generated: '2026-08-26' method: searched source: >- https://support.doubleoctopus.com/support/solutions/articles/33000294232-frequently-ask-questions, https://doubleoctopus.com/products/octopus-authentication-platform/, https://doubleoctopus.com/llms.txt, https://fidoalliance.org/company/secret-double-octopus/ note: >- All entries below are the PROVIDER'S OWN published claims, read from SDO's public pages. No machine-readable contract exists for this provider, so nothing here is derived from a spec and none of it was independently verified against a certificate registry other than the FIDO Alliance company listing. standards: - id: fido2 name: FIDO2 / WebAuthn conforms: true evidence: claim: '"Our platform is FIDO2 certified"' url: https://support.doubleoctopus.com/support/solutions/articles/33000294232-frequently-ask-questions registry: https://fidoalliance.org/company/secret-double-octopus/ - id: oidc name: OpenID Connect conforms: true evidence: claim: Listed among supported protocols (OIDC) for application integration url: https://support.doubleoctopus.com/support/solutions/articles/33000294232-frequently-ask-questions - id: saml name: SAML 2.0 conforms: true evidence: claim: Listed among supported protocols (SAML) for application integration url: https://support.doubleoctopus.com/support/solutions/articles/33000294232-frequently-ask-questions - id: radius name: RADIUS conforms: true evidence: claim: Listed among supported protocols (RADIUS) url: https://support.doubleoctopus.com/support/solutions/articles/33000294232-frequently-ask-questions - id: ws-federation name: WS-Federation conforms: true evidence: claim: Listed among supported protocols (WS-Federation) url: https://support.doubleoctopus.com/support/solutions/articles/33000294232-frequently-ask-questions - id: ws-trust name: WS-Trust conforms: true evidence: claim: Listed among supported protocols (WS-Trust) url: https://support.doubleoctopus.com/support/solutions/articles/33000294232-frequently-ask-questions - id: ldap name: LDAP / LDAPS conforms: true evidence: claim: Listed among supported protocols (LDAP/LDAPS) url: https://support.doubleoctopus.com/support/solutions/articles/33000294232-frequently-ask-questions - id: x509 name: X.509 smart card authentication conforms: true evidence: claim: X.509 smartcards listed as a supported authenticator url: https://doubleoctopus.com/products/octopus-authentication-platform/ - id: fips-140-2 name: FIPS 140-2 conforms: true evidence: claim: '"Secret Double Octopus is FIPS 140-2 certified"' url: https://support.doubleoctopus.com/support/solutions/articles/33000294232-frequently-ask-questions - id: nist-800-63-aal3 name: NIST SP 800-63 AAL3 conforms: claimed evidence: claim: '"Delivers AAL3-level authentication."' url: https://doubleoctopus.com/llms.txt - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: unknown evidence: note: >- No public error reference and no machine-readable contract; the error envelope of the Management Console REST API could not be observed. - id: scim name: SCIM conforms: unknown evidence: note: >- SDO documents REST API integration with IDM platforms such as SailPoint but nowhere states SCIM support; no SCIM schema URN was observed. Not claimed. domain_standard: market: workforce identity and access management / authentication standards_probed: - fido2 - webauthn - oidc - saml - scim - radius declared_in_contract: false note: >- REWARD-ONLY and NOT awarded here. SDO's market does have domain standards and SDO claims several of them (FIDO2 certification is registry-verifiable), but the check reads the CONTRACT, and SDO publishes no machine-readable contract in which a domain standard could be declared. The claims above are prose on marketing and support pages, which is exactly the distinction this check draws. Nothing invented to fill the slot. compliance: certifications: - name: SOC 2 scope: Octopus Cloud (SaaS deployment) claim: '"SOC2 certified Octopus Cloud"' url: https://doubleoctopus.com/products/octopus-authentication-platform/ - name: ISO 27001 scope: Information Security Management System claim: SDO maintains its ISMS in accordance with the requirements of ISO 27001 url: https://doubleoctopus.com/dpa/ - name: FIPS 140-2 scope: cryptographic modules url: https://support.doubleoctopus.com/support/solutions/articles/33000294232-frequently-ask-questions - name: FIDO2 / FIDO Certified scope: authenticator and server url: https://fidoalliance.org/company/secret-double-octopus/ regimes_supported: - NIST - PCI DSS - CIS - CCPA - NYDFS - CMMC - FFIEC - GDPR - ISO 27001 - SOC 2 regimes_source: https://doubleoctopus.com/llms.txt data_processing_addendum: https://doubleoctopus.com/dpa/ trust_center: published: false note: >- trust.doubleoctopus.com does not resolve and no /trust, /security or /compliance page was found; certification claims are scattered across the platform page, the DPA and the support FAQ rather than collected in a trust center.