generated: '2026-08-09' method: searched source: https://www.certificial.com/coi-issuance-api note: >- No OpenAPI, AsyncAPI, GraphQL SDL or JSON Schema is published by Certificial, so nothing here is derived from a machine-readable contract. Every entry below is either an explicit claim Certificial publishes on its own site, or a negative result recorded from a live anonymous probe. standards: - id: acord-forms name: ACORD certificate of insurance forms (24, 25, 27, 28, 101) conforms: true evidence: >- The COI Issuance API product page states the API generates certificates using ACORD standards — specifically ACORD 24, 25, 27, 28 and 101 forms. source: https://www.certificial.com/coi-issuance-api - id: acord-standards-partnership name: ACORD standards partnership conforms: true evidence: >- Certificial published a partnership announcement with ACORD covering delivery of certificates of insurance. Certificial's co-founder and CEO is the former CEO of ACORD Solutions Group. source: https://www.certificial.com/blog-post/certificial-partners-with-acord-to-revolutionize-delivery-of-certificates-of-insurance - id: oauth2 conforms: false evidence: >- No OAuth authorization-server metadata is served. /.well-known/oauth-authorization-server on my.certificial.com answers 200 with the SPA HTML shell (soft-404), and /api/oauth/token returns 404. The observed challenge is an opaque token scheme. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns the SPA HTML shell, not an OIDC document. - id: rfc9457-problem-details conforms: false evidence: >- The observed 401 error envelope is application/json with a bare `detail` string (Django REST Framework default), not application/problem+json. - id: rfc9116-security-txt conforms: false evidence: https://www.certificial.com/.well-known/security.txt returns 404. - id: rfc8615-well-known conforms: false evidence: >- No /.well-known document is served on the marketing host (all 404) and the application host answers every /.well-known/* path with an identical HTML shell. compliance_program: published: false note: >- No trust center, security page, or named certification (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP) was found. /security, /trust and /compliance on www.certificial.com all return 404, and trust.certificial.com does not resolve. No `Compliance` pointer is emitted.