generated: '2026-08-17' method: probed source: >- Live probes of api.odaseva.com / platform.odaseva.com / www.odaseva.com plus the published trust page (www.odaseva.com/security-trust) and the first-party odaseva-cli npm release. No OpenAPI/AsyncAPI/GraphQL contract exists for this provider, so no spec-derived conformance could be computed. standards: - id: oauth2 conforms: true scope: platform-login evidence: >- api.odaseva.com/.well-known/openid-configuration (HTTP 200) advertises authorization/token/revocation/introspection endpoints — but as the SALESFORCE platform authorization server (issuer https://login.salesforce.com), not an Odaseva-operated one. - id: oidc conforms: true scope: platform-login evidence: >- Same document: OIDC discovery with jwks_uri, userinfo_endpoint, RS256 id_token signing, DPoP signing algs. Owner is Salesforce; Odaseva inherits it as a Salesforce-hosted app. - id: rfc9116-security-txt conforms: true evidence: >- www.odaseva.com/.well-known/security.txt (HTTP 200) with Contact, Expires, Preferred-Languages and Policy fields. - id: openapi conforms: false evidence: >- No spec at any probed location on www.odaseva.com, api.odaseva.com, platform.odaseva.com or trust.odaseva.com (/openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs, /redoc all 401 or 404). - id: asyncapi conforms: false evidence: No event, streaming or webhook surface published; no AsyncAPI document found. - id: mcp conforms: false evidence: No hosted MCP server and no MCP package published by Odaseva. - id: a2a conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json probed on all four hosts — 404 on www and trust, 401 on api and platform. No agent card exists. - id: rfc9457-problem-details conforms: unknown evidence: No public contract or error reference to read; cannot be asserted either way. - id: rfc8594-sunset-header conforms: unknown evidence: No public deprecation policy; see lifecycle/odaseva-lifecycle.yml. - id: llms-txt conforms: false evidence: www.odaseva.com/llms.txt => 404 (a generated one is kept at llms/odaseva-llms.txt). compliance_program: published: true url: https://www.odaseva.com/security-trust certifications: - SOC 2 Type II - ISO 27001:2022 - HITRUST - HIPAA - GDPR - CCPA - TISAX - IRAP - MLPS 2.0 - CSA STAR Level 2 auditor: Ernst & Young source: security/odaseva-trust-center.yml note: >- Odaseva's conformance story is a REGULATORY / CERTIFICATION one, not an API-standards one: a deep, independently audited compliance program with no machine-readable API contract behind it. The `Compliance` and `TrustCenter` pointers in apis.yml already carry this.