generated: '2026-08-14' method: probed source: live probes of api.cerenovus.ai and www.cerenovus.ai note: >- Derived from what Cerenovus actually serves, not from any compliance claim. There is no OpenAPI, no AsyncAPI and no GraphQL SDL to test against, so the standards below are limited to the discovery, authorization and agent-protocol layer the company does serve. Cerenovus states on its own trust page that SOC 2 Type II and ISO 27001 are in progress and not yet awarded — so no certification is asserted here and no Compliance pointer is emitted. standards: - id: oauth2 conforms: true evidence: >- authorization_code + refresh_token grants advertised at https://api.cerenovus.ai/.well-known/oauth-authorization-server - id: rfc8414-authorization-server-metadata conforms: true evidence: 200 JSON at /.well-known/oauth-authorization-server with issuer, authorization_endpoint, token_endpoint - id: rfc9728-protected-resource-metadata conforms: true evidence: 200 JSON at /.well-known/oauth-protected-resource with resource, authorization_servers, scopes_supported - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported = [S256] - id: rfc7591-dynamic-client-registration conforms: true evidence: registration_endpoint https://api.cerenovus.ai/register (405 on GET, POST-only) - id: rfc6750-bearer-token conforms: true evidence: 401 response carries WWW-Authenticate Bearer error="invalid_token" - id: rfc9116-security-txt conforms: true evidence: >- https://www.cerenovus.ai/.well-known/security.txt returns 200 text/plain with Contact, Expires, Preferred-Languages and Canonical fields - id: mcp-authorization conforms: true evidence: >- 401 from https://api.cerenovus.ai/mcp carries a resource_metadata parameter in WWW-Authenticate, the MCP authorization spec discovery mechanism - id: llms-txt conforms: true evidence: https://www.cerenovus.ai/llms.txt returns 200 text/plain, 11184 bytes - id: openid-connect conforms: false evidence: /.well-known/openid-configuration returns 404 on both hosts - id: openapi conforms: false evidence: no OpenAPI or Swagger document found on any Cerenovus host - id: asyncapi conforms: false evidence: no event, webhook or streaming surface documented or discovered - id: rfc9457-problem-details conforms: false evidence: >- error responses use the OAuth 2.0 error/error_description envelope, not application/problem+json - id: a2a conforms: false evidence: no agent card at /.well-known/agent-card.json or /.well-known/agent.json on any host - id: soc2 conforms: false evidence: >- https://www.cerenovus.ai/trust-and-security states SOC 2 Type II certification is in process, not awarded - id: iso-27001 conforms: false evidence: >- https://www.cerenovus.ai/trust-and-security states ISO 27001 certification is in process, not awarded x-evidence: fetched: '2026-08-14'