generated: '2026-08-27' method: derived source: >- Derived by reading the three published contracts in openapi/ for declared standard signatures, cross-checked against Elastic's own documentation and trust center (https://www.elastic.co/trust). Every `conforms: true` below cites the exact location in a contract or a probed URL. standards: - id: openapi name: OpenAPI Specification version: 3.0.3 conforms: true evidence: >- openapi/elk-stack-elasticsearch-openapi.json and openapi/elk-stack-kibana-openapi.yaml both declare "openapi": "3.0.3". Generated by Elastic from elastic/elasticsearch-specification and elastic/kibana respectively. - id: swagger name: Swagger / OpenAPI 2.0 version: '2.0' conforms: true evidence: >- openapi/elk-stack-elastic-cloud-swagger.json declares "swagger": "2.0" and is served live from https://api.elastic-cloud.com/api/v1/api-docs/swagger.json (HTTP 200, application/json, 1,191,717 bytes on 2026-08-27). The Elastic Cloud control plane has not been migrated to OpenAPI 3.x. - id: oauth2 name: OAuth 2.0 / OAuth 2.1 conforms: partial evidence: >- Not declared as a securityScheme in any of the three contracts — the declared schemes are apiKey (Authorization: ApiKey) and HTTP Basic only. OAuth appears as a FEATURE Elastic implements rather than as its own API's auth: Elasticsearch ships OIDC realm operations, and Elastic documents OAuth 2.1 for interactive MCP clients on Serverless projects (https://www.elastic.co/docs/explore-analyze/ai-features/agent-builder/mcp-server). An agent authenticating to the Elasticsearch, Kibana or Cloud REST APIs uses an API key, not an OAuth token. - id: oidc name: OpenID Connect conforms: true evidence: >- Elasticsearch publishes a full OIDC relying-party surface as first-class operations in openapi/elk-stack-elasticsearch-openapi.json — security-oidc-prepare-authentication (POST /_security/oidc/prepare), security-oidc-authenticate (POST /_security/oidc/authenticate) and security-oidc-logout (POST /_security/oidc/logout). note: Elastic is an OIDC RELYING PARTY here, not an OIDC provider for its own API. - id: saml2 name: SAML 2.0 (OASIS) conforms: true evidence: >- Nine SAML operations in the Elasticsearch contract, including security-saml-service-provider-metadata (GET /_security/saml/metadata/{realm_name}), which emits standard SAML SP metadata XML, plus prepare/authenticate/logout/complete_logout/invalidate. - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: >- Zero occurrences of application/problem+json across all three contracts. Each surface ships its own vendor JSON error envelope. See errors/elk-stack-problem-types.yml. - id: rfc8594 name: RFC 8594 Sunset HTTP Header conforms: false evidence: >- Zero occurrences of Sunset or Deprecation response headers in any contract, despite 96 operations carrying `deprecated: true`. Deprecation is build-time metadata only. See lifecycle/elk-stack-lifecycle.yml. - id: rfc9116 name: RFC 9116 security.txt conforms: true evidence: >- https://api.elastic-cloud.com/.well-known/security.txt returns HTTP 200 text/plain with Contact, Encryption, Hiring and Policy fields. Saved verbatim as well-known/elk-stack-security.txt. note: >- Not served on www.elastic.co (404). The file also omits the `Expires` field that RFC 9116 makes mandatory, so it is a partial implementation. - id: rfc9727 name: RFC 9727 api-catalog well-known URI conforms: false evidence: >- /.well-known/api-catalog returns HTTP 200 on api.elastic-cloud.com but the body is a 9,582-byte SPA HTML shell identical to the one returned for /.well-known/oauth-authorization-server — a catch-all, not a catalog. - id: mcp name: Model Context Protocol conforms: true evidence: >- POST /api/agent_builder/mcp declared in openapi/elk-stack-kibana-openapi.yaml with operationId post-agent-builder-mcp, carrying MCP initialize request/response examples inline. Marked "Experimental; added in 9.2.0". A separate standalone server is distributed as docker.elastic.co/mcp/elasticsearch. See mcp/elk-stack-mcp.yml. - id: a2a name: Agent2Agent (A2A) Protocol conforms: partial evidence: >- Kibana