generated: '2026-08-17' method: searched source: >- https://cybelangel.com/solutions/compliance-cybelangel/, https://cybelangel.com/blog/cybelangel-achieves-iso-27001-certification/, https://cybelangel.com/blog/cybelangel-soc-2-type-1-certification-2026/, https://cybelangel.com/blog/cybelangel-renews-soc-2-type-1-compliance/, https://auth.cybelangel.com/.well-known/openid-configuration, https://developers.cybelangel.com/docs/alerts-api/3d22245755b86-alerts-in-stix-format + derived from the seven OpenAPI documents in openapi/ standards: - id: openapi-3.1 conforms: true evidence: 'All seven published specs declare openapi: 3.1.0 and parse cleanly (52 operations, 251 component schemas).' - id: oauth2 conforms: true evidence: >- openapi/cybelangel-platform-reports-openapi.yml declares a securityScheme of type oauth2 with a clientCredentials flow, tokenUrl https://auth.cybelangel.com/oauth/token and 10 named scopes; the docs publish the full token request. - id: oauth2-client-credentials-rfc6749 conforms: true evidence: 'grant_type=client_credentials against https://auth.cybelangel.com/oauth/token, documented on three separate auth pages.' - id: rfc6750-bearer-token conforms: true evidence: >- 'Authorization: Bearer ' on every protected endpoint; the Reports OpenAPI info.description cites RFC 6750 explicitly ("Authentication uses standard OAuth2 Bearer Tokens https://tools.ietf.org/html/rfc6750"). - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: 'https://auth.cybelangel.com/.well-known/oauth-authorization-server returns HTTP 200 with the full metadata document (Auth0 tenant).' - id: oidc-discovery conforms: true evidence: >- https://auth.cybelangel.com/.well-known/openid-configuration returns HTTP 200, issuer https://auth.cybelangel.com/, jwks_uri present, code_challenge_methods_supported [S256, plain], token_endpoint_auth_methods_supported includes private_key_jwt. note: >- This is the Auth0 tenant's conformance, inherited rather than built by CybelAngel — the APIs themselves only consume the tokens it issues. Recorded as conformant because the document is served on a cybelangel.com host. - id: jwt-rfc7519 conforms: true evidence: 'bearerFormat: JWT on the http bearer scheme in six specs; RS256 keys published at /.well-known/jwks.json.' - id: stix conforms: true standard_body: OASIS evidence: >- GET /v1/stix/alerts returns alerts as STIX; the docs publish a per-category STIX schema mapping for ADM, Board, Cloud drive, DNS, Database, Docshare, Codeshare, Fileserver, Leak and Paste alerts (RSS is explicitly "Not published in STIX"). source: https://developers.cybelangel.com/docs/alerts-api/3d22245755b86-alerts-in-stix-format - id: rfc9457-problem-details conforms: false evidence: >- Errors use a proprietary {"error": {"message"}} envelope as application/json. No application/problem+json anywhere, no type URI, no status member. - id: rfc9116-security-txt conforms: false evidence: >- A security-contact file is served, but at https://cybelangel.com/security.txt rather than /.well-known/security.txt (which 404s), it carries only Contact: and no Expires: (a MUST in RFC 9116), and the address is security@beapi.fr — the site's WordPress agency. - id: rfc8594-sunset-header conforms: false evidence: 'No Sunset or Deprecation response header is documented or declared, though one operation carries deprecated: true and three declare 410 Gone.' - id: ratelimit-headers conforms: false evidence: >- Numeric limits are published in prose (15 req/s, 20 concurrent, 2,000 tokens/month) but no X-RateLimit-*/RateLimit-*/Retry-After header is documented or declared in any spec. - id: idempotency-key conforms: false evidence: 'No Idempotency-Key (or equivalent) header/parameter in any of the 52 operations; no docs mention.' - id: cursor-pagination conforms: partial evidence: >- Cursor pagination on Alerts, ADM Inventory, Keywords, Audit Logs and Partner (cursor + limit; alerts_limit on the STIX variant), but skip/limit offset pagination on the Reports credential/domain watchlists and on Threat Intelligence. Two styles, one estate. - id: mcp conforms: false evidence: 'No MCP server published — searched the portal, changelog, GitHub org, npm and the MCP registries.' - id: a2a conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json probed on every host: 404 on cybelangel.com, api.cybelangel.com, auth.cybelangel.com and developers.cybelangel.com; HTTP 200 on platform.cybelangel.com but with the SPA's HTML shell, which is not a card. - id: asyncapi conforms: false not_applicable: true evidence: >- No event, streaming or webhook surface exists to describe — no AsyncAPI, no webhooks, no callbacks in any spec, no webhook page in the docs. "Alerts in Feed" is a polled REST feed (cursor + date window), not a push channel, and CybelAngel Connect subscribes by polling through Workato. Scored N/A rather than failing. - id: graphql conforms: false evidence: 'No /graphql surface on any host; nothing in the docs.' compliance_program: published: true page: https://cybelangel.com/solutions/compliance-cybelangel/ certifications: - name: ISO/IEC 27001:2022 auditor: A-LIGN achieved: early 2026 source: https://cybelangel.com/blog/cybelangel-achieves-iso-27001-certification/ - name: SOC 2 Type I auditor: A-LIGN Assurance signed_off: '2026-01-31' renewed: true source: https://cybelangel.com/blog/cybelangel-soc-2-type-1-certification-2026/ also: https://cybelangel.com/blog/cybelangel-renews-soc-2-type-1-compliance/ not_claimed: [SOC 2 Type II, PCI DSS, HIPAA, FedRAMP, 'CSA STAR', 'FIPS 140'] regimes_supported_for_customers: - {id: nist-csf-2.0, role: 'CybelAngel supports NIST CSF 2.0 by delivering external risk visibility and actionable threat intelligence'} - {id: dora, role: 'external risk monitoring for third-party risk and vulnerability visibility'} - {id: nis2, role: 'proactive threat detection and vulnerability management'} - {id: gdpr, role: 'https://cybelangel.com/data-processing-policy/ and https://cybelangel.com/privacy-policy/'} note: >- Read carefully: ISO 27001 and SOC 2 Type I are certifications CybelAngel HOLDS. NIST CSF 2.0, DORA and NIS 2 are regimes CybelAngel helps its CUSTOMERS meet — they are product positioning, not CybelAngel's own attestations, and are recorded separately for that reason. There is no trust center (trust.cybelangel.com does not resolve) and no downloadable attestation portal, which is why apis.yml carries a `Compliance` pointer but no `TrustCenter`.