generated: '2026-08-14' method: probed source: openapi/_original/evrim-openapi-original.yml + live probes of Evrim hosts note: >- Cross-cutting standards assertions. Upgraded from derived to probed this round: the MCP, OAuth-discovery, well-known, security.txt and A2A rows below are backed by live HTTP probes with recorded statuses, not inference. No compliance certification (SOC 2 / ISO 27001 / FedRAMP / CMMC) is published on any Evrim surface, so no Compliance pointer is emitted — notable given the stated buyers (U.S. financial institutions, the defense industrial base, federal agencies). standards: - id: openapi-3.0 conforms: true evidence: >- openapi 3.0.3 document published via the Stainless spec referenced by the first-party SDK's .stats.yml. NOTE: the live host's own /openapi.json returns 401, so the CURRENT contract is not public. - id: http-bearer-auth conforms: true evidence: >- securitySchemes knoxApiToken type http scheme bearer, applied to all 91 operations; confirmed live by `www-authenticate: Bearer` on a 401 from api.evrim.ai. - id: oauth2 conforms: false - id: oidc conforms: false - id: oauth-authorization-server-metadata conforms: false evidence: >- RFC 8414 — https://api.evrim.ai/.well-known/oauth-authorization-server 404, /.well-known/oauth-authorization-server/mcp 404. - id: oauth-protected-resource-metadata conforms: false evidence: >- RFC 9728 — https://api.evrim.ai/.well-known/oauth-protected-resource 404 and /.well-known/oauth-protected-resource/mcp 404, even though /mcp challenges with `www-authenticate: Bearer`. An MCP client cannot discover an authorization server. - id: mcp conforms: true evidence: >- Live Streamable HTTP MCP endpoint at https://api.evrim.ai/mcp — GET 405 with `allow: DELETE, POST`, JSON-RPC POST 401 with `www-authenticate: Bearer`, control path 404. Legacy /sse transport also present (401). Tool list is auth-gated and was not read. See mcp/evrim-mcp.yml. - id: rfc9457-problem-details conforms: false evidence: >- No application/problem+json response anywhere; live errors use the FastAPI/Starlette `{"detail": ...}` envelope. See errors/evrim-problem-types.yml. - id: pagination conforms: true evidence: Paginated*List response schemas with count/next/previous/results - id: idempotency conforms: false evidence: >- No Idempotency-Key contract in the spec or the first-party SDK, while that SDK retries 408/409/429/5xx twice by default. - id: rfc8594-sunset conforms: false evidence: No Sunset/Deprecation header or deprecation policy published. - id: rfc9116-security-txt conforms: false evidence: >- /.well-known/security.txt returns 404 on api.evrim.ai; the 200s on www.evrim.ai and evrim.ai are the React SPA's catch-all HTML shell, not a security.txt. See well-known/evrim-well-known.yml. - id: asyncapi conforms: false evidence: >- N/A — no event, streaming or webhook surface exists to describe. The 91-operation OpenAPI declares no webhooks and no callbacks, and no event catalog is published. - id: webhooks conforms: false evidence: No webhook subscription or delivery surface is documented. - id: a2a conforms: false evidence: >- No agent card. /.well-known/agent-card.json and /.well-known/agent.json return 404 on api.evrim.ai; the 200s on the marketing hosts are SPA HTML, not JSON. - id: llms-txt conforms: false evidence: >- No /llms.txt is served — the documentation host that would carry it fails its TLS handshake entirely. - id: json-api conforms: false - id: fhir conforms: false - id: scim conforms: false - id: odata conforms: false compliance_certifications: published: false searched: - soc2 - iso-27001 - fedramp - cmmc - pci-dss - hipaa note: >- No trust center, compliance page or named certification was found on any reachable Evrim surface. probe-security-programs.py returned vdp=none trust=none. Evrim does disclose an AFWERX SBIR Phase I contract on its blog (2026-04-01), which is a procurement fact, not a security certification. checked: '2026-08-14'