generated: '2026-08-28' method: probed source: >- Live probes of api.solveintelligence.com OAuth/OIDC discovery documents and the MCP endpoint, plus the provider's published security page (https://www.solveintelligence.com/security) and trust center (https://trust.solveintelligence.com/) name: Solve Intelligence conformance description: >- Standards and compliance posture asserted for Solve Intelligence, split between protocol conformance verified against live machine-readable documents and organizational compliance claimed on the provider's own security and trust pages. standards: - id: oauth2 name: OAuth 2.0 (RFC 6749) conforms: true evidence: >- Authorization-code flow with authorization, token, revocation and introspection endpoints published at https://api.solveintelligence.com/auth/.well-known/openid-configuration (HTTP 200). - id: rfc6750 name: OAuth 2.0 Bearer Token Usage conforms: true evidence: >- https://api.solveintelligence.com/mcp/ returns HTTP 401 with a conformant WWW-Authenticate Bearer challenge; bearer_methods_supported is ["header"]. - id: rfc9728 name: OAuth 2.0 Protected Resource Metadata conforms: true evidence: >- https://api.solveintelligence.com/.well-known/oauth-protected-resource returns HTTP 200 with resource, authorization_servers, scopes_supported, bearer_methods_supported and resource_name. The 401 challenge also carries the resource_metadata parameter, which is the discovery hook the RFC specifies. - id: oidc name: OpenID Connect Discovery 1.0 conforms: true evidence: >- https://api.solveintelligence.com/auth/.well-known/openid-configuration returns HTTP 200 with issuer, jwks_uri, userinfo_endpoint, subject_types_supported and id_token_signing_alg_values_supported (RS256). - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata conforms: partial evidence: >- No document at /.well-known/oauth-authorization-server on the host root (HTTP 404). The equivalent metadata is served through the OIDC discovery path under the issuer, so the information is available but not at the RFC 8414 location. - id: mcp name: Model Context Protocol conforms: true evidence: >- First-party remote MCP server at https://api.solveintelligence.com/mcp/ over streamable HTTP, announced by the provider and listed as a Claude connector. tools/list is auth-gated (HTTP 401), so protocol version and tool schemas were not observable anonymously. - id: rfc8615 name: Well-Known URIs conforms: partial evidence: >- Two real documents served on the API host. No security.txt (RFC 9116) and no api-catalog (RFC 9727) anywhere on the estate. - id: llmstxt name: llms.txt conforms: true evidence: >- https://www.solveintelligence.com/llms.txt returns HTTP 200 with a conformant llms.txt structure (H1, blockquote summary, H2 link sections). Generated by FirstMotion. Content is marketing and blog navigation only - it does not describe the MCP server or any API. - id: rfc9457 name: Problem Details for HTTP APIs conforms: false evidence: >- Observed error bodies are a bare JSON object {"message":"unauthorised"} with content-type application/json, not application/problem+json. - id: a2a name: A2A Agent Card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json return HTTP 404 on api.solveintelligence.com and www.solveintelligence.com. On copilot.solveintelligence.com both return 404 as well; other well-known paths there return SPA HTML shells and were rejected as non-documents. domain_standards: applicable: false note: >- Reward-only check, and it is honestly not applicable here. The intellectual-property prosecution market does have machine-readable interchange standards - WIPO ST.96 XML and ST.26 sequence listings, EPO OPS and USPTO PatentsView/ODP data schemas - but Solve Intelligence exposes no contract that declares any of them. The only public surface is a single-tool MCP server whose schemas are auth-gated, so there is no spec location to point evidence at. Not penalized; recorded so a future round knows exactly which standards to probe for if the company publishes a contract. candidates_to_probe_next_round: - WIPO ST.96 (IP data XML schema) - WIPO ST.26 (sequence listings) - EPO Open Patent Services (OPS) - USPTO Open Data Portal / PatentsView schemas compliance: certifications: - name: SOC 2 Type II status: certified source: https://www.solveintelligence.com/security - name: ISO/IEC 27001 status: certified source: https://www.solveintelligence.com/security - name: ISO/IEC 42001 status: in-progress source: https://www.solveintelligence.com/security note: AI management system standard; the provider states certification is in progress. regulations: - name: GDPR status: claimed source: https://www.solveintelligence.com/security - name: CCPA status: claimed source: https://www.solveintelligence.com/security data_handling: model_training_excluded: true detail: >- The provider states customer data is not used to train or fine-tune its own models or third-party foundation models, and that it holds zero-data-retention agreements with third-party model providers. encryption: AES-256 at rest, TLS 1.3 in transit data_residency: >- Customer-selectable; the provider states it engages only US-based or EU-based subprocessors for data processing. trust_center: https://trust.solveintelligence.com/ verification_note: >- Certification claims are read from the provider's own published pages. Audit reports are described as available on request through the trust center and were not retrieved; these are recorded as published claims, not independently verified attestations. evidence: - url: https://api.solveintelligence.com/.well-known/oauth-protected-resource status: 200 - url: https://api.solveintelligence.com/auth/.well-known/openid-configuration status: 200 - url: https://api.solveintelligence.com/mcp/ status: 401 - url: https://api.solveintelligence.com/.well-known/oauth-authorization-server status: 404 - url: https://www.solveintelligence.com/llms.txt status: 200 - url: https://www.solveintelligence.com/security status: 200 - url: https://trust.solveintelligence.com/ status: 200