generated: '2026-08-13' method: searched source: >- https://app.usenotch.ai/.well-known/oauth-authorization-server + https://app.usenotch.ai/.well-known/oauth-protected-resource/mcp + https://app.usenotch.ai/.well-known/mcp/server-card.json + live probe of https://app.usenotch.ai/mcp standards: - id: oauth2 conforms: true evidence: OAuth 2.0 authorization server metadata published; authorization_code + refresh_token grants - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: /.well-known/oauth-authorization-server returns 200 with issuer + endpoints (re-verified 2026-08-13) - id: rfc9728-oauth-protected-resource-metadata conforms: true evidence: /.well-known/oauth-protected-resource and .../mcp return 200 with resource + authorization_servers - id: rfc6750-bearer-token-usage conforms: true evidence: 'anonymous MCP request returns 401 with WWW-Authenticate: Bearer resource_metadata="..." and an {error, error_description} body' - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported = [S256] - id: rfc7591-dynamic-client-registration conforms: true evidence: registration_endpoint published; token_endpoint_auth_methods = none (public client) - id: mcp-model-context-protocol conforms: true evidence: streamable-http MCP server (version 1.0.1) with published server card at /.well-known/mcp/server-card.json; mcp-session-id and mcp-protocol-version headers advertised in CORS allow-headers - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 (OAuth 2.0 only, not OIDC) - id: rfc9457-problem-details conforms: false evidence: error responses use the OAuth {error, error_description} shape, not application/problem+json - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on app, www and apex hosts - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog returns 404 on all hosts - id: a2a-agent-card conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json return 404 on all hosts - id: openapi conforms: false evidence: no OpenAPI/Swagger document at any probed path on app, www or apex hosts (see x-coverage) compliance_program: published: false note: >- No trust center, no named certifications (SOC 2 / ISO 27001 / GDPR posture page) and no /security or /trust page were found — /security and /trust both 404 on www.usenotch.ai. No Compliance pointer is wired. checked: '2026-08-13'