generated: '2026-09-09' method: searched source: Fenergo documentation portal, live OIDC discovery, and the 145 harvested OpenAPI contracts note: 'Conformance is asserted only where the contract or a live document says so. The strongest signal here is SCIM 2.0: identity.fenergox.com serves a real SCIM 2.0 service with the IETF URNs in the schema, which is the domain standard for identity provisioning and lets an Okta or Entra ID customer integrate with no bespoke connector.' domain_standard: id: scim-2.0 conforms: true evidence_location: openapi/fenergo-identity-scim-v1-openapi.json — urn:ietf:params:scim:schemas:core:2.0:* schema URNs evidence_url: https://identity.fenergox.com/scim/swagger/v1/swagger.json certifications: - ISO/IEC 27001:2022 - SOC 2 Type II (SSAE 18) certifications_source: https://www.fenergo.com/trust-and-security trust_center: https://trust.fenergo.com/ standards: - id: scim-2.0 name: SCIM 2.0 (RFC 7642/7643/7644) conforms: true kind: domain-standard evidence: openapi/fenergo-identity-scim-v1-openapi.json declares the SCIM 2.0 core URNs verbatim — urn:ietf:params:scim:schemas:core:2.0:User, :Group, :ResourceType, :ServiceProviderConfig and urn:ietf:params:scim:api:messages:2.0:{ListResponse,PatchOp,BulkRequest,BulkResponse,Error} — and serves the canonical resource set /Users /Groups /Bulk /Schemas /ResourceTypes /ServiceProviderConfig plus the /.search endpoints. 20 operations. evidence_url: https://identity.fenergox.com/scim/swagger/v1/swagger.json http_status: 200 docs: https://docs.fenergox.com/developer-hub/api-and-system-security/scim-overview note: Fenergo states SCIM has been tested against Okta and Microsoft Entra ID (AAD) connectors. - id: oauth2-rfc6749 name: OAuth 2.0 conforms: true kind: cross-cutting evidence: Live token endpoint https://identity.fenergox.com/connect/token; grant_types_supported includes client_credentials, authorization_code, refresh_token, device_code and CIBA. evidence_url: https://identity.fenergox.com/.well-known/openid-configuration http_status: 200 - id: oidc-discovery name: OpenID Connect Discovery 1.0 conforms: true kind: cross-cutting evidence: A valid, complete OIDC discovery document is served at /.well-known/openid-configuration on identity.fenergox.com, advertising 130 scopes_supported and PKCE S256. evidence_url: https://identity.fenergox.com/.well-known/openid-configuration http_status: 200 - id: rfc8705-mtls name: RFC 8705 OAuth 2.0 Mutual-TLS Client Authentication conforms: true kind: cross-cutting evidence: token_endpoint_auth_methods_supported includes tls_client_auth and self_signed_tls_client_auth; a dedicated mTLS STS endpoint is published at https://api-mtls.fenergox.com/sts/connect/mtls/token. evidence_url: https://identity.fenergox.com/.well-known/openid-configuration http_status: 200 - id: rfc7636-pkce name: PKCE (RFC 7636) conforms: true kind: cross-cutting evidence: 'code_challenge_methods_supported: [plain, S256].' evidence_url: https://identity.fenergox.com/.well-known/openid-configuration http_status: 200 - id: rfc8594-sunset name: RFC 8594 Sunset / Deprecation headers conforms: true kind: cross-cutting evidence: '2,258 of 2,381 harvested operations declare a 410 response whose description states: "Endpoint marked as deprecated was terminated. This response will be present only if the endpoint was marked as deprecated and has reached the sunset date. During the deprecation period, the API will include additional ''sunset'' and ''deprecation'' headers." The contract itself asserts the mechanism.' evidence_url: openapi/ (145 contracts) - id: rfc9457-problem-details name: RFC 9457 Problem Details conforms: true partial: true kind: cross-cutting evidence: application/problem+json on 31 of 2,381 operations, all on the policyagent service (ASP.NET Core ProblemDetails). The house format across the rest of the estate is a proprietary ServiceResponse envelope. evidence_url: openapi/fenergo-policyagent-v1-0-openapi.json - id: openapi-3 name: OpenAPI 3.0 / 3.1 conforms: true kind: cross-cutting evidence: '145 published contracts: 68 OpenAPI 3.0.4, 69 OpenAPI 3.0.1, 8 OpenAPI 3.1.0 (Transaction Monitoring).' evidence_url: openapi/ - id: graphql name: GraphQL conforms: true kind: cross-cutting evidence: Fenergo publishes a "Supergraph" GraphQL federation endpoint at POST https://api.