generated: '2026-08-29' method: searched source: >- Public SynergySuite surfaces probed 2026-08-29; no machine-readable contract exists, so every standard below is asserted from published prose or an observed operational surface, never from a spec. contract_available: false contract_note: >- No OpenAPI, Swagger, GraphQL SDL, AsyncAPI, WSDL or .proto is published on any SynergySuite host. STEP 0b contract discovery was run against every host resolvable from DNS and Certificate Transparency and every candidate path missed. Nothing here is derived from a contract, because there is none. standards: - id: gdpr conforms: true evidence: >- SynergySuite publishes a Data Protection Policy and Commitment to GDPR describing lawful basis, data retention for the length of the agreement, and export or deletion on request with removal three months after termination. source: https://www.synergysuite.com/gdpr-data-protection/ - id: edi conforms: unknown evidence: >- "EDI" is a named, separately monitored component on the SynergySuite status page, so an electronic data interchange surface demonstrably runs in production for supplier and vendor exchange. source: https://status.synergysuite.com/api/v2/summary.json note: >- DOMAIN-STANDARD CANDIDATE, NOT CONFIRMED. Foodservice supplier exchange normally runs on ANSI X12 (850 purchase order, 810 invoice, 856 ASN) or UN/EDIFACT (ORDERS, INVOIC, DESADV), but SynergySuite publishes no message set, version, or partner implementation guide, and there is no contract to read a signature from. Recorded as unknown deliberately: the surface is real, the standard it speaks is not disclosed. - id: oauth2 conforms: unknown evidence: No public securityScheme, authorization server metadata or auth documentation. - id: oidc conforms: false evidence: >- /.well-known/openid-configuration returns 404 on every SynergySuite-operated host. - id: rfc9457-problem-details conforms: unknown evidence: No public error reference or contract to inspect. - id: rfc9116-security-txt conforms: false evidence: >- No security.txt on any SynergySuite-controlled host. The only 200 observed is Atlassian's own document on the vendor-operated status subdomain. - id: rfc8594-sunset-header conforms: unknown evidence: No reachable unauthenticated endpoint on which to observe headers. compliance_program: published: true page: https://www.synergysuite.com/gdpr-data-protection/ certifications: [] note: >- A GDPR/data-protection commitment is published. No named third-party certification (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP) was found on any public page. SynergySuite does self-host a Google VSAQ (Vendor Security Assessment Questionnaire) instance at https://vsaq.synergysuite.com/ (HTTP 200), which is a vendor security-review surface rather than a certification attestation. x-evidence: - url: https://www.synergysuite.com/gdpr-data-protection/ status: 403 note: page exists and is search-indexed; host bot-challenges automated clients - url: https://status.synergysuite.com/api/v2/summary.json status: 200 - url: https://vsaq.synergysuite.com/ status: 200