generated: '2026-09-12' method: searched source: https://cloud.google.com/dialogflow/docs/compliance-security-controls, https://accounts.google.com/.well-known/openid-configuration, https://accounts.google.com/.well-known/oauth-authorization-server, https://cloud.google.com/apis/design, discovery/google-dialogflow-v2.json, discovery/google-dialogflow-v3.json provider: Google Dialogflow providerId: google-dialogflow description: >- Cross-cutting standards and certifications this API surface actually conforms to, each with the evidence that establishes it. Certifications are read from Google's own Dialogflow compliance page (last updated 2026-09-03 on the page itself); protocol conformance is read from the live authorization-server metadata and from the two Discovery Documents. conformance: - id: oauth2 name: OAuth 2.0 (RFC 6749) conforms: true evidence: https://accounts.google.com/.well-known/oauth-authorization-server note: >- Every one of the 437 operations in v2 and v3 declares OAuth 2.0 scopes. The authorization server publishes RFC 8414 metadata at the URL above (HTTP 200, probed 2026-09-12). - id: oauth2-authorization-server-metadata name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: true evidence: https://accounts.google.com/.well-known/oauth-authorization-server - id: oidc name: OpenID Connect Discovery 1.0 conforms: true evidence: https://accounts.google.com/.well-known/openid-configuration note: issuer https://accounts.google.com, jwks_uri https://www.googleapis.com/oauth2/v3/certs. Dialogflow itself is not an OIDC relying party, but its tokens are issued by an OIDC-conformant server, and CX webhook/tool authentication can be configured to present an OIDC ID token. - id: security-txt name: RFC 9116 security.txt conforms: true evidence: https://www.google.com/.well-known/security.txt note: Served on the registrable domain, not the API host. Expires 2030-04-01. - id: pagination name: Cursor pagination (AIP-158 page token) conforms: true evidence: discovery/google-dialogflow-v2.json — every list method declares pageSize + pageToken and every List*Response declares nextPageToken. - id: field-mask name: Partial update via FieldMask (AIP-134) conforms: true evidence: All 53 PATCH operations across v2 (33) and v3 (20) declare an updateMask query parameter of format google-fieldmask. - id: long-running-operations name: google.longrunning.Operation (AIP-151) conforms: true evidence: 59 v2 and 23 v3 operations return a google.longrunning.Operation, with get / list / cancel operations on projects.operations and projects.locations.operations. - id: google-rpc-status name: google.rpc.Status canonical error model conforms: true evidence: https://cloud.google.com/apis/design/errors note: See errors/google-dialogflow-problem-types.yml. - id: grpc name: gRPC / Protocol Buffers conforms: true evidence: grpc/v2/ and grpc/cx-v3/ — 42 services and 267 RPCs published verbatim by Google in googleapis/googleapis. - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: No application/problem+json response is declared anywhere in either Discovery Document; the envelope is google.rpc.Status. - id: rfc8594 name: RFC 8594 Sunset header conforms: false evidence: No Sunset or Deprecation response header is documented or declared; deprecations are announced in prose at https://cloud.google.com/dialogflow/docs/release-notes. - id: idempotency name: Replay-safe writes via an idempotency key conforms: false evidence: No Idempotency-Key header, no ETag field and no If-Match precondition on any of the 199 mutating operations. See conventions/google-dialogflow-conventions.yml. - id: openapi name: OpenAPI conforms: false evidence: >- Google publishes no OpenAPI for Dialogflow. The first-party machine-readable contract is the Google Discovery Document at https://dialogflow.googleapis.com/$discovery/rest?version=v2 (and v3). The OpenAPI files in openapi/ are API Evangelist's mechanical conversion of it, not a provider artifact. - id: asyncapi name: AsyncAPI conforms: false evidence: No AsyncAPI document is published. Dialogflow's event surface is outbound HTTPS webhook fulfillment plus Pub/Sub notifications; see asyncapi/google-dialogflow-webhooks.yml. domain_standards: - id: none-applicable name: Conversational AI / NLU conforms: null note: >- The conversational-agent market has no adopted interchange standard that a contract can declare. Dialogflow does not implement one, and none exists to implement — this is recorded as not-applicable rather than as a failure. The nearest adjacent thing Dialogflow does implement is the Google Cloud API Design Guide (AIP), captured above. certifications: source: https://cloud.google.com/dialogflow/docs/compliance-security-controls page_last_updated: '2026-09-03' note: Dialogflow is composed of other Google Cloud services (Speech-to-Text, Text-to-Speech); Google states these certifications cover Dialogflow in its entirety. items: - name: HIPAA dialogflow_cx: true dialogflow_es: true - name: ISO 27001 dialogflow_cx: true dialogflow_es: true - name: ISO 27017 dialogflow_cx: true dialogflow_es: true - name: ISO 27018 dialogflow_cx: true dialogflow_es: true - name: ISO 27701 dialogflow_cx: true dialogflow_es: true - name: SOC 1 dialogflow_cx: true dialogflow_es: true - name: SOC 2 dialogflow_cx: true dialogflow_es: true - name: SOC 3 dialogflow_cx: true dialogflow_es: true government_authorizations: - name: FedRAMP High dialogflow_cx: true dialogflow_es: false evidence: https://cloud.google.com/dialogflow/docs/compliance-security-controls note: CX only. Dialogflow ES carries no FedRAMP authorization — a real difference between the two editions for public-sector buyers. security_controls: - name: Data residency / regionalization dialogflow_cx: true dialogflow_es: true - name: Customer-managed encryption keys (CMEK) dialogflow_cx: true dialogflow_es: false - name: VPC Service Controls dialogflow_cx: true dialogflow_es: true - name: Access Transparency dialogflow_cx: true dialogflow_es: false maintainers: - FN: Kin Lane email: kin@apievangelist.com