generated: '2026-09-05' method: searched source: >- smithy/cloudfront-2020-05-31.json (AWS first-party model), https://aws.amazon.com/compliance/programs/, https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/ note: >- Reward-only. CloudFront is a CDN control plane; the content-delivery market has no bilateral API standard of the SCIM/OData/FHIR kind, so no domain standard is claimed. What it does declare, in the contract itself, is HTTP conditional requests (RFC 7232) and AWS SigV4 - both verifiable from the model. standards: - id: oauth2 conforms: false evidence: >- No oauth2 securityScheme anywhere in the model; authorization is IAM policy evaluated against a SigV4-signed request. - id: oidc conforms: false evidence: /.well-known/openid-configuration returned 404 on all five probed hosts (well-known/cloudfront-well-known.yml). - id: aws-sigv4 conforms: true evidence: 'aws.auth#sigv4 trait on the service shape, name "cloudfront" (smithy/cloudfront-2020-05-31.json)' - id: rfc7232-conditional-requests conforms: true evidence: >- ETag returned on 91 modeled structures; If-Match required on 51 request structures; PreconditionFailed modeled with HTTP 412. - id: rfc9457-problem-details conforms: false evidence: >- Errors are an XML ErrorResponse document (aws.protocols#restXml), not application/problem+json. Confirmed on a live 404 from https://cloudfront.amazonaws.com/ on 2026-09-05. - id: json-api conforms: false evidence: REST-XML protocol; no JSON representation of the control plane. - id: pagination conforms: true evidence: 'Marker/MaxItems + NextMarker/IsTruncated on 17 modeled list operations (smithy.api#paginated trait).' - id: idempotency conforms: partial evidence: >- CallerReference replay protection on 17 of 95 mutating operations; see conventions/cloudfront-conventions.yml idempotency.coverage = partial. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header support documented; no operation carries the smithy.api#deprecated trait. - id: rfc9116-security-txt conforms: true evidence: 'https://aws.amazon.com/.well-known/security.txt returned 200 with Policy, Contact, Expires and Encryption fields (well-known/cloudfront-security.txt).' - id: smithy-idl conforms: true evidence: >- AWS publishes the CloudFront service contract as a Smithy 2.0 JSON AST at github.com/aws/api-models-aws - 167 operations, 669 structures, 152 modeled error shapes. - id: fhir-r4 conforms: false - id: scim conforms: false - id: odata conforms: false - id: psd2 conforms: false domain_standard: applicable: false note: >- Content delivery has no adopted cross-vendor API standard (no CDN equivalent of SCIM or FHIR); CloudFront is not penalised for the absence and none is invented here. The nearest cross-cutting standards it DOES implement are recorded above (RFC 7232, RFC 9116, SigV4). compliance_program: published: true url: https://aws.amazon.com/compliance/programs/ certifications: - SOC 1 - SOC 2 - SOC 3 - ISO 27001 - ISO 27017 - ISO 27018 - PCI DSS Level 1 - HIPAA eligible - FedRAMP (High / Moderate) - GDPR - FIPS 140 (CloudFront FIPS endpoints) service_specific: - name: CloudFront in-scope services list url: https://aws.amazon.com/compliance/services-in-scope/ note: CloudFront is listed as in scope for PCI DSS, SOC, ISO, HIPAA and FedRAMP. evidence: security/cloudfront-trust-center.yml (probed 2026-09-05)