generated: '2026-08-12' method: searched source: >- Live probes of api.singular.net, s2s.singular.net, gdpr.singular.net, mcp.singular.net and www.singular.net, plus the Singular Help Center developer reference (https://support.singular.net/hc/en-us) and https://www.singular.net/data-security-privacy/ standards: - id: openapi conforms: false evidence: >- No OpenAPI/Swagger document on any host. /openapi.json, /openapi.yaml, /swagger.json, /api-docs, /docs, /redoc, /v1/openapi.json and /api/v2.0/openapi.json all return 404 on api.singular.net, s2s.singular.net, gdpr.singular.net, mcp.singular.net and www.singular.net. The API reference is prose in a Zendesk help center. - id: asyncapi conforms: false evidence: >- Singular has a real outbound event surface (postbacks) but publishes no AsyncAPI document. Captured instead as a webhook catalog in asyncapi/singular-postbacks-webhooks.yml. - id: graphql conforms: false evidence: No /graphql surface documented or discoverable. - id: mcp conforms: true evidence: >- First-party remote MCP server at https://mcp.singular.net/mcp-server/mcp, streamable HTTP transport, documented for ChatGPT/Claude/Cursor/VS Code Copilot/Gemini CLI. tools/list answers with an RFC 9728 Bearer challenge (401 invalid_token), which is the spec-correct unauthenticated response. - id: oauth2 conforms: true evidence: >- authorization_code flow with PKCE S256 on mcp.singular.net (and a second server on www.singular.net). REST APIs are API-key only and out of scope for this check. - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: 'https://mcp.singular.net/.well-known/oauth-authorization-server → 200 (saved verbatim)' - id: rfc9728-oauth-protected-resource-metadata conforms: true evidence: >- https://mcp.singular.net/.well-known/oauth-protected-resource → 200, and the 401 from the MCP endpoint carries a WWW-Authenticate header naming that resource_metadata URL. - id: rfc7591-dynamic-client-registration conforms: true evidence: 'registration_endpoint: https://mcp.singular.net/oauth_server/register' - id: rfc7636-pkce conforms: true evidence: 'code_challenge_methods_supported: ["S256"]' - id: rfc7517-jwks conforms: true evidence: 'https://mcp.singular.net/.well-known/jwks.json → 200 (RS256 signing key, kid singular-mcp)' - id: oidc-discovery conforms: false evidence: /.well-known/openid-configuration returns 404 on every Singular host, mcp.singular.net included. - id: rfc9457-problem-details conforms: false evidence: >- Errors use two proprietary envelopes — {status, substatus, value} on api.singular.net and {status:"ok"|"error", reason} on s2s.singular.net — not application/problem+json. See errors/singular-error-codes.yml. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on all nine hosts probed. - id: rfc8594-sunset-header conforms: false evidence: No Sunset/Deprecation header support documented; version retirement is announced in prose. - id: opendsr conforms: true version: 0.1.4 evidence: >- https://gdpr.singular.net/api/gdpr/discovery → 200, an OpenDSR/OpenGDPR discovery document declaring supported_identities and supported_subject_request_types [erasure, access]. Singular also maintains the OpenGDPR framework repo at github.com/singular-labs/opengdpr. - id: skadnetwork conforms: true evidence: >- Full SKAdNetwork/AdAttributionKit postback receipt, conversion-value modelling and a dedicated SKAN reporting API; Singular maintains the SKAN standard repo at github.com/singular-labs/skan. - id: llmstxt conforms: true evidence: 'https://www.singular.net/llms.txt → 200 (196 KB, saved verbatim to llms/)' - id: a2a-agent-card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json return 404 on all nine hosts probed 2026-08-12. No agent card is published, so no AgentCard artifact was written. compliance_program: published: true url: https://www.singular.net/data-security-privacy/ certifications: [SOC 1, SOC 2, ISO 27001, ePrivacy, CSA STAR, COPPA (PRIVO), GDPR Kids (PRIVO), EU-U.S. Data Privacy Framework] regulations: [GDPR, CCPA, COPPA, Apple ATT] detail: security/singular-trust-center.yml