generated: '2026-08-01' method: searched source: https://www.fundguard.com/product/ note: >- FundGuard publishes no OpenAPI, AsyncAPI, GraphQL SDL or JSON Schema, so nothing could be derived from a contract. Everything below is either observed live on a FundGuard host or read from a published FundGuard page. Claims the company makes on its website are recorded as claims, not as verified conformance. standards: - id: oauth2 conforms: true evidence: >- RFC 6749 authorization_code + refresh_token grants advertised at https://www.fundguard.com/.well-known/oauth-authorization-server (HTTP 200) - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: /.well-known/oauth-authorization-server returns a valid metadata document (HTTP 200) - id: rfc9728-oauth-protected-resource-metadata conforms: true evidence: /.well-known/oauth-protected-resource returns a valid metadata document (HTTP 200) - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported = ["S256"] - id: oauth2.1-public-clients conforms: true evidence: token_endpoint_auth_methods_supported = ["none"], client_id_metadata_document_supported = true - id: mcp conforms: true evidence: >- Model Context Protocol server routes live at /wp-json/mcp/mcp-oauth-server and /wp-json/mcp/mcp-adapter-default-server; both 401 anonymously, so protocol version and tool schemas could not be observed - id: rfc8615-well-known-uris conforms: true evidence: two well-known documents served correctly; unregistered paths correctly return 404 - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returned 404 on every FundGuard host probed - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog returned 404 - id: oidc-discovery conforms: false evidence: /.well-known/openid-configuration returned 404 - id: a2a conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json both 404 on every host probed - id: openapi conforms: unknown evidence: >- FundGuard displays the OpenAPI Initiative logo in the industry-certifications row on https://www.fundguard.com/product/ and https://www.fundguard.com/digital-operational-resilience-act/ (img alt="open api logo"), but no OpenAPI document is published at any reachable FundGuard host - all of /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs and /redoc returned 404 or the WordPress 404 shell. The badge is a positioning claim, not a discoverable contract. - id: asyncapi conforms: false evidence: no event, streaming or webhook documentation published; no AsyncAPI document found - id: rfc9457-problem-details conforms: unknown evidence: no public API contract or error reference to evaluate - id: mta-sts conforms: true evidence: >- https://mta-sts.fundguard.com/.well-known/mta-sts.txt returns STSv1 with mode=enforce and a 604800 max_age over Google Workspace MX hosts - id: dmarc conforms: true evidence: 'v=DMARC1; p=reject; pct=100 with aggregate reporting' - id: dnssec conforms: false evidence: fundguard.com is not DNSSEC signed compliance_claims: - claim: AICPA SOC kind: certification-badge source: https://www.fundguard.com/product/ detail: >- AICPA SOC seal displayed in the industry-certifications row (img alt="AICPA SOC logo"). The SOC report type (SOC 1 / SOC 2 Type I / Type II) is not stated and no report, bridge letter or trust portal is published. verified: false - claim: DORA (EU Digital Operational Resilience Act) alignment kind: regulatory-positioning source: https://www.fundguard.com/digital-operational-resilience-act/ detail: >- "aligning with DORA's ICT risk management standards and similar frameworks worldwide"; page also names FCA/PRA, SEC and MAS readiness. Product positioning for regulated customers rather than a FundGuard attestation. verified: false - claim: AWS Partner kind: partner-badge source: https://www.fundguard.com/product/ verified: false - claim: Microsoft Azure kind: partner-badge source: https://www.fundguard.com/product/ verified: false not_found: - ISO 27001 - ISO 27017 - ISO 27018 - PCI DSS - HIPAA - FedRAMP - CSA STAR - a trust center or security portal (trust.fundguard.com and security.fundguard.com are NXDOMAIN; /security, /trust, /compliance all 404) - a published vulnerability disclosure or bug bounty program x-evidence: fetched: '2026-08-01' hosts_probed: [www.fundguard.com, kb.fundguard.com, mta-sts.fundguard.com, platform.fundguard.com]