generated: '2026-08-09' method: derived source: - openapi/ (19 published OpenAPI 3.1.0 documents) - https://www.chilipiper.com/security - https://fire.chilipiper.com/.well-known/oauth-protected-resource standards: - id: openapi-3.1 conforms: true evidence: 'All 19 published documents declare openapi: 3.1.0 and parse cleanly.' - id: mcp conforms: true evidence: 'Hosted streamable-HTTP MCP server at https://fire.chilipiper.com/api/fire-edge/v1/org/mcp; responds to JSON-RPC tools/list with 401 when anonymous.' - id: rfc9728-oauth-protected-resource conforms: true evidence: '/.well-known/oauth-protected-resource returns valid JSON metadata for the MCP resource.' - id: oauth2 conforms: true evidence: 'Browser-based OAuth authorization is documented for the MCP server (Admin only).' - id: rfc6750-bearer-token conforms: true evidence: 'Authorization: Bearer required on every Edge API operation; bearer_methods_supported=[header].' - id: rfc9457-problem-details conforms: false evidence: 'All declared 4xx/default responses are text/plain; no application/problem+json anywhere in the published specs.' - id: rfc9116-security-txt conforms: false evidence: 'https://www.chilipiper.com/.well-known/security.txt -> 404.' - id: rfc8594-sunset-header conforms: false evidence: 'No Sunset or Deprecation header support and no deprecation policy published.' - id: asyncapi conforms: false evidence: 'Webhooks are documented in prose with one example payload; no AsyncAPI document and no payload schema published.' - id: openid-connect conforms: false evidence: 'No /.well-known/openid-configuration served on any host. SAML SSO (Okta, Azure, custom) is offered for app login, not as an API auth surface.' - id: a2a conforms: false evidence: 'No agent card at /.well-known/agent-card.json or /.well-known/agent.json on any host.' - id: graphql conforms: false evidence: 'No GraphQL surface found.' - id: json-api conforms: false - id: scim conforms: false evidence: 'User and license provisioning is offered through proprietary Edge API operations (userInvite, userUpdateLicenses), not SCIM 2.0.' compliance_program: published: true url: https://www.chilipiper.com/security trust_center: https://trust.chilipiper.com/ certifications: [SOC 2, ISO 27001, GDPR] see: security/chili-piper-trust-center.yml