generated: '2026-08-19' method: searched source: >- https://www.splunk.com/en_us/about-splunk/splunk-data-security-and-privacy/compliance-at-splunk.html, https://www.splunk.com/.well-known/security.txt, https://dev.splunk.com/observability/docs/, plus derivation from openapi/ (48 documents) standards: - id: openapi-3 conforms: true evidence: >- Splunk builds its API reference from 48 OpenAPI documents (info.version 1.0.0 through 5.0.1) and embeds the parsed spec object in its own reference pages. It does not publish the source files for download — see the contract note at the bottom of this file. - id: opentelemetry conforms: true evidence: >- OpenTelemetry-native ingest. Splunk ships its own OpenTelemetry distributions (splunk-otel-collector, -java, -python, -js, -go, -dotnet, -android, -ios) and its GDI specification governs cross-repository compatibility. - id: rfc9116-security-txt conforms: true evidence: PGP-signed security.txt served at https://www.splunk.com/.well-known/security.txt with Contact, Policy, Encryption, Expires and Canonical fields. - id: rfc9457-problem-details conforms: false evidence: >- No operation returns application/problem+json. Five distinct vendor JSON envelopes plus a bare-string form are in use across the 48 documents. - id: oauth2 conforms: false evidence: >- No securityScheme of type oauth2 in any spec. Authentication is a single X-SF-TOKEN API-key header. /.well-known/oauth-authorization-server returns 404 on every API host. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on every host probed. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header is documented, and no operation is marked deprecated. - id: idempotency-key conforms: false evidence: No Idempotency-Key parameter in any of the 242 operations; no idempotency contract in the docs. - id: json-api conforms: false - id: odata conforms: false - id: scim2 conforms: false evidence: >- User and team management is a proprietary surface (/v2/organization/member, /v2/team) rather than SCIM 2.0. - id: mcp conforms: true evidence: >- Hosted MCP server using the streamable HTTP transport defined in the MCP specification; probed live at https://region-pdx10.api.scs.splunk.com/system/mcp-gateway/v1/ (HTTP 401 unauthenticated). See mcp/splunk-observability-mcp.yml. - id: a2a conforms: false evidence: No agent card at /.well-known/agent-card.json or /.well-known/agent.json on any host. - id: asyncapi conforms: false evidence: >- Splunk publishes no AsyncAPI document. The SignalFlow WebSocket/SSE surface is fully documented in prose; asyncapi/splunk-observability-signalflow-asyncapi.yml is an API Evangelist derivation of it, not a Splunk artifact. - id: webhook-hmac-signing conforms: true evidence: >- Outbound webhook notifications carry X-SFX-Signature, a base64-encoded HMAC-SHA256 of the payload keyed on the integration's sharedSecret. compliance_program: published: true url: https://www.splunk.com/en_us/about-splunk/splunk-data-security-and-privacy/compliance-at-splunk.html certifications: - SOC 1 - SOC 2 - ISO 27001 - ISO 27017 - ISO 27018 - ISO 9001 - PCI DSS - HIPAA - CSA STAR Level 1 - CSA STAR Level 2 - FedRAMP Moderate - FedRAMP High - DoD CC SRG IL5 - GovRAMP - TX-RAMP - IRAP - ISMAP - TISAX - FIPS 140-2 - Common Criteria - UK Cyber Essentials scope_caveat: >- READ THIS BEFORE CITING THE LIST. Splunk's compliance page is a Splunk-wide page and most of the named authorizations (FedRAMP Moderate/High, DoD CC SRG IL5, SOC 1, PCI DSS, HIPAA, CSA STAR, GovRAMP, TX-RAMP, IRAP, ISMAP) are stated against SPLUNK CLOUD PLATFORM, not against Splunk Observability Cloud. The ISO family (27001/27017/27018/9001) is the set stated to span observability products. Splunk Observability Cloud is governed by its own security addendum. Treat the list as Splunk-corporate evidence and verify product scope for any regulated deployment. contract_note: >- Splunk publishes no downloadable OpenAPI file, no /openapi.json, no Swagger UI export and no spec repository for Splunk Observability Cloud. The 48 documents in openapi/ were reconstructed by API Evangelist from the parsed OpenAPI object Splunk embeds in its own reference pages. The contract exists and is complete; it is simply not offered as a file.