generated: '2026-08-09' method: searched source: https://cmgx.io/workflow-management/ note: >- Capital Markets Gateway publishes no machine-readable contract, so nothing here is derived from a spec. Every entry below is either a regulatory regime CMG states its platform supports in its own public FAQ, or a cross-cutting API standard recorded as not-conformant because no public evidence exists either way. This file asserts what CMG says its PRODUCT supports; it is not a claim about CMG's own certifications — CMG publishes no SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP attestation on any public page, so no Compliance pointer is wired. standards: - id: finra-rule-5130 name: FINRA Rule 5130 (new issue eligibility) conforms: true scope: product-feature evidence: >- "CMG's Certificate Library allows sell-side firms to manage eligibility certificates across their investor population. Supported certificates types include FINRA Rules 5130/5131, Rule 144A QIB and Regulation S." source: https://cmgx.io/workflow-management/ - id: finra-rule-5131 name: FINRA Rule 5131 (spinning / new issue allocations) conforms: true scope: product-feature evidence: >- "Supported certificates types include FINRA Rules 5130/5131, Rule 144A QIB and Regulation S." source: https://cmgx.io/workflow-management/ - id: sec-rule-144a name: SEC Rule 144A (QIB) conforms: true scope: product-feature evidence: >- "Supported certificates types include FINRA Rules 5130/5131, Rule 144A QIB and Regulation S." CMG XC also states support for "convertible bond transactions (144A and SEC registered)". source: https://cmgx.io/workflow-management/ - id: sec-regulation-s name: SEC Regulation S (offshore offerings) conforms: true scope: product-feature evidence: >- "Supported certificates types include FINRA Rules 5130/5131, Rule 144A QIB and Regulation S." source: https://cmgx.io/workflow-management/ - id: audit-trail name: Full workflow audit trail with role-based access control conforms: true scope: product-feature evidence: >- "CMG XC maintains a full audit trail across every stage of the deal workflow, from offering launch through allocation and trade release. Role-based access controls create a clear record of who took which action at each stage." source: https://cmgx.io/workflow-management/ - id: oidc name: OpenID Connect conforms: unknown scope: platform-auth evidence: >- The CMG customer platform SPA declares REACT_APP_OIDC_AUTHORITY_BASE_URL = https://id.cmgecm.com in its public runtime-env.js, indicating OIDC-based platform sign-in. The authority publishes no anonymously reachable /.well-known/openid-configuration (every path 302s to /app/select-domain), so conformance cannot be verified and is not asserted. source: https://id.cmgecm.com/app/runtime-env.js - id: graphql name: GraphQL conforms: true scope: api-surface evidence: >- CMG describes the DataLab Real-Time Feed as a "GraphQL API" offering "flexible, schema-driven access" through "a single flexible endpoint". The endpoint is not published and introspection could not be attempted, so no SDL was captured. source: https://cmgx.io/data-insights/ - id: rest name: REST conforms: true scope: api-surface evidence: >- CMG describes a "REST API" providing "systemic support of the full ECM deal lifecycle from setup through allocation and post-trade". No endpoint, OpenAPI or reference is published. source: https://cmgx.io/workflow-management/ - id: openapi name: OpenAPI conforms: false evidence: >- No OpenAPI or Swagger document was found on any CMG host. Probed /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs and /redoc against cmgx.io and docs.cmgx.io — all 404 or 302-to-login. api./developer./docs.cmgecm.com are a wildcard SPA catch-all (byte-identical to a control subdomain), not real API hosts. - id: asyncapi name: AsyncAPI conforms: false evidence: >- An event surface (EventHub) is advertised but no AsyncAPI document is published. See asyncapi/capital-markets-gateway-eventhub.yml. - id: rfc9457-problem-details name: RFC 9457 Problem Details conforms: unknown evidence: No public error reference or spec exists to evaluate. - id: oauth2 name: OAuth 2.0 conforms: unknown evidence: >- No public authentication documentation and no anonymously reachable authorization-server metadata. x-evidence: fetched: '2026-08-09' urls: - url: https://cmgx.io/workflow-management/ status: 200 - url: https://cmgx.io/data-insights/ status: 200 - url: https://id.cmgecm.com/app/runtime-env.js status: 200 - url: https://cmgx.io/.well-known/security.txt status: 404