generated: '2026-07-18' method: searched source: https://www.definite.app/security docs: - https://www.definite.app/security - https://api.definite.app/.well-known/oauth-authorization-server standards: - id: oauth2 conforms: true evidence: >- /.well-known/oauth-authorization-server advertises authorization_code + refresh_token grants for MCP auth. - id: oauth2.1-pkce conforms: true evidence: code_challenge_methods_supported [S256] in authorization-server metadata. - id: rfc8414-oauth-authorization-server conforms: true evidence: /.well-known/oauth-authorization-server returns 200 with issuer/endpoints. - id: mcp conforms: true evidence: >- Native Model Context Protocol server at /v3/mcp/http with 40+ tools; scope "mcp" in OAuth metadata. - id: oidc-discovery conforms: false evidence: /.well-known/openid-configuration returns 404 on api.definite.app. - id: soc2-type-ii conforms: partial evidence: 'Security page: SOC 2 Type II audit underway, interim Type I available on request.' - id: hipaa conforms: true evidence: 'Security page: BAA available for Enterprise customers with PHI workloads.' - id: gdpr conforms: true evidence: 'Security page: GDPR compliant, DPA and EU data processing agreements available.' - id: ccpa conforms: true evidence: 'Security page: CCPA compliant, honors California consumer data rights.' - id: rfc9457-problem-details conforms: false evidence: No application/problem+json error envelope documented.