generated: '2026-08-11' method: searched source: >- openapi/credo-ai-governance-platform-swagger.json, openapi/credo-ai-audit-logs-shadow-ai-openapi.json, https://trust.credo.ai/, https://www.credo.ai/legal/vulnerability-disclosure-policy, https://credoai-cs.us.auth0.com/.well-known/openid-configuration standards: - id: json:api name: 'JSON:API 1.0' conforms: true confidence: high evidence: >- Top-level consumes/produces of application/vnd.api+json across all 300 Swagger operations; {data, included, meta} envelopes; {id, type, attributes, relationships} resource objects; errors[] with code/title/detail; filter[...]/sort/include query parameters; explicit /relationships/ sub-resources. deviations: - >- The OpenAPI 3.0.0 audit-log/Shadow-AI document uses application/json, and POST /shadow_ai/ai_events/bulk accepts either a JSON:API 'data' array or a plain 'events' array. Two conventions coexist in one API. - id: openapi name: OpenAPI 3.0.0 conforms: true confidence: high evidence: >- https://api.credo.ai/openapi returns a parsing OpenAPI 3.0.0 document with 10 paths / 11 operations, servers[], components.schemas and a BearerAuth security scheme. - id: swagger name: Swagger 2.0 conforms: true confidence: high evidence: >- https://api.credo.ai/swagger.json returns a parsing Swagger 2.0 document — 183 paths, 300 operations, 346 definitions, 26 tags, unique operationIds on 100% of operations. deviations: - 'No `host` and no `info.version` field; only `basePath: /api/v2/credoai`.' - >- A `webhooks` tag is declared with a description but carries zero operations. - id: oauth2 name: OAuth 2.0 conforms: partial confidence: medium evidence: >- The API itself does NOT use OAuth 2.0 — it uses a bearer JWT exchanged from a tenant API token at POST /auth/exchange, with no authorization server, no scopes and no consent step. Credo AI does operate an Auth0 tenant (credoai-cs.us.auth0.com) whose discovery document advertises authorization_code, client_credentials, refresh_token, device_code and token-exchange grants, but that governs the web application and Knowledge Center login, not the v2 API contract. - id: oidc name: OpenID Connect conforms: partial confidence: medium evidence: >- https://credoai-cs.us.auth0.com/.well-known/openid-configuration returns 200 with a valid OIDC discovery document (issuer, authorization_endpoint, token_endpoint, stock OIDC scopes). Served by Auth0, not by a credo.ai host, and not reachable from any credo.ai /.well-known/ path. - id: rfc9457 name: 'RFC 9457 Problem Details for HTTP APIs' conforms: false confidence: high evidence: >- Errors use the JSON:API errors[] envelope with application/vnd.api+json (or application/json), never application/problem+json. No type/title/status/detail/ instance members. - id: rfc9116 name: 'RFC 9116 security.txt' conforms: false confidence: high evidence: >- /.well-known/security.txt returns 404 on www.credo.ai, api.credo.ai, app.credo.ai, knowledge.credo.ai and docs.sdk.credo.ai — despite a published vulnerability disclosure policy naming security@credo.ai. - id: rfc8594 name: 'RFC 8594 Sunset header' conforms: false confidence: high evidence: >- No Sunset or Deprecation header is declared in either contract or observed on a live response; three operations carry `deprecated: true` with no sunset date. - id: pagination name: Cursor pagination conforms: true confidence: high evidence: >- page[after] / page[before] / page[limit] request parameters and a meta {after, before, limit} response block. Declared on only 10 of 300 operations even though far more return a paged response schema. - id: idempotency name: Idempotent request keys conforms: false confidence: high evidence: >- Zero occurrences of "idempoten" or "Idempotency-Key" in either published contract across 311 operations, 60 of which are POSTs. - id: soc2 name: 'SOC 2 Type II' conforms: true confidence: high evidence: >- "We maintain a SOC 2 Type II examination" — https://trust.credo.ai/ (Vanta trust center), fetched 2026-08-11. - id: iso42001 name: 'ISO/IEC 42001' conforms: unknown confidence: low evidence: >- Credo AI SELLS ISO 42001 readiness as a product capability (https://www.credo.ai/responsible-ai/iso-42001) but does not claim the certification for itself on its own trust center. Recorded as unknown rather than true — the sell/hold distinction is the point. - id: vulnerability-disclosure name: Coordinated vulnerability disclosure conforms: true confidence: high evidence: >- https://www.credo.ai/legal/vulnerability-disclosure-policy — scope, safe harbor, anonymous submissions, security@credo.ai. No bug bounty. regulatory_frameworks_productized: note: >- These are the regimes Credo AI's PLATFORM helps customers comply with. They are product surface, not Credo AI's own conformance, and are listed separately so the two are never conflated. frameworks: - EU AI Act - NIST AI RMF - ISO/IEC 42001 - NYC Local Law 144 - Colorado SB21-169 - OMB M-25 - NAIC AI guidelines summary: conforms: 6 partial: 2 does_not_conform: 4 unknown: 1