generated: '2026-08-04' method: searched source: >- Hammerspace product pages and press announcements, plus the protocol and interface surface evidenced in Hammerspace's own open source clients note: >- Hammerspace's conformance story is overwhelmingly about STORAGE and FILE protocol standards rather than API-design standards. The management REST API itself conforms to very few cross-cutting web-API conventions, and that asymmetry is the honest finding here. standards: - id: nfsv4.2 name: NFS version 4.2 (RFC 7862) conforms: true evidence: >- Hammerspace is built on a standards-based parallel NFS implementation and serves data over NFS v4.2; Hammerspace engineers are long-standing contributors to the Linux NFS client and server. - id: pnfs-flexfiles name: pNFS with Flex File Layout (RFC 8435) conforms: true evidence: >- Hammerspace exposes data via pNFS v4.2 with Flex Files as its parallel data path — the mechanism behind its separated metadata and data planes. - id: smb name: SMB conforms: true evidence: Data is accessible over SMB alongside NFS from the same global namespace. - id: s3 name: Amazon S3 object API conforms: true evidence: >- S3 access to the global namespace, plus client-side S3 protocol support added in Data Platform 5.1; object-storage volumes back the namespace with S3 targets including AWS, Backblaze B2, Wasabi, Zadara and Storj. - id: csi name: Container Storage Interface conforms: true version: v1.9.0 (CSI_MAJOR_VERSION=1); v0.3.0 legacy mode evidence: >- github.com/hammer-space/csi-plugin implements the Identity, Node and Controller services with a published capability matrix. - id: posix name: POSIX file semantics conforms: true evidence: >- File-backed volumes are formatted ext4 or xfs and mounted as loop devices specifically so that software depending on POSIX semantics NFS does not provide behaves as it would on a local disk. - id: fips-140-3 name: FIPS 140-3 validated cryptography conforms: partial evidence: >- Hammerspace announced FIPS 140-3 validation on 2026-03-31. Integration of the validated cryptographic modules into the Data Platform (data in flight and at rest) was stated as planned for a release by the end of 2026, so at the time of this pass the validation exists but the shipped platform integration does not yet. source: https://hammerspace.com/hammerspace-announces-fips-140-3-validation-plans-to-integrate-certified-cryptography-into-data-platform/ - id: w3c-trace-context name: W3C Trace Context (traceparent) conforms: true evidence: >- Hammerspace's reference client injects a W3C traceparent header into every REST call to the Anvil using OpenTelemetry propagation. source: https://github.com/hammer-space/csi-plugin/blob/main/CHANGELOG.md - id: opentelemetry name: OpenTelemetry conforms: true evidence: >- OTLP traces and metrics exported from the CSI driver under the hammerspace-csi instrumentation scope; configured with the standard OTEL_TRACES_EXPORTER / OTEL_METRICS_EXPORTER environment variables. - id: prometheus name: Prometheus exposition conforms: true evidence: >- Prometheus exporters are built into Hammerspace, with first-party Grafana dashboards published at github.com/hammer-space/hammerspace-grafana-dashboards. - id: mcp name: Model Context Protocol conforms: claimed evidence: >- Hammerspace ships an MCP server as part of the AI Data Platform, announced generally available on an NVIDIA reference design in March 2026. No public endpoint exists to introspect, so protocol-version conformance could not be verified. detail: mcp/hammerspace-mcp.yml - id: oidc name: OpenID Connect Discovery 1.0 conforms: true scope: support portal only evidence: >- supportportal.hammerspace.com serves a valid /.well-known/openid-configuration (HTTP 200). This is the Salesforce Experience Cloud identity provider fronting customer support, not the data platform API. source: well-known/hammerspace-openid-configuration.json - id: oauth2 name: OAuth 2.0 conforms: false scope: management API evidence: >- The Anvil management REST API authenticates with a form login and a session cookie. No OAuth 2.0 or bearer-token surface exists on it. - id: openapi name: OpenAPI conforms: false evidence: >- No OpenAPI or Swagger description is published at any public URL. Probed /openapi.json, /swagger.json and /api-docs on hammerspace.com (all answered by a bot-protection challenge) and on supportportal.hammerspace.com (401/404); searched the whole hammer-space GitHub organization for swagger/openapi artifacts and found none. - id: rfc9457-problem-details name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: >- No application/problem+json media type appears in any Hammerspace client or document, and no error catalogue is published. - id: rfc8594-sunset name: RFC 8594 Sunset header conforms: false evidence: No Sunset or Deprecation header support and no deprecation policy published. - id: rfc9116-security-txt name: RFC 9116 security.txt conforms: false evidence: >- /.well-known/security.txt could not be retrieved on hammerspace.com (bot challenge, HTTP 202) and returns 401 on the support portal. No security.txt is discoverable. - id: rfc8615-well-known-agent-card name: A2A Agent Card at a well-known URI conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json probed on every Hammerspace host; no agent card served. - id: asyncapi name: AsyncAPI conforms: false evidence: >- No webhook, event-stream or message-broker surface is documented publicly, so there is nothing for an AsyncAPI description to describe. compliance_program: published: true certifications: - name: FIPS 140-3 status: validated cryptography announced 2026-03-31; platform integration planned for a release by end of 2026 authority: NIST CMVP url: https://hammerspace.com/hammerspace-announces-fips-140-3-validation-plans-to-integrate-certified-cryptography-into-data-platform/ target_regimes: - US federal - defense - healthcare - finance not_found: - SOC 2 - ISO 27001 - PCI DSS - HIPAA attestation - FedRAMP note: >- No trust center exists (trust.hammerspace.com does not resolve) and no SOC 2, ISO 27001, PCI DSS or FedRAMP attestation was discoverable on any public page. FIPS 140-3 is the only named, third-party-validated credential Hammerspace publishes, so it is the sole basis for the Compliance pointer. x-evidence: fetched: '2026-08-04'