conforms: true evidence: >- json-schema/calico-projectcalico.org_*-crd.yaml — 9 published CRDs, each apiVersion apiextensions.k8s.io/v1, kind CustomResourceDefinition, group projectcalico.org, with a structural openAPIV3Schema per version. Generated by controller-gen v0.18.0. category: platform - id: kubernetes-networkpolicy-api name: Kubernetes NetworkPolicy API (networking.k8s.io/v1) conforms: true evidence: >- DOMAIN STANDARD for this market. Calico is a conformant implementation of the upstream Kubernetes NetworkPolicy API and extends it with projectcalico.org/v3 NetworkPolicy and GlobalNetworkPolicy. Declared throughout https://docs.tigera.io/calico/latest/network-policy/get-started/calico-policy/calico-network-policy and evidenced by the networkpolicies/globalnetworkpolicies CRDs in json-schema/. category: domain-standard - id: kubernetes-clusternetworkpolicy name: Kubernetes ClusterNetworkPolicy (upstream network-policy-api) conforms: true evidence: >- Release notes for v3.32.0 — "Support for the upstream Kubernetes ClusterNetworkPolicy resource, giving cluster admins cluster-scoped rules." Adopted in place of the earlier AdminNetworkPolicy/BaselineAdminNetworkPolicy support, which v3.32 removes. https://docs.tigera.io/calico/latest/release-notes/ category: domain-standard - id: cni-specification name: Container Network Interface (CNI) specification conforms: true evidence: >- DOMAIN STANDARD for this market. Calico ships a CNI plugin binary and a CNI config; the dataplane gRPC contract is published at grpc/calico-cni-plugin-cnibackend.proto. Configuration reference: https://docs.tigera.io/calico/latest/reference/configure-cni-plugins category: domain-standard - id: bgp-rfc4271 name: BGP-4 (RFC 4271) conforms: true evidence: >- Calico distributes routes over BGP using a fork of the BIRD protocol stack (github.com/projectcalico/bird). The BGPPeer and BGPConfiguration resources in openapi/ and json-schema/ are the configuration surface; https://docs.tigera.io/calico/latest/networking/configuring/bgp category: domain-standard - id: grpc-protobuf3 name: gRPC / Protocol Buffers 3 conforms: true evidence: >- grpc/*.proto — five published proto3 contracts, all `syntax = "proto3"`. goldmane/api.proto defines service Flows with List, Stream and FilterHints RPCs. category: platform - id: istio-ambient name: Istio ambient mesh conforms: true evidence: >- Release notes v3.32.0 — "Istio ambient mode ... delivers mTLS encryption at much lower resource cost than sidecar mesh." https://docs.tigera.io/calico/latest/release-notes/ category: domain-standard - id: oauth2-rfc8414 name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: true evidence: >- https://www.tigera.io/.well-known/oauth-authorization-server/ returns HTTP 200 with a valid RFC 8414 document (issuer, authorization_endpoint, token_endpoint, revocation_endpoint, code_challenge_methods_supported S256). Saved verbatim at well-known/calico-oauth-authorization-server.json. Serves the Tigera MCP server, not the Calico API. category: auth - id: oauth2-rfc9728 name: OAuth 2.0 Protected Resource Metadata (RFC 9728) conforms: true evidence: >- https://www.tigera.io/.well-known/oauth-protected-resource/ returns HTTP 200 with resource, authorization_servers, bearer_methods_supported and scopes_supported. Saved verbatim at well-known/calico-oauth-protected-resource.json. category: auth - id: mcp name: Model Context Protocol conforms: true evidence: >- https://www.tigera.io/wp-json/mcp/mcp-oauth-server answers JSON-RPC with a structured MCP error envelope ({"code":"mcp_unauthorized",...,"data":{"status":401}}). The server is real; its tool set is OAuth-gated. See mcp/calico-mcp.yml. category: agent - id: llms-txt name: llms.txt conforms: true evidence: >- https://docs.tigera.io/calico/llms.txt returns HTTP 200, 83,091 bytes, valid llms.txt structure (H1, blockquote summary, H2 sections of annotated links). Saved verbatim at llms/calico-llms.txt. A second index is served at https://docs.tigera.io/llms.txt. category: agent - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: >- No application/problem+json response in any openapi/ file. Errors use the Kubernetes metav1.Status envelope (application/json) instead — a real, documented and consistent error contract, but not RFC 9457. See errors/calico-problem-types.yml. category: errors - id: rfc9116-security-txt name: RFC 9116 security.txt conforms: false evidence: >- 404 on /.well-known/security.txt on every host probed — www.tigera.io, docs.tigera.io, tigera.io, projectcalico.org. See well-known/calico-well-known.yml. Tigera does run a disclosure programme; it is just not machine-discoverable. category: security - id: rfc8594-sunset name: RFC 8594 Sunset / Deprecation headers conforms: false evidence: >- Deprecations are announced in the release notes, not in HTTP headers. See lifecycle/calico-lifecycle.yml. category: lifecycle - id: a2a-agent-card name: A2A Agent Card conforms: false evidence: >- 404 on /.well-known/agent-card.json and /.well-known/agent.json on every host probed. No a2a/ artifact was written and no AgentCard pointer is emitted. category: agent - id: asyncapi name: AsyncAPI conforms: false evidence: >- No AsyncAPI document and no webhook surface. Calico's event surface is the Goldmane gRPC Flows.Stream server-streaming RPC (grpc/calico-goldmane-api.proto) and the Kubernetes watch mechanism — neither is AsyncAPI-shaped. N/A rather than a gap. category: events compliance: scope: >- IMPORTANT DISTINCTION. Calico Open Source is Apache-2.0 software an operator runs in its own cluster; it holds no certification and needs none. Everything below applies to CALICO CLOUD, the hosted commercial edition operated by Tigera, Inc. source: https://www.tigera.io/tigera-products/calico-cloud-trust-center/ trust_center: https://www.tigera.io/tigera-products/calico-cloud-trust-center/ held_by_provider: - name: SOC 2 quote: '"Calico Cloud is SOC 2, CCPA, GDPR compliant"' type_level: not stated (the page does not say Type I or Type II) - name: Cloud Security Alliance (CSA) quote: '"Calico Cloud is certified with Cloud Security Alliance"' note: Report available via the CSA STAR registry. - name: GDPR quote: '"Calico Cloud is SOC 2, CCPA, GDPR compliant"' - name: CCPA quote: '"Calico Cloud is SOC 2, CCPA, GDPR compliant"' - name: PCI DSS quote: '"Our payment processing system is PCI compliant"' scope_caveat: >- Reads as the BILLING system, not the Calico Cloud platform. Recorded with the caveat rather than promoted to a platform certification. penetration_testing: quote: '"perform yearly PEN test to ensure compliance and the report is available to customers upon request"' customer_enablement_only: note: >- Calico markets features that help CUSTOMERS meet PCI DSS, HIPAA, NIST and custom frameworks (https://www.tigera.io/features/compliance-and-audit/). Those are product capabilities, not Tigera certifications, and are deliberately NOT listed above. gaps_observed: - No ISO 27001 claim found. - No FedRAMP claim found. - No published sub-processor list found. - No published data-residency statement found. - No self-serve report request portal; SOC 2 and pen-test reports are "available upon request".