generated: '2026-08-14' method: searched source: https://klue.com/product/security standards: - id: oidc-discovery conforms: true evidence: >- https://app.klue.com/.well-known/openid-configuration returns HTTP 200 anonymously with a valid OpenID Connect Discovery 1.0 document: issuer, authorization/token/revocation/introspection/userinfo endpoints, jwks_uri, RS256 id_token signing, pairwise subject types, and 23 scopes. source: well-known/klue-openid-configuration.json - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: >- https://app.klue.com/.well-known/oauth-authorization-server returns HTTP 200 with a document byte-identical to the OIDC discovery document. source: well-known/klue-oauth-authorization-server.json - id: rfc7591-dynamic-client-registration conforms: true evidence: >- registration_endpoint https://app.klue.com/oauth/register is advertised in the discovery document and is live — an anonymous POST with an invalid redirect_uri returns HTTP 400 invalid_redirect_uri rather than 404. source: well-known/klue-openid-configuration.json - id: rfc7636-pkce conforms: true evidence: >- code_challenge_methods_supported lists S256 and plain. Note that `plain` is still offered, which RFC 8252/current OAuth BCP discourages. source: well-known/klue-openid-configuration.json - id: rfc7009-token-revocation conforms: true evidence: revocation_endpoint https://app.klue.com/oauth/revoke advertised in discovery. source: well-known/klue-openid-configuration.json - id: rfc7662-token-introspection conforms: true evidence: introspection_endpoint https://app.klue.com/oauth/introspect advertised in discovery. source: well-known/klue-openid-configuration.json - id: scim2 conforms: likely evidence: >- The published OAuth scope set includes scim:read and scim:edit, and the kluein GitHub organization maintains a fork of scimitar, a Rails SCIM v2 endpoint implementation. Klue publishes no SCIM documentation or base path publicly, so this is recorded as `likely` rather than `true`. source: well-known/klue-openid-configuration.json - id: soc2-type-ii conforms: true evidence: >- "Klue maintains SOC 2, Type II compliance in accordance with the five Trust Services Criteria defined by the American Institute of Certified Public Accountants." Audit report available on request via security@klue.com. source: https://klue.com/product/security - id: gdpr conforms: true evidence: >- "Klue complies with the GDPR and utilizes the June 2021 Standard Contractual Clauses when applicable to govern its relationship with sub-processors." source: https://klue.com/product/security - id: ccpa conforms: true evidence: >- Klue states its California sales volume does not trigger CCPA applicability but that it actively complies regardless, and does not sell personal data. source: https://klue.com/product/security - id: pipeda conforms: true evidence: >- Klue is headquartered in Canada and subject to PIPEDA; the European Commission recognises PIPEDA as providing adequate safeguards with respect to GDPR. source: https://klue.com/product/security - id: saml2-sso conforms: true evidence: >- Single Sign On listed in the enterprise-ready suite; published SAML SSO integrations for Okta and Microsoft Entra ID. source: https://www.okta.com/integrations/klue/ - id: tls12-plus conforms: true evidence: >- "Our web servers use the strongest grade HTTPS security (TLS 1.2+)". SSL certificates 2048-bit RSA signed with SHA-256. source: https://klue.com/product/security - id: aes256-encryption-at-rest conforms: true evidence: >- Customer data stored in cloud-hosted databases and backups "encrypted with AES-256 block-level storage encryption". source: https://klue.com/product/security - id: rfc9116-security-txt conforms: true evidence: >- https://klue.com/.well-known/security.txt returns 200 with Canonical, Contact, Expires, Hiring, Policy and Preferred-Languages fields. source: well-known/klue-security.txt - id: mcp conforms: true evidence: >- Klue ships a production Model Context Protocol server with two connector surfaces and a publicly published Agent Skill. source: mcp/klue-mcp.yml - id: iso-27001 conforms: unknown evidence: Not claimed on Klue's public security page. - id: hipaa conforms: unknown evidence: Not claimed on Klue's public security page. - id: fedramp conforms: unknown evidence: Not claimed on Klue's public security page. - id: pci-dss conforms: unknown evidence: Not claimed on Klue's public security page. - id: oauth2 conforms: true evidence: >- CORRECTED 2026-08-14. The previous round recorded this as unknown because klue.com/.well-known/oauth-authorization-server returns 404 — but the authorization server is on the APPLICATION host, not the marketing host. https://app.klue.com/.well-known/oauth-authorization-server returns HTTP 200 with authorization_code + refresh_token grants, PKCE, and 23 scopes. Klue documents none of this in prose; the discovery document is the only public statement of it. source: well-known/klue-oauth-authorization-server.json - id: rfc9457-problem-details conforms: unknown evidence: No public error reference or OpenAPI document to evaluate. infrastructure: primary_cloud: Amazon Web Services secondary_cloud: Google Cloud Storage on_premise: false source: https://klue.com/product/security