generated: '2026-07-21' method: searched source: https://docs.strise.ai/technology/compliance-in-strise/, https://docs.strise.ai/mcp/, https://docs.strise.ai/technology/single-sign-on/ standards: - id: graphql conforms: true evidence: Connect API is a GraphQL API (graphql.strise.ai/connect) - id: oauth2 conforms: true evidence: MCP server is an OAuth 2.0 protected resource with authorization_code flow - id: oauth2-dcr-rfc7591 conforms: true evidence: MCP publishes a registration_endpoint for dynamic client registration - id: oauth2-pkce-rfc7636 conforms: true evidence: code_challenge_methods_supported = [S256] - id: oauth-authorization-server-metadata-rfc8414 conforms: true evidence: /.well-known/oauth-authorization-server returns 200 - id: oauth-protected-resource-metadata-rfc9728 conforms: true evidence: /.well-known/oauth-protected-resource returns 200 - id: openid-connect conforms: true evidence: SSO and MCP auth via Auth0 OIDC (Microsoft/Google); scopes include openid/profile/email - id: soc2-type-ii conforms: true evidence: SOC 2 Type II certified (compliance-in-strise) - id: iso-27001 conforms: true evidence: ISO 27001 certified (compliance-in-strise) - id: gdpr conforms: true evidence: GDPR compliant; EU data residency (Google Cloud, Belgium) - id: rfc9457-problem-details conforms: false evidence: GraphQL API uses GraphQL errors[] envelope, not application/problem+json - id: rest conforms: false evidence: primary API is GraphQL, not REST