generated: '2026-08-09' method: searched source: >- https://cionic.com/platform, https://www.cionic.com/legal/data-disclosure, https://www.cionic.com/legal/privacy, and live probes of the CIONIC API surface note: >- CIONIC publishes no OpenAPI, so nothing here is derived from a spec. Every entry is either a compliance claim published on the company's own pages or an observation from an anonymous probe. standards: - id: oauth2 conforms: true evidence: >- GET https://cionic.com/oauth/authorize returns 302 to the portal login with a redir parameter; GET https://cionic.com/oauth/token returns 405 (POST-only); the first-party client sends Authorization: Bearer to /oauth/user and receives a platform token. Authorization-code shape, though no scope or metadata document is published. - id: oidc conforms: false evidence: >- /.well-known/openid-configuration soft-404s to the marketing homepage on every cionic.com host. - id: rfc8414-oauth-server-metadata conforms: false evidence: /.well-known/oauth-authorization-server not published on any host. - id: rfc9457-problem-details conforms: false evidence: >- Errors are a bare {"error": "message"} JSON object served as application/json; the /c service returns 401 with an empty body. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt not published on any cionic.com host. - id: rfc8615-well-known conforms: false evidence: >- No /.well-known document of any kind resolves; the marketing host answers 200 with the homepage for every path, which was confirmed as a soft 404 against a control path. - id: rfc8594-sunset-header conforms: false evidence: No Deprecation or Sunset headers observed. - id: hipaa conforms: true kind: regulatory evidence: >- "HIPAA-compliant patient management and data infrastructure" on the research platform page, and a published "Cionic HIPAA and Privacy Practices — Data Disclosure Policy". url: https://www.cionic.com/legal/data-disclosure - id: gdpr conforms: true kind: regulatory evidence: Dedicated EU GDPR data-subject rights section in the privacy policy. url: https://www.cionic.com/legal/privacy - id: ccpa conforms: true kind: regulatory evidence: California Consumer Privacy Act disclosures in the privacy policy. url: https://www.cionic.com/legal/privacy - id: fda-510k conforms: true kind: regulatory evidence: >- The Neural Sleeve 2 is marketed as "the only FDA-cleared system to improve walking by activating functional muscle movement and relaxing muscle spasms". No 510(k) clearance number is published on the site. url: https://www.cionic.com/neuralsleeve - id: irb conforms: true kind: research-governance evidence: >- "Our platform is currently used in IRB-approved studies" on the research platform page. url: https://cionic.com/platform - id: soc2 conforms: unknown evidence: No SOC 2 claim, trust centre or certification page found. - id: iso-27001 conforms: unknown evidence: No ISO 27001 claim found. gaps: - No machine-readable API contract of any kind (OpenAPI, AsyncAPI, GraphQL SDL, Postman collection, JSON Schema). - No public API reference; the only developer documentation is the open-source client repository README. - No OAuth scope or permission reference to accompany the authorization-code flow. - No security.txt and no vulnerability disclosure policy. - No trust centre or published certification set to back the HIPAA claim. x-evidence: - url: https://cionic.com/platform http_status: 200 fetched: '2026-08-09' - url: https://www.cionic.com/legal/data-disclosure http_status: 200 fetched: '2026-08-09' - url: https://www.cionic.com/legal/privacy http_status: 200 fetched: '2026-08-09' - url: https://cionic.com/oauth/authorize http_status: 302 fetched: '2026-08-09'