generated: '2026-08-17' method: searched source: https://trust.cloudexmachina.io/ + https://docs.cloudexmachina.io/setup/sso/okta note: >- Cloud ex Machina exposes no public API, so the API-shaped standards below (OpenAPI, AsyncAPI, RFC 9457, OAuth 2.0 as a provider, pagination, idempotency) are all recorded as non-conforming for the honest reason that there is no contract to conform. What IS published and verified is the organizational compliance posture on the Secureframe-hosted trust center, and SAML 2.0 single sign-on documented in the setup guide. standards: - id: soc2-type2 conforms: true evidence: 'trust.cloudexmachina.io states "SOC 2 Type 2" as an achieved certification' source: https://trust.cloudexmachina.io/ - id: iso-27001 conforms: false status: planned evidence: 'trust.cloudexmachina.io states verbatim "ISO 27001: Planned 2026."' source: https://trust.cloudexmachina.io/ - id: gdpr conforms: true evidence: 'trust.cloudexmachina.io states "GDPR: Data Processing Addendum (DPA) available."' source: https://trust.cloudexmachina.io/ - id: saml-2.0 conforms: true evidence: >- Okta SSO setup guide documents a SAML 2.0 integration federated into Amazon Cognito — RSA_SHA256 signature, SHA256 digest, signed response and assertion, unencrypted assertion, PasswordProtectedTransport authnContextClassRef source: https://docs.cloudexmachina.io/setup/sso/okta - id: oauth2 conforms: false evidence: >- OAuth 2.0 appears only as a client-side requirement Cloud ex Machina satisfies against third parties (ServiceNow client-credentials integration). Cloud ex Machina is not an OAuth authorization server; /.well-known/oauth-authorization-server returned no document on any host. - id: openid-connect conforms: false evidence: /.well-known/openid-configuration served no document on any of the four hosts - id: openapi conforms: false evidence: no OpenAPI or Swagger document found on any host (see x-coverage in apis.yml) - id: asyncapi conforms: false evidence: no event, streaming or webhook surface published for consumers - id: rfc9457-problem-details conforms: false evidence: no public API, therefore no documented error envelope - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt 404 on www.cloudexmachina.io, soft-200 HTML elsewhere - id: rfc8594-sunset-header conforms: false evidence: no deprecation or sunset policy published - id: a2a conforms: false evidence: no agent card at /.well-known/agent-card.json or /.well-known/agent.json on any host - id: mcp conforms: false evidence: >- no hosted MCP server; mcp.cloudexmachina.io does not resolve; app.cloudexmachina.io/mcp returns the application HTML shell subprocessors: source: https://trust.cloudexmachina.io/ entries: - {name: AWS, purpose: Cloud Provider} - {name: Google LLC, purpose: Google Cloud Platform, AI/ML services} - {name: Anthropic, purpose: AI/ML services} - {name: Nango, purpose: Product integrations} - {name: Sentry, purpose: Performance monitoring and error tracking}