generated: '2026-08-05' method: probed source: >- https://scs.sifive.com/.well-known/oauth-authorization-server, https://www.sifive.com/psirt-report-vulnerability, json-schema/sifive-duh-schema.json description: >- Cross-cutting standards conformance for SiFive's public surface. Assertions are drawn from live probes of the SiFive Cloud Services OAuth 2.0 authorization server, the published PSIRT disclosure policy, and the DUH JSON Schema — not from marketing claims. Note this covers the API/discovery surface only; SiFive's silicon-level standards work (RISC-V ISA ratification, ISO 26262 automotive, RISC-V CHERI and similar) is out of scope for this artifact. standards: - id: oauth2 name: OAuth 2.0 (RFC 6749) conforms: true evidence: >- Live authorization server at https://scs.sifive.com/o with authorization, token, revocation and introspection endpoints; authorization_code + refresh_token grants. - id: rfc8414-as-metadata name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: partial evidence: >- Document served at /.well-known/oauth-authorization-server (HTTP 200), but the declared `issuer` and every endpoint URL are http://localhost:8000/o rather than the deployed https://scs.sifive.com/o origin, which breaks RFC 8414 §3.3 issuer validation for a conformant client. See authentication/sifive-authentication.yml#issuer-points-at-localhost. - id: rfc7636-pkce name: PKCE (RFC 7636) conforms: true evidence: 'code_challenge_methods_supported: ["S256"]' - id: rfc7591-dynamic-client-registration name: OAuth 2.0 Dynamic Client Registration (RFC 7591) conforms: true evidence: 'registration_endpoint advertised; https://scs.sifive.com/o/register/ returns 405 to GET (POST-only)' - id: rfc7009-token-revocation name: OAuth 2.0 Token Revocation (RFC 7009) conforms: true evidence: 'revocation_endpoint advertised; https://scs.sifive.com/o/revoke_token/ returns 405 to GET' - id: rfc7662-token-introspection name: OAuth 2.0 Token Introspection (RFC 7662) conforms: true evidence: 'introspection_endpoint advertised; https://scs.sifive.com/o/introspect/ returns 403 to an unauthenticated caller' - id: oidc-core name: OpenID Connect Core 1.0 conforms: partial evidence: >- "openid" scope, userinfo endpoint (401 unauthenticated) and RS256 id_token signing are advertised, but the advertised JWKS is empty ({"keys": []}), so ID token signatures cannot be verified from published key material. - id: oidc-discovery name: OpenID Connect Discovery 1.0 conforms: false evidence: 'https://scs.sifive.com/.well-known/openid-configuration returns 404' - id: rfc9728-protected-resource-metadata name: OAuth 2.0 Protected Resource Metadata (RFC 9728) conforms: false evidence: >- /.well-known/oauth-protected-resource returns 404, so the MCP resource implied by the mcp:read / mcp:write scopes is not discoverable. - id: rfc7517-jwks name: JSON Web Key Set (RFC 7517) conforms: partial evidence: 'jwks_uri serves valid JWKS JSON but with an empty keys array' - id: rfc9116-security-txt name: security.txt conforms: false evidence: '/.well-known/security.txt returns 404 on both www.sifive.com and scs.sifive.com' - id: iso-iec-29147 name: ISO/IEC 29147 Vulnerability disclosure conforms: true evidence: 'SiFive PSIRT policy states adherence — https://www.sifive.com/psirt-report-vulnerability' - id: iso-iec-30111 name: ISO/IEC 30111 Vulnerability handling processes conforms: true evidence: 'SiFive PSIRT policy states adherence' - id: cvss name: Common Vulnerability Scoring System conforms: true evidence: 'PSIRT policy scores vulnerability severity with CVSS' - id: cve name: Common Vulnerabilities and Exposures conforms: true evidence: 'PSIRT policy uses CVE nomenclature' - id: json-schema-draft-07 name: JSON Schema draft-07 conforms: true evidence: 'json-schema/sifive-duh-schema.json declares $schema http://json-schema.org/draft-07/schema#' - id: ieee-1685-ip-xact name: IEEE 1685 IP-XACT conforms: true evidence: 'duh-ipxact provides IP-XACT import/export for DUH documents — https://github.com/sifive/duh-ipxact' - id: cmsis-svd name: CMSIS-SVD conforms: true evidence: 'duh-svd converts DUH documents to SVD — https://github.com/sifive/duh-svd' - id: openapi name: OpenAPI conforms: false evidence: 'No OpenAPI/Swagger document found on any SiFive host — see x-coverage in apis.yml' - id: asyncapi name: AsyncAPI conforms: false evidence: 'No event, streaming or webhook surface published' - id: rfc9457-problem-details name: RFC 9457 Problem Details conforms: false evidence: 'SCS errors use a custom {status, error_code, message} envelope — see errors/sifive-problem-types.yml' - id: a2a name: A2A Agent Card conforms: false evidence: '/.well-known/agent-card.json and /.well-known/agent.json return 404 on every SiFive host' compliance_program: published: false note: >- No trust center, and no SOC 2 / ISO 27001 / PCI / FedRAMP certification page found on sifive.com. Deliberately no `type: Compliance` pointer is wired in apis.yml — the standards above are conformance assertions, not a published compliance program.