generated: '2026-08-29' method: searched source: https://trust.strivr.com/ + https://developer.strivr.com/docs/sdk/latest/index.html note: Strivr publishes no machine-readable contract, so nothing here is derived from a spec. Cross-cutting API standards are asserted false because there is no contract in which to declare them - this is an absence of evidence recorded honestly, not a failed conformance test. standards: - id: soc2-type2 name: SOC 2 Type 2 conforms: true evidence: https://trust.strivr.com/ - Compliance section lists SOC 2; a SOC 2 Type 2 Report is offered under Documents > Reports (access-gated) - id: ccpa name: CCPA conforms: true evidence: https://trust.strivr.com/ Compliance section - id: cpra name: CPRA conforms: true evidence: https://trust.strivr.com/ Compliance section - id: oauth2 name: OAuth 2.0 conforms: false evidence: 'api.strivr.com answers WWW-Authenticate: Bearer, implying bearer tokens, but no authorization-server metadata, grant, or scope documentation is published; /.well-known/oauth-authorization-server is itself 401' - id: oidc name: OpenID Connect conforms: true partial: true evidence: https://developer.strivr.com/docs/sdk/latest/unity/access-strivr-portal.html - Portal SSO is brokered by Auth0 with Google as identity provider; no discovery document is publicly served (/.well-known/openid-configuration is 401 on api.strivr.com, 404 on portal.strivr.com) - id: rfc9457 name: RFC 9457 Problem Details conforms: false evidence: no error contract or error reference published - id: rfc9116 name: RFC 9116 security.txt conforms: false evidence: /.well-known/security.txt missing on all four hosts (401/200-shell/404/404) - id: rfc8594 name: RFC 8594 Sunset header conforms: false evidence: no deprecation or sunset policy published - id: pagination name: Pagination convention conforms: false evidence: no public contract - id: idempotency name: Idempotency keys conforms: false evidence: no public contract; the SDK telemetry surface documents no idempotency mechanism domain_standards: - id: xapi name: xAPI (Experience API / Tin Can) conforms: false evidence: https://developer.strivr.com/docs/sdk/latest/unity/how-to-track-events.html - Strivr ships a proprietary event vocabulary (StrivrAnalytics.TrackEvent(name).Add(key,value).End()) with its own naming rules, not xAPI statements. No LRS endpoint, actor/verb/object triple, or xAPI profile is published. - id: scorm name: SCORM conforms: false evidence: no SCORM package or manifest surface published - id: cmi5 name: cmi5 conforms: false evidence: no cmi5 course structure or AU launch surface published - id: lti name: IMS LTI conforms: false evidence: no LTI launch surface published - id: caliper name: IMS Caliper Analytics conforms: false evidence: no Caliper sensor or event envelope published domain_standard_finding: 'Strivr operates in enterprise learning/workforce training, a market with real interoperability standards (xAPI, cmi5, SCORM, Caliper). Strivr conforms to none of them in its public contract: learner telemetry is captured through a proprietary Unity event API and lands only in the Strivr Portal. A buyer who already speaks xAPI and expects to route Strivr experience data into an existing LRS needs a bespoke connector. This is recorded as a finding, not a penalty.' compliance_published: true