generated: '2026-07-18' method: derived source: openapi/devcycle-management-openapi.json + openapi/devcycle-bucketing-openapi.yaml + https://devcycle.com/security standards: - id: oauth2 conforms: true evidence: Management API uses OAuth2 client_credentials against auth.devcycle.com (Auth0 tenant) - id: oidc conforms: true evidence: auth.devcycle.com serves /.well-known/openid-configuration (OIDC discovery) - id: rfc8414-oauth-metadata conforms: true evidence: auth.devcycle.com serves /.well-known/oauth-authorization-server - id: rfc9116-security-txt conforms: true evidence: /.well-known/security.txt published on api/www/docs hosts - id: rfc9457-problem-details conforms: false evidence: errors use a custom { statusCode, message, error } envelope, not application/problem+json - id: openapi-3 conforms: true evidence: Management API is OpenAPI 3.0.0, Bucketing API is OpenAPI 3.1.0 - id: openfeature conforms: true evidence: DevCycle is OpenFeature-native and ships OpenFeature providers (e.g. @devcycle/openfeature-web-provider) - id: soc2-type2 conforms: true evidence: SOC 2 Type II published on devcycle.com/security - id: gdpr conforms: true evidence: full GDPR compliance published on devcycle.com/security - id: mcp conforms: true evidence: official MCP server registered as com.devcycle/mcp, hosted at mcp.devcycle.com compliance: published: true programs: [SOC 2 Type II, GDPR] page: https://devcycle.com/security notes: >- Conformance asserted from published specs, discovery documents, and DevCycle's security page. SOC 2 Type II and GDPR are published compliance programs, so a Compliance pointer is warranted.