generated: '2026-08-04' method: searched source: >- openapi/clozd-data-api-v3-openapi.yml, https://oauth.clozd.com/.well-known/oauth-authorization-server, https://www.clozd.com/privacy/gdpr, https://www.clozd.com/privacy/policy, https://trust.clozd.com standards: - id: openapi-3.0.3 conforms: true evidence: All three published Clozd Data API specs declare openapi 3.0.3 with paths and components. - id: openapi-3.1 conforms: false evidence: Specs are pinned to 3.0.3. - id: oauth2 conforms: true evidence: >- https://oauth.clozd.com publishes RFC 6749 authorization_code, client_credentials and refresh_token grants at /authorize and /token. - id: oauth2-pkce-rfc7636 conforms: true evidence: code_challenge_methods_supported = [S256] in the authorization server metadata. - id: oauth2-authorization-server-metadata-rfc8414 conforms: true evidence: https://oauth.clozd.com/.well-known/oauth-authorization-server returns 200 application/json. - id: oauth2-protected-resource-metadata-rfc9728 conforms: true evidence: >- https://mcp.clozd.com/.well-known/oauth-protected-resource/mcp returns 200 and is advertised in the WWW-Authenticate header of the 401 from POST /mcp. - id: oauth2-dynamic-client-registration-rfc7591 conforms: true evidence: registration_endpoint https://oauth.clozd.com/register advertised in the AS metadata. - id: oauth2-token-revocation-rfc7009 conforms: true evidence: revocation_endpoint https://oauth.clozd.com/revoke advertised in the AS metadata. - id: oauth2-token-introspection-rfc7662 conforms: true evidence: introspection_endpoint https://oauth.clozd.com/introspect advertised in the AS metadata. - id: oidc-discovery conforms: true evidence: >- https://oauth.clozd.com/.well-known/openid-configuration returns 200 with issuer, jwks_uri, userinfo endpoint and RS256 id_token signing. - id: jwks-rfc7517 conforms: true evidence: https://oauth.clozd.com/.well-known/jwks.json returns 200. - id: saml2 conforms: true evidence: >- Platform SSO is documented for SAML with Okta, Microsoft Entra and OneLogin (https://help.clozd.com/hc/en-us/articles/45409542002587-Single-Sign-On-SSO). - id: model-context-protocol conforms: true evidence: >- Hosted streamable-HTTP MCP server at https://mcp.clozd.com/mcp with 19 published tools; JSON-RPC 2.0 request to tools/list returns a structured 401, confirming a live MCP endpoint. - id: a2a conforms: false evidence: >- No agent card at /.well-known/agent-card.json or /.well-known/agent.json on any Clozd host (app, mcp, www, apex). SPA hosts return an HTML shell, not JSON. - id: rfc9457-problem-details conforms: false evidence: >- Errors use a proprietary {success, message, errorCode, data} envelope with application/json, not application/problem+json. - id: json-api conforms: false evidence: Responses are a custom wrapper, not JSON:API. - id: rfc8594-sunset-header conforms: false evidence: No deprecation or sunset policy published; no operation marked deprecated. - id: rfc9116-security-txt conforms: false evidence: No /.well-known/security.txt on any Clozd host. - id: rfc8615-well-known-uris conforms: partial evidence: >- OAuth/OIDC well-known documents are served correctly, but app.clozd.com and mcp.clozd.com answer 200 with an SPA HTML shell for unknown /.well-known/* paths instead of 404, which breaks well-known discovery for any consumer that trusts status codes. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface is published; incremental sync is poll-based via filter[*_updated_since]. - id: llms-txt conforms: false evidence: /llms.txt returns 404 on clozd.com and www.clozd.com; no docs host publishes one. - id: iso-27001 conforms: true evidence: >- "Clozd is ISO 27001 compliant and maintains industry-best technical and organizational security measures" — https://www.clozd.com/privacy/gdpr; site navigation states "ISO 27001 and 27701 certified". - id: iso-27701 conforms: true evidence: Site navigation on every clozd.com page states "Clozd is ISO 27001 and 27701 certified". - id: soc2-type-ii conforms: true evidence: >- "Clozd is audited annually for ISO 27001 and SOC 2 Type II compliance" — https://www.clozd.com/privacy/gdpr - id: gdpr conforms: true evidence: >- Dedicated GDPR page (https://www.clozd.com/privacy/gdpr); privacy policy documents Standard Contractual Clauses for EEA transfers, the UK Addendum for UK transfers, and Swiss-modified SCCs; DPA with SCCs offered to clients; privacy@clozd.com as the data-subject request channel. - id: hipaa conforms: false evidence: >- Terms of use state the site "is not tailored to comply with industry-specific regulations (HIPAA, FISMA, etc.)". compliance_program: published: true trust_center: https://trust.clozd.com trust_center_platform: Vanta compliance_page: https://www.clozd.com/privacy/gdpr certifications: - ISO 27001 - ISO 27701 - SOC 2 Type II regulatory: - GDPR - UK GDPR - Swiss FADP audit_cadence: annual