generated: '2026-07-19' method: derived source: well-known/kixeye-openid-configuration.json, well-known/kixeye-jwks.json notes: 'Derived only from the OpenID Connect discovery document served by api.kixeye.com. KIXEYE publishes no public API, no OpenAPI, and no compliance program (no trust center, no SOC 2 / ISO 27001 / PCI DSS claims found on kixeye.com or corp.kixeye.com). No Compliance pointer is emitted. Privacy-law posture (CCPA / California privacy rights, an EU-facing non-US privacy policy, a named DPO) is documented in the legal pages but is a privacy notice, not a published certification program.' standards: - id: openid-connect-discovery conforms: true evidence: api.kixeye.com serves /.well-known/openid-configuration (issuer, jwks_uri, response_types_supported, id_token_signing_alg_values_supported, claims_supported) - id: rfc7517-jwks conforms: true evidence: /.well-known/jwks returns one RSA sig key, alg RS256 - id: oauth2 conforms: partial evidence: response_types_supported is ["code"], but no authorization_endpoint or token_endpoint is advertised; the discovery document is verification-only - id: rfc8414-oauth-authorization-server-metadata conforms: false evidence: /.well-known/oauth-authorization-server returns 404 - id: rfc9116-security-txt conforms: false evidence: no /.well-known/security.txt on any KIXEYE host - id: rfc9457-problem-details conforms: unknown evidence: no public API surface or OpenAPI to evaluate - id: openapi conforms: false evidence: no published OpenAPI/Swagger definition found privacy_posture: - id: ccpa-california-privacy-rights documented: true evidence: https://corp.kixeye.com/ca-privacy-rights.html - id: privacy-policy-non-us documented: true evidence: 'https://corp.kixeye.com/pp.html (Last Updated: June 23, 2023; contacts privacy@kixeye.com, dpo@kixeye.com; 12 localizations)' certifications: []