generated: '2026-09-06' method: searched source: https://docs.envzero.com (guides + API reference), https://docs.envzero.com/guides/overview/security-overview note: >- Assertions below come from env zero's own published surfaces. Where a standard is claimed only in prose it is marked as such; where the contract itself declares the standard (SCIM discovery endpoints, CloudEvents webhook envelope) the evidence names the exact location. standards: - id: scim-2.0 name: SCIM 2.0 (RFC 7643 / RFC 7644) conforms: true domain_standard: true evidence: >- env zero publishes the SCIM self-describing discovery triple - /scim/v2/ServiceProviderConfig, /scim/v2/ResourceTypes and /scim/v2/Schemas - and documents "For any other IdP that supports SCIM 2.0, point it at the same endpoint with the bearer token in the Authorization header." Provisioning modes, group push to env zero teams, token rotation with a 24h grace window and a reconcile/diff job are all exposed as REST operations under the Users section of the reference. evidence_url: https://docs.envzero.com/guides/sso-integrations/scim-provisioning#set-up-scim supported_features: [filtering, discovery endpoints, group push, token rotation] unsupported_features: [sorting, bulk operations, ETags] unsupported_note: env zero states these plainly rather than leaving them to be discovered - "Filtering is supported; sorting, bulk operations, and ETags are not." certified_integrations: [Okta, Microsoft Entra ID] ga_date: '2026-08' - id: cloudevents-1.0 name: CloudEvents 1.0 conforms: true domain_standard: true evidence: >- Every webhook delivery uses the CloudEvents structured JSON envelope - type, source, id, time, datacontenttype, data - with reverse-DNS event types (com.env-zero.deploy.succeeded). The binding is CloudEvents-SHAPED rather than a declared CloudEvents implementation - env zero does not name the specification, and it does not send the ce-* HTTP binding headers, using its own x-env-zero-event / x-env-zero-event-id / x-env-zero-signature instead. evidence_url: https://docs.envzero.com/guides/integrations/notifications/webhooks caveat: shape matches; conformance is not claimed by the provider - id: oidc name: OpenID Connect conforms: true evidence: >- env zero acts as an OIDC IDENTITY PROVIDER for outbound workload identity - issuing JWTs that AWS, Azure, GCP and HashiCorp Vault trust, with per-cloud-provider audiences since July 2026 (V2 OIDC tokens). It is also an OIDC RELYING PARTY for Azure AD sign-in. It does NOT serve /.well-known/openid-configuration on any host probed 2026-09-06 (env0.com, www.env0.com, envzero.com, www.envzero.com, api.env0.com, docs.envzero.com, app.env0.com all 404 or return an SPA shell). evidence_url: https://docs.envzero.com/guides/integrations/oidc-integrations - id: saml-2.0 name: SAML 2.0 conforms: true evidence: self-service SSO supports SAML 2.0 with any compliant IdP (Okta, OneLogin, Google Workspace, JumpCloud) plus Azure AD / Microsoft Entra ID evidence_url: https://docs.envzero.com/guides/sso-integrations/self-service-sso - id: oauth2 name: OAuth 2.0 conforms: partial evidence: >- OAuth is used for VCS connections (GitHub.com, GitLab.com, Bitbucket.org) and for Azure AD sign-in. The env zero REST API itself does NOT use OAuth - it uses HTTP Basic with an API Key ID and Secret. No oauth2 securityScheme, no authorization/token endpoint, no scopes. - id: rfc9457-problem-details name: RFC 9457 Problem Details conforms: false evidence: no application/problem+json anywhere in the published reference; error responses are not documented at all (327 operation pages, 200-only responses) - id: json-api name: JSON:API conforms: false - id: odata name: OData conforms: false - id: fhir name: FHIR conforms: false applicable: false - id: fapi name: FAPI conforms: false applicable: false - id: psd2 name: PSD2 conforms: false applicable: false - id: idempotency-key name: Idempotency-Key (draft-ietf-httpapi-idempotency-key-header) conforms: false evidence: no idempotency key of any form; see conventions/env0-conventions.yml - id: rfc8594-sunset name: RFC 8594 Sunset header conforms: false evidence: no deprecation or sunset policy published; see lifecycle/env0-lifecycle.yml - id: rfc9116-security-txt name: RFC 9116 security.txt conforms: false evidence: /.well-known/security.txt returns 404 on all eight hosts probed 2026-09-06 - id: a2a-1.0 name: A2A Agent Card 1.0 conforms: true evidence: conformant agent card served at https://docs.envzero.com/.well-known/agent-card.json - capabilities is an object, protocolVersion 0.3 present, skills is an array see: a2a/env0-a2a.yml - id: mcp name: Model Context Protocol conforms: true evidence: official MCP server (github.com/env0/mcp-server, 14 tools, Apache-2.0) plus a remote docs MCP server answering tools/list anonymously at https://docs.envzero.com/mcp see: mcp/env0-mcp.yml - id: llms-txt name: llms.txt conforms: true evidence: https://docs.envzero.com/llms.txt (200), with per-section /_llms/*.md indexes see: llms/env0-llms.txt - id: agent-skills name: Agent Skills conforms: true evidence: provider-published skill at https://docs.envzero.com/.well-known/agent-skills/envzero/skill.md, also installable via `env0 skill install` see: skills/_index.yml - id: terraform-provider-protocol name: Terraform Provider Protocol conforms: true domain_standard: true evidence: first-party provider env0/env0 published to the public Terraform Registry, v1.32.2, 9.35M downloads evidence_url: https://registry.terraform.io/providers/env0/env0/latest - id: opentofu name: OpenTofu conforms: true evidence: OpenTofu is a first-class supported IaC framework alongside Terraform, Terragrunt, Pulumi, CloudFormation, Kubernetes and Helm evidence_url: https://docs.envzero.com/guides/getting-started/supported-platforms compliance: published: true page: https://docs.envzero.com/guides/overview/security-overview certifications: - name: SOC 2 Type II scope: entire service offering latest_report_issued: '2025-11' availability: on request from your account manager also_bundled_in: Cloud Navigator tier ("SOC 2 Report access") note: >- SOC 2 Type II is the only named attestation. No ISO 27001, no PCI DSS, no HIPAA, no FedRAMP, no GDPR page, no CSA STAR entry, and no trust portal was found. The report is not self-serve - it is gated behind an account manager. hosting: AWS (multi-account isolation, API Gateway + CloudFront + WAF at the edge, AWS SSO with MFA for internal access) encryption: HTTPS/SSH in transit; S3/RDS/DynamoDB encryption at rest; sensitive variables encrypted and not readable by the customer, their team, or env zero employees isolation: each deployment runs in a single-use sandboxed Docker container, destroyed after the run; self-hosted agent option keeps secrets and runs in the customer's own cloud account disclosed_risks: >- env zero publishes a candid "Possible Exploits" section naming three risks it explicitly does NOT mitigate - malicious code in a linked VCS repo exfiltrating data during PR plans, malicious third-party Terraform providers/modules reaching state and secrets, and arbitrary code execution through custom flows. Publishing an un-mitigated risk register is rare and worth crediting.