generated: '2026-08-15' method: searched source: https://secure.everlywell.com/.well-known/openid-configuration note: >- Conformance is asserted only where a fetched document proves it. Everly Health publishes no OpenAPI and no public API reference, so most cross-cutting standards below are recorded as not-evidenced rather than as failures. Revised 2026-08-15: the company DOES operate an undisclosed platform API (api.pwnhealth.com, live AWS API Gateway) and a developer hub ("PWNHealth APIs", docs.pwnhealth.com) — both auth-gated, so nothing about their contract semantics can be asserted here. Also revised: Everly Health does publish a HIPAA compliance statement in its consumer help centre claiming independent third-party verification, so `compliance_program.published` is now true and a `Compliance` pointer is emitted — with the caveat that no auditor, certification name, report or renewal date is given and the page has not been updated since 2020-06-17. standards: - id: oauth2 conforms: true evidence: >- RFC 6749 authorization server with authorize/token/revoke/introspect endpoints declared at https://secure.everlywell.com/.well-known/oauth-authorization-server - id: rfc8414-authorization-server-metadata conforms: true evidence: /.well-known/oauth-authorization-server returns 200 application/json - id: oidc-discovery conforms: true evidence: /.well-known/openid-configuration returns 200 with issuer, jwks_uri, userinfo_endpoint - id: oidc-core conforms: true evidence: response_types [code], id_token_signing_alg_values_supported [RS256], claims_supported present - id: rfc7517-jwks conforms: true evidence: jwks_uri https://secure.everlywell.com/jwks/signature returns 200 application/json RSA keys - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported [plain, S256] note: >- `plain` is still advertised alongside S256; OAuth 2.1 requires S256 for public clients. - id: rfc7009-token-revocation conforms: true evidence: revocation_endpoint https://secure.everlywell.com/oauth2/revoke - id: rfc7662-token-introspection conforms: true evidence: introspection_endpoint https://secure.everlywell.com/oauth2/introspect - id: rfc7591-dynamic-client-registration conforms: false evidence: no registration_endpoint in the discovery document - id: rfc9728-protected-resource-metadata conforms: false evidence: /.well-known/oauth-protected-resource returned 404 - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returned 404 on every Everly Health host - id: oauth2.1 conforms: false evidence: >- grant_types_supported includes `password` (resource owner password credentials), which OAuth 2.1 / RFC 9700 removes; code_challenge_methods_supported includes `plain` - id: openapi conforms: false evidence: >- No OpenAPI/Swagger anonymously reachable on any Everly Health host or in the public GitHub org. Re-probed 2026-08-15 against api.pwnhealth.com (/openapi.json, /swagger.json, /v1/openapi.json, /api-docs — all 403 MissingAuthenticationToken), secure.everlywell.com (all 404), www.everlywell.com (all 404) and docs.pwnhealth.com (/openapi.json 302 to the password wall). note: >- A spec very likely exists inside the gated ReadMe hub — ReadMe's /openapi.json and /reference routes are wired but password-protected. Absence here means "not published", not "does not exist". - id: mcp conforms: true evidence: >- https://docs.pwnhealth.com/mcp answers a JSON-RPC POST with a well-formed MCP error envelope (HTTP 401, code -32001 "Authorization required"), so an MCP server is deployed on an Everly Health host. note: >- Auto-provisioned by ReadMe for the documentation hub, not authored by Everly Health, and gated — tools/list and every inputSchema are unreachable anonymously. - id: asyncapi conforms: false evidence: no event, streaming or webhook surface published - id: fhir conforms: false evidence: not evidenced — no public FHIR endpoint, capability statement or claim found - id: rfc9457-problem-details conforms: false evidence: not evidenced — no public error contract published - id: rfc8594-sunset-header conforms: false evidence: not evidenced — no deprecation or versioning policy published compliance_program: published: true trust_center: null certifications: [] claims: - regime: HIPAA / HITECH Security Standards url: https://support.everlywell.com/article/559-is-everlywell-hipaa-compliant statement: >- "Everlywell has been verified by an independent third party to be HIPAA compliant at levels required to support partnerships with the largest health providers in the United States" and its handling of PHI "earned the company 'Highly Compliant' status per the HIPAA/HITECH Security Standards." third_party_verified: claimed auditor_named: false report_available: false last_updated: '2020-06-17' note: >- A consumer help-centre article, not a trust centre. No auditor, report, scope, certificate or renewal date is given, and the page has not been updated in six years. Recorded verbatim as a published compliance claim; it is not an attestation. note: >- No trust.everlywell.com (DNS does not resolve), no /security, /compliance or /hipaa page (all 404), no bug-bounty program (hackerone.com/everlywell and bugcrowd.com/everlywell both 404), and no named SOC 2 / ISO 27001 / HITRUST certification anywhere public. The only published compliance content is the HIPAA help-centre article above plus the privacy policy, the consumer health data privacy notice and the terms of use. x-evidence: fetched: '2026-08-15' probes: - {url: 'https://secure.everlywell.com/.well-known/openid-configuration', http_status: 200} - {url: 'https://secure.everlywell.com/.well-known/oauth-authorization-server', http_status: 200} - {url: 'https://secure.everlywell.com/jwks/signature', http_status: 200} - {url: 'https://secure.everlywell.com/.well-known/oauth-protected-resource', http_status: 404} - {url: 'https://www.everlywell.com/security/', http_status: 404} - {url: 'https://www.everlywell.com/compliance/', http_status: 404} - {url: 'https://www.everlywell.com/hipaa/', http_status: 404} - {url: 'https://trust.everlywell.com/', http_status: 0, note: 'DNS does not resolve'} - {url: 'https://support.everlywell.com/article/559-is-everlywell-hipaa-compliant', http_status: 200} - {url: 'https://hackerone.com/everlywell', http_status: 404} - {url: 'https://bugcrowd.com/everlywell', http_status: 404} - {url: 'https://api.pwnhealth.com/ping', http_status: 200, note: 'body "healthy"'} - {url: 'https://api.pwnhealth.com/openapi.json', http_status: 403} - {url: 'https://docs.pwnhealth.com/', http_status: 302, note: 'to /password?redirect=/'} - {url: 'https://docs.pwnhealth.com/mcp', http_status: 401, note: 'POST tools/list — Authorization required'}