generated: '2026-07-19' method: searched source: https://lightsource.ai/security # LightSource publishes no public API, OpenAPI, or developer surface as of # 2026-07-19, so the API-shaped standards below cannot be asserted and are # recorded as unknown rather than false-by-derivation. standards: - id: soc2-type2 conforms: true evidence: SOC 2 Type 2 attestation report issued by Sensiba for the LightSource platform source: https://lightsource.ai/security - id: tls conforms: true evidence: TLSv1.3 with HSTS max-age=31536000 (security/lightsource-domain-security.yml) - id: sso-saml-oidc conforms: true evidence: security page documents single sign-on (SSO) and MFA support for the platform source: https://lightsource.ai/security - id: llms-txt conforms: true evidence: publishes a valid llms.txt at https://lightsource.ai/llms.txt - id: oauth2 conforms: unknown evidence: no public API or securitySchemes published - id: oidc conforms: unknown evidence: SSO is offered to customers but no public OIDC discovery document - id: rfc9457-problem-details conforms: unknown evidence: no public API specification to evaluate - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns catch-all HTML, not RFC 9116 text - id: iso-27001 conforms: false evidence: not claimed on the published security page