generated: '2026-07-21' method: searched source: https://rillet.com/product/security-and-permissions standards: - id: oauth2 conforms: true evidence: RFC 8414 authorization-server metadata + oauth2 authorization-code flow (PKCE S256) - id: rfc9728-protected-resource conforms: true evidence: /.well-known/oauth-protected-resource advertises resource + scopes - id: rfc9457-problem-details conforms: true evidence: docs state error responses follow RFC 9457 application/problem+json - id: rfc8594-sunset conforms: false evidence: version cutover documented but no Sunset/Deprecation response headers found - id: idempotency-key conforms: true evidence: Idempotency-Key header on POST, 24h retention - id: keyset-pagination conforms: true evidence: cursor/limit keyset pagination with next_cursor - id: mtls-bound-tokens conforms: true evidence: tls_client_certificate_bound_access_tokens true in OAuth metadata - id: dpop conforms: true evidence: dpop_signing_alg_values_supported present in OAuth metadata - id: soc2-type2 conforms: true evidence: SOC 2 Type II annual third-party audit (security-and-permissions page) - id: soc1-type2 conforms: true evidence: SOC 1 Type II controls for customers' financial reporting - id: gdpr conforms: true evidence: GDPR-aligned data handling (security-and-permissions page) - id: fhir-r4 conforms: false - id: scim2 conforms: false compliance: page: https://rillet.com/product/security-and-permissions certifications: - SOC 2 Type II - SOC 1 Type II - GDPR - SOX-ready by design encryption: at_rest: AES-256 in_transit: TLS 1.2+ hosting: AWS