generated: '2026-08-14' method: searched source: https://matchory.com/en/technology standards: - id: oauth2 conforms: true evidence: >- Full OAuth 2.0 authorization server at discovery.matchory.com with authorize/token/revoke/register endpoints (well-known/matchory-oauth-authorization-server.json). - id: oidc conforms: true evidence: >- OpenID Connect discovery document at /.well-known/openid-configuration; userinfo + id_token (RS256). - id: oauth2-pkce conforms: true evidence: code_challenge_methods_supported = [S256]. - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: /.well-known/oauth-authorization-server returns 200 metadata. - id: rfc9728-oauth-protected-resource-metadata conforms: true evidence: >- /.well-known/oauth-protected-resource advertises resource https://discovery.matchory.com and scope mcp:use for the MCP server. - id: oauth2-token-exchange conforms: true evidence: grant_types include urn:ietf:params:oauth:grant-type:token-exchange. - id: saml2 conforms: true evidence: Enterprise SSO via SAML 2.0 (technology page). - id: iso-27001 conforms: true evidence: ISO 27001 certified for information security (technology page). - id: gdpr conforms: true evidence: GDPR compliant, EU data-protection aligned, hosted in Germany (technology page). - id: mcp conforms: true evidence: First-party Model Context Protocol server at https://discovery.matchory.com/mcp. - id: soc2 conforms: false evidence: No SOC 2 attestation published. - id: rfc6750-bearer-token conforms: true evidence: >- POST https://discovery.matchory.com/mcp returns HTTP 401 with 'WWW-Authenticate: Bearer realm="mcp", error="invalid_token"' (probed 2026-08-14). - id: rfc9116-security-txt conforms: false evidence: >- /.well-known/security.txt is 404 on matchory.com and api.matchory.com, and answers the SPA HTML shell on discovery.matchory.com. No security.txt is served. - id: rfc9457-problem-details conforms: false evidence: >- No application/problem+json response was observed and no error reference is published. The MCP surface uses the JSON-RPC 2.0 error object instead. - id: rfc8594-sunset-header conforms: false evidence: No deprecation or sunset policy is published; no Sunset header observed. - id: rfc9331-ratelimit-headers conforms: false evidence: No RateLimit-* or X-RateLimit-* headers observed; no limits published. - id: content-signals conforms: true evidence: >- matchory.com/robots.txt publishes a Cloudflare-managed Content-Signal policy (search=yes, ai-train=no, use=reference) as an express Article 4 (EU 2019/790) reservation of rights, plus explicit Disallow for nine named AI crawlers. Saved verbatim at well-known/matchory-robots.txt. - id: a2a conforms: false evidence: >- No agent card at /.well-known/agent-card.json or /.well-known/agent.json on any of matchory.com, discovery.matchory.com, api.matchory.com (probed 2026-08-14). - id: openapi conforms: false evidence: >- No OpenAPI/Swagger document found on any host after full contract discovery (2026-08-14) — see x-coverage in apis.yml. - id: graphql conforms: false evidence: >- A "GraphQL endpoint" is advertised on matchory.com/en/technology, but no introspectable endpoint is publicly reachable: POST to /graphql, /api/graphql and /v1/graphql on discovery.matchory.com returns HTTP 405 Method Not Allowed (the SPA catch-all is GET-only), and api.matchory.com/graphql returns 404. No SDL captured.