generated: '2026-08-04' method: derived source: openapi/passivelogic-rest-api-openapi.yml docs: https://quantumalliance.org/documentation/ standards: - id: openapi-3.0 conforms: true evidence: OpenAPI 3.0.1 document published at https://passivelogic.com/api/doc and rendered at /app/swagger/ - id: openapi-3.1 conforms: false evidence: spec declares openapi 3.0.1 - id: graphql conforms: true evidence: >- GraphQL endpoint at /api/graphql (GET and POST), GraphQLRequest/GraphQLResult/GraphQLError schemas in the OpenAPI, and GraphQL documented as the Quantum API query language - id: graphql-over-websocket conforms: true evidence: >- /api/graphqlSubscribe opens a WebSocket for GraphQL subscriptions; the PassiveLogic GitHub org publishes Swift implementations of the graphql-ws and graphql-transport-ws subprotocols - id: oidc-discovery conforms: true evidence: >- RFC 8414 / OpenID Connect Discovery document served at https://login.passivelogic.com/realms/prod/.well-known/openid-configuration - id: oauth2 conforms: true evidence: >- authorization_code (PKCE S256), client_credentials, device_code, refresh_token, token-exchange and CIBA grants advertised by the Keycloak realm - id: oauth2-dpop conforms: true evidence: dpop_signing_alg_values_supported present in the realm discovery document - id: oauth2-mtls-bound-tokens conforms: true evidence: tls_client_certificate_bound_access_tokens is true in the realm discovery document - id: jwt-jwks conforms: true evidence: PassiveLogic publishes its token-signing JWKS anonymously at GET /api/auth/keys (ES384 / P-384) - id: rfc9457-problem-details conforms: false evidence: failures use a custom {"error":true,"reason":"..."} envelope; no application/problem+json - id: rfc9116-security-txt conforms: false evidence: no /.well-known/security.txt on passivelogic.com, login.passivelogic.com or quantumalliance.org - id: rfc8594-sunset-header conforms: false evidence: operations carry deprecated:true in the spec but no Sunset or Deprecation response headers - id: a2a-agent-card conforms: false evidence: no /.well-known/agent-card.json or /.well-known/agent.json on any PassiveLogic host - id: llms-txt conforms: false evidence: /llms.txt on passivelogic.com returns the Framer SPA HTML shell, not an llms.txt document - id: asyncapi conforms: false evidence: real WebSocket event surface exists (/api/graphqlSubscribe, /api/quantumsync) but no AsyncAPI is published - id: quantum-digital-twin-standard conforms: true evidence: >- PassiveLogic authors and implements the Quantum standard (open physics-based digital twin ontology, developed with the U.S. Department of Energy and the Quantum Alliance consortium); the running server reports Quantum Schema 0.28.0 at GET /api/util/quantumversion - id: brick-schema conforms: false evidence: >- the Quantum documentation positions Quantum as a complement to, not an implementation of, Brick and Project Haystack - id: project-haystack conforms: false evidence: same — named as an adjacent semantic standard, not implemented compliance_program: published: false certifications: [] trust_center: null note: >- No trust centre, SOC 2 / ISO 27001 claim, compliance page or security policy was found on any PassiveLogic host. probe-security-programs.py returned vdp=none trust=none. x-evidence: fetched: '2026-08-04' probes: - url: https://passivelogic.com/api/doc http_status: 200 - url: https://login.passivelogic.com/realms/prod/.well-known/openid-configuration http_status: 200 - url: https://passivelogic.com/api/auth/keys http_status: 200 - url: https://passivelogic.com/.well-known/agent-card.json http_status: 301 note: Framer SPA catch-all, not an agent card