declares GET /api/agent_builder/a2a/{agentId}.json (agent card) and POST /api/agent_builder/a2a/{agentId} (send task) in its published OpenAPI, and the example card carries name, url, version, skills[] with inputModes and outputModes. But the card is served from the CUSTOMER's deployment — every probe of /.well-known/agent-card.json and /.well-known/agent.json on Elastic's own hosts returned 404 — so Elastic itself publishes no agent card and no a2a/ artifact is claimed for this provider. - id: pagination name: Pagination conforms: true evidence: >- Elasticsearch declares `from` + `size` for shallow paging, `search_after` for deep paging, `scroll` for cursor iteration, and point-in-time (open-point-in-time / close-point-in-time) for consistent deep pagination. All are named parameters in openapi/elk-stack-elasticsearch-openapi.json. - id: idempotency name: Idempotency conforms: partial evidence: >- No Idempotency-Key header anywhere in the three contracts. Elastic instead documents idempotency SEMANTICALLY: Kibana's Security Detections bulk edit action states per-action which operations are idempotent and which are not ("The edit action is idempotent... The only exception is add_rule_actions and set_rule_actions, which is non-idempotent"), and Elasticsearch offers natural idempotence via PUT-with-explicit-_id plus optimistic concurrency control on if_seq_no / if_primary_term. See conventions/elk-stack-conventions.yml. - id: compliance-certifications name: Third-party security certifications conforms: true evidence: >- https://www.elastic.co/trust (HTTP 200) names FedRAMP High, FedRAMP Moderate, PCI DSS Level 1 Service Provider, CSA STAR, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, SOC 2, SOC 3, TISAX, HIPAA, Cyber Essentials Plus and IRAP Protected B, with reports available through the assurance portal at assurance.elastic.co. See security/elk-stack-trust-center.yml. domain_standards: - id: mitre-attack name: MITRE ATT&CK market: Security operations / SIEM / detection engineering conforms: true evidence: >- The Kibana Security Detections API models detection-rule threat mapping directly on ATT&CK in the CONTRACT, not in marketing prose: openapi/elk-stack-kibana-openapi.yaml carries a `threat[]` object whose members are { framework: "MITRE ATT&CK", tactic: { id: TA0001, name: "Initial Access", reference: https://attack.mitre.org/tactics/TA0001 }, technique: [ { id: T1193, ... } ] }. The Attack Discovery API description states discoveries are mapped to "the MITRE ATT&CK matrix". why_it_matters: >- A SOC that already speaks ATT&CK can map Elastic detection rules onto its existing coverage matrix with no bespoke connector; the tactic and technique identifiers are the interchange keys the whole detection-content market shares (Sigma, ATT&CK Navigator, D3FEND). - id: ecs name: Elastic Common Schema (ECS) market: Observability and security telemetry conforms: true evidence: >- ECS is referenced 132 times in the Kibana contract (ecs_mapping on Osquery saved queries and packs, ECS field mappings on detection rules) and 38 times in the Elasticsearch contract. note: >- ECS is Elastic's own schema, donated to the OpenTelemetry project in 2023 and merged into OpenTelemetry Semantic Conventions. Counted here because it is a published, adopted cross-vendor field schema, but it originates with this provider rather than being an external standard Elastic conformed to. - id: opentelemetry name: OpenTelemetry / OTLP market: Observability conforms: unverified evidence: >- Elastic ships EDOT (Elastic Distribution of OpenTelemetry) SDKs and an OTLP ingest endpoint, and its EOL feed lists EDOT SDKs as maintained products. But zero occurrences of "opentelemetry" or "otlp" appear in any of the three published OpenAPI contracts, so nothing was recorded as conformant on contract evidence. The OTLP endpoint is a gRPC/protobuf surface described outside these files. note: >- Deliberately left unverified rather than asserted. Confirming it needs the OTLP protobuf definitions, which Elastic consumes from the CNCF rather than publishing itself.