generated: '2026-08-29' method: searched source: >- https://www.sparxsystems.jp/help/17.0/oslc_am_top.html, https://www.sparxsystems.jp/help/17.0/creation_factory.html, https://www.sparxsystems.jp/help/17.0/query_capability.html, https://www.sparxsystems.jp/help/17.0/oslc_user_cred.html, https://www.sparxsystems.us/pro-cloud-server/ description: >- Standards conformance for the Sparx Systems Enterprise Architect platform, split between the API/protocol layer (what the Pro Cloud Server OSLC interface implements) and the modelling notation layer (what Enterprise Architect authors). The notation layer is unusual for this catalog: for a modelling tool the notations ARE the interchange contract, because a model exported as XMI in a declared notation is what actually moves between vendors. domain_standard: id: oslc-am-2.0 name: OSLC Architecture Management v2.0 declared_in_contract: true evidence: >- The Pro Cloud Server acts as an OSLC Service Provider and the documentation enumerates the Architecture Management 2.0 base requirements it satisfies. The wire format carries the canonical namespace http://open-services.net/ns/rm# alongside Dublin Core dcterms and foaf, and resources are addressed by absolute URI at /{model}/oslc/re/{GUID}/. A client that already speaks OSLC integrates without a bespoke connector. evidence_url: https://www.sparxsystems.jp/help/17.0/oslc_am_top.html market_note: >- OSLC is the interoperability standard for the ALM/PLM lifecycle-tool market Enterprise Architect sells into — IBM ELM/DOORS, Jazz, PTC, Siemens. Implementing it is what lets an EA repository be linked from a requirements tool without either side writing an adapter. standards: - id: oslc-am-2.0 conforms: true evidence: >- Documented conformance to the Architecture Management 2.0 base requirements: Service Provider Resource, Absolute URIs, RDF/XML Representations, HTTP REST Services, Resource Creation Factory, Resource Query Capability, Link Type Query Capability, Partial Resource Update, Resource Removal, Selective Properties, Error Responses, and Authentication (Form and OAuth/OpenID Connect). - id: rdf-xml conforms: true evidence: All OSLC request and response payloads are RDF/XML; namespace rdf declared on every document. - id: w3c-linked-data conforms: true evidence: >- The provider states OSLC is based on W3C Linked Data and that each Enterprise Architect model resource is identifiable by a unique URL linkable from other tools. - id: dublin-core-1.1 conforms: true evidence: 'dcterms namespace (http://purl.org/dc/terms/) used for title, description, creator, identifier, created, modified.' - id: foaf conforms: true evidence: 'foaf:Person / foaf:name / foaf:nick used for the creator and the authenticated user.' - id: openid-connect conforms: true evidence: >- OpenID Connect authorization-code login supported on Pro Cloud Server; ss:accesstoken and ss:refreshtoken are returned at login. The IdP is configured per deployment, so no vendor discovery document is published. - id: oauth2 conforms: true evidence: Authorization-code exchange underpinning the OpenID Connect login path. - id: ntlm conforms: true evidence: 'sso=ntlm login mode for Windows single sign-on.' - id: rfc9457-problem-details conforms: false evidence: Errors are returned as RDF/XML per OSLC, not as application/problem+json. - id: openapi conforms: false evidence: >- No OpenAPI or Swagger document is published for the OSLC API, and no /openapi.json, /swagger.json or /api-docs endpoint exists on any Sparx host. The machine-readable discovery surface is the OSLC Service Provider Resource, served by the customer's own deployment. - id: graphql conforms: false evidence: No GraphQL endpoint documented or discoverable. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface is documented for Enterprise Architect or Pro Cloud Server. - id: json-api conforms: false evidence: No JSON representation is offered on the OSLC surface at all. - id: mcp conforms: true evidence: >- First-party MCP server (v2.8.11) exposing 38 tools plus MCP prompts over the STDIO transport. Deliberately no HTTP transport — the provider states an HTTP MCP server could violate the Enterprise Architect EULA. evidence_url: https://www.sparxsystems.jp/en/MCP/ - id: a2a conforms: false evidence: 'No agent card at /.well-known/agent-card.json or /.well-known/agent.json on any host (404).' modelling_standards: note: >- Notations Enterprise Architect implements. For a modelling tool these are the substantive interoperability claims — a model authored in a declared notation and exported as XMI is the portable artifact. standards: - id: uml-2.5 conforms: true evidence: Full support for the 14 UML 2.5 diagram types; MCP creation prompts ship UML element type rules. - id: archimate-3.2 conforms: true evidence: Native ArchiMate 3.2 modelling. - id: bpmn-2.0 conforms: true evidence: BPMN 2.0 process modelling; a BPMN 2.0 creation-rules prompt ships with the MCP server. - id: sysml conforms: true evidence: >- SysML 1.4/1.5 supported; the MCP server accepts the SysML1.5:: stereotype prefix and maps it to SysML1.4::. Sparx Systems Trechoro is the separate KerML-native SysML v2 product. - id: uaf-1.2 conforms: true evidence: UAF 1.2 support added in Enterprise Architect 17.2. confidence: medium confidence_note: Read from the search index of the provider's 17.2 release page; the page itself 403s to our crawler. - id: xmi conforms: true evidence: XMI import/export is Enterprise Architect's model interchange format. - id: togaf conforms: true evidence: TOGAF framework support listed as a supported enterprise-architecture framework. - id: naf-v4 conforms: true evidence: NATO Architecture Framework v4 named as a specialised solution. - id: bian conforms: true evidence: Banking Industry Architecture Network named as a specialised solution. - id: tmforum-oda conforms: true evidence: TM Forum Open Digital Architecture named as a specialised solution. - id: c4-model conforms: true evidence: C4 Model framework named as a specialised solution. compliance_program: published: false note: >- No trust centre, SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP attestation was found. Probed with 0-working/probe-security-programs.py on 2026-08-29: vdp=none, trust=none. Enterprise Architect and Pro Cloud Server are customer-installed software, so the compliance boundary sits with the customer's own deployment rather than with a Sparx-operated service. No Compliance or TrustCenter pointer is emitted.