generated: '2026-08-04' method: probed source: https://auth.partner.iralogix.com/.well-known/openid-configuration; https://iralogix.com/platform/ notes: 'Assertions are limited to what IRALOGIX publishes anonymously. There is no public OpenAPI, AsyncAPI, JSON Schema, error reference or convention documentation to test the REST/HTTP standards against, so those are recorded as unknown rather than false.' standards: - id: openid-connect-discovery-1.0 conforms: true evidence: /.well-known/openid-configuration returns a complete OIDC discovery document at https://auth.partner.iralogix.com/ - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: /.well-known/oauth-authorization-server returns 200 with authorization-server metadata - id: oauth2 conforms: true evidence: authorization_code, client_credentials, refresh_token, device_code and token-exchange grants advertised - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported includes S256 - id: rfc7009-token-revocation conforms: true evidence: revocation_endpoint https://auth.partner.iralogix.com/oauth/revoke - id: rfc8628-device-authorization-grant conforms: true evidence: device_authorization_endpoint advertised and urn:ietf:params:oauth:grant-type:device_code in grant_types_supported - id: rfc8693-token-exchange conforms: true evidence: urn:ietf:params:oauth:grant-type:token-exchange in grant_types_supported - id: rfc7591-dynamic-client-registration conforms: true evidence: registration_endpoint https://auth.partner.iralogix.com/oidc/register - id: oidc-backchannel-logout-1.0 conforms: true evidence: backchannel_logout_supported true, backchannel_logout_session_supported true - id: rfc9449-dpop conforms: true evidence: dpop_signing_alg_values_supported present in discovery metadata - id: rfc9126-pushed-authorization-requests conforms: false evidence: no pushed_authorization_request_endpoint in discovery metadata - id: fapi-2.0 conforms: false evidence: no PAR endpoint, no signed request objects, and implicit + resource-owner-password grants remain enabled - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on iralogix.com and auth.partner.iralogix.com - id: rfc8615-well-known-api-catalog conforms: false evidence: /.well-known/api-catalog returns 404 - id: a2a-agent-card conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json return 404 on every real host - id: openapi conforms: unknown evidence: no public OpenAPI found on any host; partner documentation is behind Okta visitor authentication - id: rfc9457-problem-details conforms: unknown evidence: no public spec or error reference to inspect compliance: published: true source: https://iralogix.com/platform/ claims: - name: SSAE SOC 2 Type 1 verbatim: SSAE SOC 2 Type 1 scope: platform - name: SSAE SOC 1 Type 2 verbatim: SSAE SOC I Type 2 scope: platform notes: Stated in the site footer under "Certified and Tested" alongside an AICPA mark. No trust centre, no downloadable report portal, and no report request flow is published — trust.iralogix.com resolves only via the *.iralogix.com wildcard and is not a real host. x-evidence: fetched: '2026-08-04' urls: - url: https://auth.partner.iralogix.com/.well-known/openid-configuration http_status: 200 - url: https://auth.partner.iralogix.com/.well-known/oauth-authorization-server http_status: 200 - url: https://iralogix.com/platform/ http_status: 200