generated: '2026-07-20' method: searched source: >- Qogita /.well-known/ discovery documents on api.qogita.com standards: - id: oauth2 conforms: true evidence: >- Authorization server metadata advertises authorization_code + refresh_token grants with a token endpoint (RFC 6749 / OAuth 2.1). - id: oauth2-pkce conforms: true evidence: code_challenge_methods_supported includes S256 (RFC 7636). - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: /.well-known/oauth-authorization-server returns 200 with issuer + endpoints. - id: rfc9728-oauth-protected-resource-metadata conforms: true evidence: >- /.well-known/oauth-protected-resource/staff/mcp returns 200; the MCP endpoint issues a WWW-Authenticate Bearer challenge referencing it. - id: oidc-discovery conforms: true evidence: /.well-known/openid-configuration returns 200. - id: mcp conforms: true evidence: Hosted Model Context Protocol server at api.qogita.com/staff/mcp (OAuth-protected). - id: dnssec conforms: true evidence: qogita.com zone is DNSSEC-signed (see security/qogita-domain-security.yml). notes: >- Conformance asserted from live discovery documents. No published compliance program (SOC 2 / ISO 27001 / PCI / GDPR certification page) was found, so no Compliance pointer is emitted.