generated: '2026-08-09' method: searched source: https://dara.causalens.com/docs/ , https://raw.githubusercontent.com/causalens/dara/master/packages/dara-core/changelog.md scope: 'Dara open-source application framework. No claim is made about the commercial decisionOS platform, whose documentation is login-gated.' standards: - id: oidc name: OpenID Connect conforms: true evidence: 'dara-core ships an OIDC authentication path; the 1.29.6 OpenTelemetry work explicitly instruments "authentication and OIDC" as a covered code path, and dara.core.auth publishes base/basic/definitions/routes modules.' evidence_url: https://dara.causalens.com/docs/generated/dara/reference/dara/core/auth/base confidence: medium note: 'OIDC support is present in the framework, but no OIDC discovery document is served by causaLens itself (/.well-known/openid-configuration is 404 on every host that answers honestly) — the identity provider is supplied by the operator.' - id: oauth2 name: OAuth 2.0 conforms: false evidence: 'No OAuth 2.0 authorization-server metadata (RFC 8414) and no /.well-known/oauth-authorization-server or /.well-known/oauth-protected-resource on any causaLens host. Dara uses a bearer JWT session token plus a refresh-token cookie issued by the application itself, not an OAuth flow.' confidence: high - id: jwt name: JSON Web Token (RFC 7519) conforms: true evidence: 'Session tokens are JWTs verified at POST /verify-session, signed with a JWT_SECRET; refresh tokens are exchanged at POST /refresh-token.' evidence_url: https://dara.causalens.com/docs/generated/dara/reference/dara/core/auth/routes confidence: high - id: opentelemetry name: OpenTelemetry conforms: true evidence: 'Opt-in, explicitly vendor-neutral OpenTelemetry traces, logs and metrics added in dara-core 1.29.6 via Pydantic Logfire, covering HTTP, startup/shutdown, auth/OIDC, actions, WebSockets, tasks, workers and scheduled jobs.' evidence_url: https://raw.githubusercontent.com/causalens/dara/master/packages/dara-core/changelog.md confidence: high - id: w3c-trace-context name: W3C Trace Context conforms: true evidence: Cross-process W3C context propagation is named in the 1.29.6 telemetry work. confidence: high - id: prometheus name: Prometheus exposition conforms: true evidence: 'dara-core exposes a Prometheus endpoint including HTTP request stats; collectors were isolated from the process-wide default registry in 1.29.4.' confidence: high - id: sse name: Server-Sent Events conforms: true evidence: StreamVariable uses SSE with configurable keepalive comments. confidence: high - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: 'No application/problem+json usage documented; errors follow the FastAPI default JSON `detail` envelope.' confidence: medium - id: rfc9116 name: RFC 9116 security.txt conforms: false evidence: '/.well-known/security.txt returns 404 on every causaLens host that answers honestly, and only the login-wall HTML on the two gated hosts.' confidence: high - id: rfc8594 name: RFC 8594 Sunset header conforms: false evidence: No Sunset or Deprecation header support is documented. confidence: medium - id: openapi name: OpenAPI conforms: false evidence: 'No OpenAPI document is published on any causaLens host. Dara is built on FastAPI, which can generate one at runtime for a deployed app, but causaLens publishes no spec for the framework''s own routes and none for decisionOS.' confidence: high - id: semver name: Semantic Versioning conforms: true evidence: All PyPI and npm packages release under semver with Python/JS halves kept in lockstep (both at 1.29.7). confidence: high certifications: published: false notes: 'No trust center, no certification page and no textual SOC 2 / ISO 27001 / HIPAA / PCI / FedRAMP claim was found in the causalens.com page source. trust.causalens.com does not resolve; /security, /trust and /compliance return 404. No `Compliance` pointer is emitted, because there is no published claim to point at.' probed: - url: https://causalens.com/security status: 404 - url: https://causalens.com/trust status: 404 - host: trust.causalens.com status: NXDOMAIN licensing: open_source_license: Apache-2.0 applies_to: - dara-core - dara-components - create-dara-app - '@darajs/*'