generated: '2026-08-13' method: probed source: >- https://api.persado.com/.well-known/oauth-authorization-server, https://api.persado.com/.well-known/oauth-protected-resource, https://myaccount.persado.com/realms/persado-portal/.well-known/openid-configuration, https://api.persado.com/mcp, https://www.persado.com/platform supersedes: >- The 2026-07-20 revision of this file, which recorded oauth2 and openid-connect as conforms: false on the basis that Persado published no OAuth surface. That was wrong. It was reached by probing only www.persado.com; the API host api.persado.com serves a complete OAuth 2.0 / OIDC discovery surface and a production MCP gateway. Both entries are corrected below with live evidence. notes: >- Persado publishes no OpenAPI, so no REST-shaped standards (RFC 9457, JSON:API, OData, pagination conventions) can be asserted either way — they are recorded as unknown, not false. The standards Persado DOES demonstrably conform to are all in the OAuth / OIDC / MCP identity family, and they are conformed to properly: RFC 8414, RFC 9728, RFC 7591 and the MCP authorization spec are all implemented correctly, including the WWW-Authenticate resource_metadata challenge most MCP deployments get wrong. standards: - id: oauth2 conforms: true evidence: >- RFC 8414 authorization-server metadata served at https://api.persado.com/.well-known/oauth-authorization-server (HTTP 200); authorization_code + refresh_token grants against a Keycloak issuer. - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: 'HTTP 200, application/json, valid AS metadata document with issuer, authorization_endpoint, token_endpoint, jwks_uri' - id: rfc9728-oauth-protected-resource-metadata conforms: true evidence: >- HTTP 200 at /.well-known/oauth-protected-resource naming resource https://api.persado.com/mcp and its authorization_servers[]; also served at the resource-scoped /.well-known/oauth-protected-resource/mcp alias. - id: rfc7591-dynamic-client-registration conforms: true evidence: >- registration_endpoint https://api.persado.com/register advertised in AS metadata; GET returns 405 (POST-only), confirming a live DCR endpoint. - id: rfc7636-pkce conforms: true evidence: 'code_challenge_methods_supported: ["S256"] on the MCP gateway — S256 only, plain not offered' - id: oauth2.1-public-client conforms: true evidence: 'token_endpoint_auth_methods_supported: ["none"] with mandatory S256 PKCE — the OAuth 2.1 public-client profile' - id: openid-connect conforms: true evidence: >- Full OIDC Discovery 1.0 document at https://myaccount.persado.com/realms/persado-portal/.well-known/openid-configuration (HTTP 200) with userinfo, introspection, revocation and end_session endpoints. - id: rfc6750-bearer-token conforms: true evidence: 'bearer_methods_supported: ["header"]; POST /mcp returns 401 with a WWW-Authenticate: Bearer challenge' - id: mcp-authorization conforms: true evidence: >- POST https://api.persado.com/mcp returns HTTP 401 with WWW-Authenticate: Bearer resource_metadata="https://api.persado.com/.well-known/oauth-protected-resource" — the discovery hand-off the MCP authorization specification requires. - id: model-context-protocol conforms: true evidence: >- Live remote MCP server "Persado MCP Gateway (Production)" at https://api.persado.com/mcp. Tool list is auth-gated so protocol version and capabilities could not be observed. partial: true note: 'presence and authorization behaviour verified; tools/list gated behind the mcp:tools scope' - id: rfc9116-security-txt conforms: false evidence: '/.well-known/security.txt returns 404 on www.persado.com, api.persado.com and myaccount.persado.com' - id: a2a-agent-card conforms: false evidence: '/.well-known/agent-card.json and /.well-known/agent.json return 404 on every Persado host' - id: llms-txt conforms: true evidence: 'https://www.persado.com/llms.txt returns HTTP 200, text/plain, valid llms.txt structure' - id: openapi conforms: false evidence: >- No OpenAPI document found on api.persado.com, portal.persado.com or www.persado.com after probing /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs, /redoc and /v2/api-docs. - id: rfc9457-problem-details conforms: unknown evidence: 'no public spec and no anonymously reachable error body to assert an error format' - id: graphql conforms: false evidence: '/graphql returns 404 on api.persado.com' - id: soc2-type-ii conforms: true evidence: 'Persado states SOC 2 Type II on https://www.persado.com/platform' - id: iso-27001 conforms: partial evidence: >- Persado states "ISO 27001 Aligned" and an "ISMS aligned to ISO 27001:2013" on https://www.persado.com/platform. Alignment is claimed, certification is NOT claimed — recorded as partial rather than true. - id: gdpr conforms: true evidence: 'GDPR compliance stated on https://www.persado.com/platform; GDPR sub-processors page referenced' - id: pci-dss conforms: partial evidence: >- "PCI DSS Level 1" is stated on https://www.persado.com/platform as a property of the AWS hosting environment, not of Persado's own assessment. compliance_program: published: true certifications: - SOC 2 Type II - GDPR aligned_not_certified: - ISO 27001:2013 (stated as "aligned", not certified) inherited_from_infrastructure: - PCI DSS Level 1 (AWS hosting) regulatory_frameworks_claimed: '20+ regulatory frameworks (per product marketing)' regulated_verticals: - banking - credit cards - credit unions - fintech - insurance - mortgage named_regulations_in_marketing: - NCUA - UDAAP - Reg DD - TILA - Reg Z - ECOA source: https://www.persado.com/platform trust_center: null trust_center_note: >- No trust center exists. trust.persado.com does not resolve; /trust, /security and /legal/trust-center all return 404 on www.persado.com. Certifications are stated in marketing copy on the platform page only, with no downloadable report, no subprocessor register at a stable URL and no audit-letter request flow.