generated: '2026-07-18' method: searched source: >- https://api.domesystems.ai/.well-known/oauth-authorization-server + https://login.domesystems.ai/.well-known/openid-configuration standards: - id: oauth2 conforms: true evidence: Published RFC 8414 authorization-server metadata at api.domesystems.ai (client_credentials grant, token endpoint, JWKS). - id: oauth2-client-credentials conforms: true evidence: grant_types_supported includes client_credentials; token_endpoint_auth_methods_supported includes client_secret_basic. - id: oidc conforms: true evidence: Published OpenID Connect discovery document at login.domesystems.ai (authorization/token/userinfo/jwks endpoints, RS256 id_token). - id: oauth2-device-code conforms: true evidence: device_authorization_endpoint and urn:ietf:params:oauth:grant-type:device_code advertised at login.domesystems.ai. - id: rfc8414-as-metadata conforms: true evidence: /.well-known/oauth-authorization-server served at the API host. - id: rfc9116-security-txt conforms: true evidence: /.well-known/security.txt published at domesystems.ai. - id: cedar-authorization conforms: true evidence: Authorization is expressed as Cedar policy evaluated at the call boundary (per product docs / llms.txt). - id: rfc9457-problem-details conforms: false evidence: No public OpenAPI available (docs access-gated); error envelope not verified. notes: - No published compliance certifications (SOC 2, ISO 27001, PCI, HIPAA, FedRAMP) were found; no Compliance pointer is emitted.