{environment}.fenergox.com/supergraph spanning EntityData, Journey, Associations and Product, plus a Comments GraphQL API (scope fenx.comments). Introspection is auth-gated — the endpoint returned HTTP 401 {"message":"Unauthorized"} to an anonymous introspection POST on 2026-09-09, so no SDL was harvested and none has been generated. evidence_url: https://docs.fenergox.com/developer-hub/data-extraction/supergraph-query-overview http_status: 401 - id: hmac-webhook-signing name: HMAC-SHA256 webhook signatures conforms: true kind: cross-cutting evidence: Every webhook notification carries x-fenx-signature = sha256=. evidence_url: https://docs.fenergox.com/developer-hub/event-notifications/webhook-security-using-hmac - id: iso-27001 name: ISO/IEC 27001:2022 conforms: true kind: certification evidence: Certification named on the Fenergo Trust & Security page; certificate available inside the Fenergo Trust Center. evidence_url: https://www.fenergo.com/trust-and-security http_status: 200 - id: soc2-type-ii name: SOC 2 Type II (SSAE 18) conforms: true kind: certification evidence: Fenergo states a SOC 2 Type II report is available on request through the Trust Center under NDA. evidence_url: https://www.fenergo.com/trust-and-security http_status: 200 - id: gdpr name: GDPR / data protection conforms: true kind: regulatory evidence: A dedicated Data Protection domain ships Command and Query APIs with their own erasure scope fenx.dataprotection.deleteentitydata, plus published Legal Holds, Conditional Data Protection Periods and Automatic Reonboarding features. BYOK encryption is documented. evidence_url: https://docs.fenergox.com/developer-hub/api-and-system-security/encryption-and-byok - id: byok name: Bring Your Own Key encryption conforms: true kind: security evidence: Encryption and BYOK is a documented tenant provisioning step; clients complete key setup before production tenant provisioning. evidence_url: https://docs.fenergox.com/developer-hub/api-and-system-security/encryption-and-byok - id: fatca name: FATCA classification conforms: true kind: domain-content evidence: FATCA classification fields appear in the Policy Command and Product Policy Command contracts (5 specs). evidence_url: openapi/fenergo-policycommand-v2-0-openapi.json - id: isda name: ISDA Amend conforms: true kind: domain-content evidence: ISDA is a first-class domain with its own scopes (fenx.isda.read / fenx.isda.write) and dated release notes (ISDA Amend Individual Link Datasets, ISDA API Notification, ISDA Amend Scheduler Frequency). evidence_url: https://docs.fenergox.com/release-notes/fenergo-release-notes - id: iso-20022 name: ISO 20022 conforms: false evidence: No ISO 20022 message types (pacs./camt./pain.) appear in any of the 145 harvested contracts. The Transaction Monitoring transaction model is a Fenergo-defined JSON shape, not an ISO 20022 payload. - id: fdx name: FDX (Financial Data Exchange) conforms: false evidence: No FDX resource shapes or references found in the contracts or documentation. - id: psd2-obie name: PSD2 / Open Banking (OBIE) conforms: false evidence: Fenergo is a compliance/CLM platform, not an ASPSP; no PSD2 or OBIE endpoints are published. - id: fapi name: FAPI (Financial-grade API) conforms: false evidence: No FAPI profile is claimed. The IdP does support mTLS client authentication and PKCE S256, which are FAPI building blocks, but no FAPI conformance is asserted and no fapi profile appears in the discovery document. - id: odata name: OData conforms: false evidence: A single incidental string match in the Data Migration contract; no $metadata surface is served and no OData conventions are used. - id: json-api name: JSON:API conforms: false evidence: No application/vnd.api+json media type anywhere in the estate. - id: asyncapi name: AsyncAPI conforms: false evidence: Fenergo ships a substantial event surface (93 published event types, webhooks and a polling API) but publishes no AsyncAPI document for it. The event catalogue is captured in asyncapi/fenergo-event-notifications-webhooks.yml as a Webhooks artifact instead. - id: idempotency-key name: Idempotency-Key conforms: false evidence: No idempotency key parameter or header in any of 2,381 operations, and no documented replay protection.