generated: '2026-08-13' method: derived source: >- https://www.getnoded.ai/security, https://www.getnoded.ai/developers, npm @bigfootai/noded-sdk@0.1.2 note: >- Assertions are limited to what Noded actually publishes. Noded is a SaaS application with a GraphQL API and a hosted MCP layer; most REST-shaped standards below are simply not applicable and are recorded as conforms:false with that reason rather than left out. standards: - id: oidc name: OpenID Connect Core 1.0 conforms: true evidence: >- Browser auth is OIDC authorization-code with PKCE against a Noded-hosted Auth0 tenant (issuer https://login.getnoded.ai/), requesting openid profile email offline_access with an audience parameter, per the developer page and the first-party SDK. caveat: >- The issuer host does not resolve in public DNS, so /.well-known/openid-configuration discovery cannot be verified anonymously. - id: oauth2 name: OAuth 2.0 / 2.1 conforms: true evidence: >- Authorization-code + PKCE, refresh tokens via offline_access, Bearer token in the Authorization header. caveat: >- The apiKey mode transports a composite 'Bearer apiKey::' string, which is not an OAuth 2.0 access token. - id: graphql name: GraphQL (June 2018 spec) over HTTP conforms: true evidence: >- Apollo Server at POST /api/v1/graph; standard { data, errors[] } response envelope; named operations with typed *Input variables. - id: mcp name: Model Context Protocol conforms: unknown evidence: >- Noded states it ships a single hosted MCP layer that Claude, ChatGPT and Gemini connect to, but publishes no endpoint, no transport detail, and no protocol version, so conformance cannot be verified. See mcp/noded-ai-mcp.yml. - id: rfc9457 name: RFC 9457 Problem Details conforms: false evidence: GraphQL errors[] envelope; no application/problem+json anywhere. - id: idempotency name: Idempotency keys (draft-ietf-httpapi-idempotency-key-header) conforms: false evidence: No idempotency key or header is documented in the SDK, developer page, or AGENTS.md. - id: pagination name: Documented pagination conforms: false evidence: >- Only a `limit` option is exposed; no cursor, offset, page token, or total count is documented, so a consumer cannot page deterministically. - id: rfc9116 name: RFC 9116 security.txt conforms: false evidence: /.well-known/security.txt returns 404 on www.getnoded.ai. - id: rfc8594 name: RFC 8594 Sunset header conforms: false evidence: No deprecation or sunset policy published. - id: openapi name: OpenAPI conforms: false evidence: >- No OpenAPI is published. The API is GraphQL; probes of /openapi.json, /swagger.json and /api-docs on every host missed (404 on www, 403 on the app origin, NXDOMAIN on api). applicable: false - id: asyncapi name: AsyncAPI conforms: false evidence: No event, streaming, or webhook surface is documented. applicable: false - id: a2a name: A2A Agent Card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json return 404 on www.getnoded.ai and 403 on app.getnoded.ai. compliance: certifications: - name: SOC 2 status: audited source: https://www.getnoded.ai/security - name: GDPR status: stated alignment source: https://www.getnoded.ai/security ai_commitments: - does not train on customer data - contractual prohibition on AI subprocessors training on customer data - no data stored with LLM providers - permission-aware access; data stays in place; write-backs opt-in policy_url: https://www.getnoded.ai/ai-policy report_available: not-published note: >- Certifications are asserted on Noded's own security page. No trust portal, no downloadable report, no subprocessor list, and no auditor named. conforms_count: 3