generated: '2026-08-14' method: probed source: >- live probes of https://mcp.cloverleaf.ai/ and https://auth.cloverleaf.ai/.well-known/openid-configuration standards: - id: mcp name: Model Context Protocol conforms: true evidence: >- https://mcp.cloverleaf.ai/ answers OPTIONS with allow-methods GET,POST,OPTIONS and exposes Mcp-Session-Id, and accepts allow-headers mcp-session-id and mcp-protocol-version — the Streamable HTTP transport contract. /health reports service "cloverleaf-ai-mcp". - id: oauth2 name: OAuth 2.0 (RFC 6749) conforms: true evidence: authorization_code + refresh_token grants advertised at auth.cloverleaf.ai - id: rfc6750-bearer name: OAuth 2.0 Bearer Token Usage conforms: true evidence: >- 401 responses carry WWW-Authenticate: Bearer error="invalid_token" with an error_description, per RFC 6750 section 3 - id: rfc9728-protected-resource-metadata name: OAuth 2.0 Protected Resource Metadata conforms: true evidence: >- /.well-known/oauth-protected-resource returns 200 with resource, authorization_servers, scopes_supported and resource_name; the 401 challenge also carries the resource_metadata parameter that RFC 9728 defines - id: rfc8414-authorization-server-metadata name: OAuth 2.0 Authorization Server Metadata conforms: true evidence: /.well-known/oauth-authorization-server returns 200 on both mcp. and auth. hosts - id: oidc-discovery name: OpenID Connect Discovery 1.0 conforms: true evidence: >- https://auth.cloverleaf.ai/.well-known/openid-configuration returns 200 with issuer, jwks_uri, userinfo_endpoint and claims_supported - id: rfc7636-pkce name: PKCE conforms: true evidence: code_challenge_methods_supported includes S256 - id: rfc7591-dynamic-client-registration name: OAuth 2.0 Dynamic Client Registration conforms: true evidence: registration_endpoint https://auth.cloverleaf.ai/oidc/register advertised - id: rfc9449-dpop name: DPoP (Demonstrating Proof of Possession) conforms: true evidence: dpop_signing_alg_values_supported ["ES256"] in the OIDC discovery document - id: openapi name: OpenAPI conforms: false evidence: >- no OpenAPI/Swagger document at any probed path on api.cloverleaf.ai, mcp.cloverleaf.ai, app.cloverleaf.ai or www.cloverleaf.ai - id: asyncapi name: AsyncAPI conforms: false evidence: no event, streaming or webhook surface is published - id: rfc9457-problem-details name: Problem Details for HTTP APIs conforms: false evidence: >- errors are the OAuth 2.0 JSON envelope {"error","error_description"}, content-type application/json — not application/problem+json - id: rfc9116-security-txt name: security.txt conforms: false evidence: /.well-known/security.txt returns 404 on www.cloverleaf.ai - id: a2a name: A2A Agent Card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json return 404 on www., mcp. and api.cloverleaf.ai compliance_program: published: false note: >- A Vanta-hosted trust center exists at https://trust.cloverleaf.ai/ but it renders client-side and the served HTML names no certification, so no SOC 2 / ISO 27001 / HIPAA / FedRAMP claim can be verified from the public surface. No Compliance pointer is emitted; see security/cloverleaf-ai-trust-center.yml.