generated: '2026-08-13' method: searched source: - https://raw.githubusercontent.com/About-Intelligence/soku-cli/main/skills/soku/references/auth-workspace.md - https://raw.githubusercontent.com/About-Intelligence/soku-cli/main/skills/soku/SKILL.md - https://soku.ai/pricing - https://api.soku.ai/mcp - cli/nexad-capabilities.json product: Nexad / Soku (About Intelligence, Inc.) notes: >- Standards conformance read from the provider's published docs and live probes. Nexad publishes no OpenAPI, so several spec-level standards cannot be asserted either way and are recorded as conforms:false with the reason, rather than left out. No certifications page, trust center or audit report was found on any host, so no Compliance pointer is emitted — the only compliance signal the company publishes is that a "security review" is an ENTERPRISE PLAN FEATURE on the pricing page, which is a sales term, not a published certification. standards: - id: oauth2-device-authorization-grant name: OAuth 2.0 Device Authorization Grant (RFC 8628) conforms: true evidence: >- `soku auth login` runs a device flow returning a verification_uri and a user_code, resumable with `--device-code ` — the RFC 8628 shape. Documented in the provider's auth-workspace reference. - id: oauth2-scopes name: OAuth 2.0 scopes / resource indicators conforms: false evidence: >- No scope model. The provider states plainly: "A default `soku auth login` reaches the entire CLI surface — there is no resource model to grant or check." Authorization is enforced by the human review gate instead of by token scope. - id: bearer-token-usage name: OAuth 2.0 Bearer Token Usage (RFC 6750) conforms: true evidence: >- Authorization Bearer header; /api/cli/capabilities returns 401 missing_bearer unauthenticated (observed live 2026-08-13). - id: oidc-discovery name: OpenID Connect Discovery conforms: false evidence: /.well-known/openid-configuration returns 404 on nex.ad, soku.ai and docs.nex.ad; 401 on api.soku.ai. - id: rfc8414-oauth-authorization-server-metadata name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: false evidence: /.well-known/oauth-authorization-server returns 404 on the public hosts and 401 on api.soku.ai. - id: rfc9728-oauth-protected-resource-metadata name: OAuth 2.0 Protected Resource Metadata (RFC 9728) conforms: false evidence: >- /.well-known/oauth-protected-resource is not served. This is the notable gap for an MCP-bearing provider — it is the document an MCP client uses to discover how to authorize against https://api.soku.ai/mcp. - id: mcp name: Model Context Protocol conforms: true partial: true evidence: >- A hosted MCP endpoint is served at https://api.soku.ai/mcp. A live tools/list JSON-RPC POST returned HTTP 401 (auth-gated), so protocol conformance beyond the presence of the endpoint and its auth challenge could not be verified anonymously. The endpoint returns the platform's own JSON error envelope rather than an MCP/OAuth challenge with a WWW-Authenticate header, which is itself a deviation from the MCP authorization spec. - id: rfc9457-problem-details name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: >- Errors use a proprietary {"success","data","error":{"code","message","details"},"meta"} envelope, not application/problem+json. See errors/nexad-error-codes.yml. - id: rfc9116-security-txt name: security.txt (RFC 9116) conforms: false evidence: >- 404 on nex.ad, soku.ai and docs.nex.ad. A real disclosure policy DOES exist (security@soku.ai, GitHub private reporting, 3-business-day acknowledgement) but is published only as SECURITY.md in the company's GitHub repo. See security/nexad-vulnerability-disclosure.yml. - id: rfc8615-well-known-uris name: Well-Known URIs (RFC 8615) conforms: false evidence: No /.well-known/ document returned 200 on any host. See well-known/nexad-well-known.yml. - id: a2a-agent-card name: A2A Agent Card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json probed on nex.ad, soku.ai, docs.nex.ad and api.soku.ai — 404 (HTML) on the public hosts, 401 on api.soku.ai. No card published. - id: llmstxt name: llms.txt conforms: true evidence: >- https://soku.ai/llms.txt returns 200 text/plain with a conformant llms.txt (H1, blockquote summary, sectioned link lists), plus a companion https://soku.ai/llms-full.txt. Saved verbatim to llms/nexad-soku-llms.txt. This is NEW since the previous enrichment pass, which recorded 404. - id: agent-skills name: Agent Skills (frontmatter + markdown, with references/) conforms: true evidence: >- The provider ships a conformant Agent Skill at skills/soku/SKILL.md in its public repo — YAML frontmatter (name, description, license, metadata.author, metadata.version) plus a seven-file references/ router — and publishes 52 installable business skills. Saved verbatim to skills/soku/. - id: x-agentic-access name: Agentic access / execution-contract classification conforms: true partial: true evidence: >- Not the x-agentic-access vocabulary itself, but a functionally equivalent provider-published classification: every one of the 281 registry actions carries a `mode` (read/write/risk) and a `requires_review` flag, and the platform enforces a human-approval gate on 124 of them at runtime. Mapped in agentic-access/nexad-agentic-access.yml. - id: rfc8594-sunset-header name: Sunset HTTP Header (RFC 8594) conforms: false evidence: >- No Sunset or Deprecation headers observed and no published deprecation policy. Ten registry actions are marked deprecated in prose only. - id: semver name: Semantic Versioning conforms: true partial: true evidence: >- @soku-ai/cli is published to npm on semver prerelease tags (0.1.0-alpha.17). The API itself reports a build version (v4.61.0) alongside a separate /v1 path, which are two different version schemes. - id: spdx-license name: Published open-source licensing conforms: true evidence: >- The CLI, the agent skill and the marketing-skills hub are MIT-licensed in the About-Intelligence GitHub org (38 public repositories). - id: openapi name: OpenAPI conforms: false evidence: >- No OpenAPI at any probed location on api.soku.ai, soku.ai, nex.ad or docs.nex.ad (see x-coverage in apis.yml). The machine-readable substitute the provider does ship is the capability registry, cli/nexad-capabilities.json. - id: asyncapi name: AsyncAPI / event surface conforms: false not_applicable: true evidence: >- No webhook, event or streaming surface found — zero webhook references across 281 registry actions and no webhook documentation. Not a gap; this platform has no event surface to describe. certifications: published: [] trust_center: null note: >- No SOC 2 / ISO 27001 / PCI / HIPAA / GDPR certification page, trust center or audit report found on nex.ad, soku.ai, trust.soku.ai or docs.nex.ad. The pricing page lists "security review" as an Enterprise-tier inclusion, which is a contract term rather than a published compliance program, so no Compliance pointer is emitted.