generated: '2026-08-13' method: probed source: openapi/_original/signal-ai-openapi-original.json + live /.well-known/ probes on api./mcp./login.signal-ai.com notes: >- Cross-cutting standards assertions. OAuth/OIDC/MCP-discovery entries are now PROBED against live documents rather than inferred from the spec. No industry-regulatory conformance (FHIR, FAPI, SCIM, PSD2, OData) is claimed or evidenced anywhere on Signal AI's public surface, and no compliance certification page (SOC 2 / ISO 27001 / trust center) was found — see gaps. standards: - id: openapi-3.1 conforms: true evidence: Document declares openapi 3.1.0 and self-serves it unauthenticated at https://api.signal-ai.com/openapi.json (HTTP 200, 20 operations). - id: oauth2 conforms: true evidence: securitySchemes declares oauth2 with a clientCredentials flow (tokenUrl https://api.signal-ai.com/auth/token). - id: oauth2-client-credentials conforms: true evidence: Machine-to-machine client_credentials grant with 7 scopes (default, search, metrics, affinity, events, risk-events, manage-organisation). - id: oidc conforms: true evidence: Backing IdP is Keycloak at https://login.signal-ai.com/auth/realms/signal, serving a valid openid-configuration (HTTP 200). - id: rfc8414-authorization-server-metadata conforms: true evidence: GET https://mcp.signal-ai.com/.well-known/oauth-authorization-server -> 200, saved to well-known/signal-ai-oauth-authorization-server.json. - id: rfc9728-protected-resource-metadata conforms: true evidence: GET https://mcp.signal-ai.com/.well-known/oauth-protected-resource -> 200 declaring resource, authorization_servers and scopes_supported [openid, mcp:tools, offline_access]. - id: rfc6750-bearer-www-authenticate conforms: true evidence: >- An unauthenticated POST to https://mcp.signal-ai.com/mcp returns 401 with a WWW-Authenticate Bearer header carrying both realm and a resource_metadata pointer at the RFC 9728 document. - id: mcp conforms: true evidence: Official hosted remote MCP server at https://mcp.signal-ai.com with a spec-correct OAuth challenge; tool list is auth-gated so tool-level conformance is unverified. - id: pkce-s256 conforms: true evidence: The MCP docs route (https://mcp.signal-ai.com/docs) 302s to a Keycloak authorization request carrying code_challenge_method=S256; the realm advertises S256 in code_challenge_methods_supported. - id: cursor-pagination conforms: true evidence: Documented Pagination section — `next-cursor` in responses, `from-cursor` + `size` in requests, absence of next-cursor terminates. - id: iso8601-utc conforms: true evidence: '"Dates & Time Zones" section mandates ISO 8601 with Z / UTC+0 for publication dates.' - id: rfc9457-problem-details conforms: false evidence: Errors are a proprietary {"errors":[[pointer,message]]} envelope in application/json; no type/title/status/detail and no application/problem+json media type. See errors/signal-ai-problem-types.yml. - id: rfc9331-ratelimit-headers conforms: false evidence: Rate limits are published as a documentation table only; no RateLimit-*, X-RateLimit-* or Retry-After header is documented or observed on a live response. - id: rfc8594-sunset-header conforms: false evidence: No Sunset/Deprecation header support and no published deprecation policy; the v1.1-deprecated affinity endpoints were removed outright. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on both https://signal-ai.com and https://api.signal-ai.com (probed 2026-08-13). - id: asyncapi conforms: false evidence: No event, streaming or webhook surface is published; /asyncapi.yaml and /webhooks 404 on the API host. - id: json-api conforms: false - id: odata conforms: false - id: fhir-r4 conforms: false - id: scim2 conforms: false - id: fapi conforms: false - id: psd2 conforms: false gaps: - id: compliance-certifications finding: >- No published SOC 2, ISO 27001, PCI, HIPAA or FedRAMP attestation and no trust center. https://signal-ai.com/security and /security-policy return 404; https://signal-ai.com/trust returns 200 but serves a JPEG image, not a trust page. No Compliance pointer is emitted, because none is evidenced. - id: vulnerability-disclosure finding: >- No security.txt, no /security page, no bug-bounty programme found on HackerOne, Bugcrowd or Intigriti. probe-security-programs.py reported vdp=none trust=none on 2026-08-13.