generated: '2026-08-13' method: searched source: >- openapi/_original/synthflow-openapi.json, https://docs.synthflow.ai/security, https://mcp.synthflow.ai/.well-known/oauth-protected-resource, https://docs.synthflow.ai/.well-known/api-catalog description: >- Standards conformance for the Synthflow estate. The REST API is a plain bearer-key JSON API with no cross-cutting standards adopted; the agent surface is where Synthflow actually conforms to modern specifications — MCP, OAuth 2.0 protected-resource metadata, RFC 9727 api-catalog and the Agent Skills specification. standards: - id: openapi-3.1 conforms: true evidence: 'openapi/_original/synthflow-openapi.json declares openapi 3.1.0 with 63 paths / 100 operations and 547 component schemas, served live at https://docs.synthflow.ai/openapi.json' - id: oauth2 conforms: partial evidence: >- The MCP surface is OAuth 2.0 protected (401 + WWW-Authenticate: Bearer, delegated to WorkOS AuthKit with authorization_code + refresh_token + device_code grants and S256 PKCE). The REST Platform API is NOT OAuth — it is a static bearer API key. - id: rfc9728-oauth-protected-resource-metadata conforms: true evidence: 'https://mcp.synthflow.ai/.well-known/oauth-protected-resource returns 200 with resource + authorization_servers + bearer_methods_supported' - id: rfc8414-oauth-authorization-server-metadata conforms: delegated evidence: 'Served by the delegated IdP at https://kind-prelude-27.authkit.app/.well-known/oauth-authorization-server, not by a Synthflow host.' - id: rfc7591-dynamic-client-registration conforms: true evidence: 'The delegated authorization server advertises registration_endpoint, which is what lets an MCP client register itself without a manual app setup.' - id: pkce-rfc7636 conforms: true evidence: 'code_challenge_methods_supported: [S256]' - id: oidc conforms: partial evidence: >- The delegated AuthKit issuer advertises openid/profile/email/offline_access scopes, but no /.well-known/openid-configuration is served on any synthflow.ai host. - id: mcp conforms: true evidence: >- Hosted remote MCP server at https://mcp.synthflow.ai/mcp in three regions plus an unauthenticated docs MCP server at https://docs.synthflow.ai/_mcp/server, observed answering initialize with protocolVersion 2025-06-18. - id: agent-skills conforms: true evidence: >- https://github.com/SynthFlowAI/synthflow-skills declares conformance to the Agent Skills specification (agentskills.io/specification) and ships a Claude Code plugin marketplace manifest. Saved verbatim under skills/. - id: rfc9727-api-catalog conforms: true evidence: 'https://docs.synthflow.ai/.well-known/api-catalog returns a 200 linkset with service-desc and service-doc for the Platform API.' - id: llmstxt conforms: true evidence: 'https://docs.synthflow.ai/llms.txt returns 200 (36.9 KB index); llms-full.txt is advertised on every page header.' - id: rfc9457-problem-details conforms: false evidence: 'No application/problem+json anywhere; application/json is the only media type across 207 declared response bodies. See errors/synthflow-problem-types.yml.' - id: rfc9116-security-txt conforms: false evidence: '/.well-known/security.txt returns 404 on synthflow.ai, api.synthflow.ai, api.us/eu.synthflow.ai, docs.synthflow.ai and mcp.synthflow.ai.' - id: rfc8594-sunset-header conforms: false evidence: 'No Sunset or Deprecation headers documented; no operation marked deprecated in the spec. Deprecations are announced in the changelog only.' - id: a2a conforms: false evidence: '/.well-known/agent-card.json and the legacy /.well-known/agent.json return 404 on every host probed.' - id: asyncapi conforms: false evidence: 'No AsyncAPI document published; /asyncapi.yaml and /asyncapi.json 404. A documented webhook surface exists — see asyncapi/synthflow-webhooks.yml.' - id: json-api conforms: false - id: odata conforms: false - id: scim conforms: false - id: fhir conforms: false - id: hmac-webhook-signing conforms: true evidence: 'HMAC-SHA256 over call_id, base64-encoded, delivered in HTTP_SYNTHFLOW_SIGNATURE on both webhook types.' - id: saml-sso conforms: true evidence: 'Enterprise SSO via WorkOS; Okta, Entra ID, Google SAML and Auth0 named as supported providers.' - id: totp-2fa conforms: true evidence: 'TOTP 2FA with backup codes, workspace-level enforcement documented.' - id: e164 conforms: true evidence: 'Phone numbers are specified in E.164 format for calls and transfers.' - id: sip conforms: true evidence: >- SIP trunking, direct SIP dialing, SIP diversion headers, X-EI and custom SIP X-headers are documented, with published ACL/firewall ranges per region. compliance_program: published: true trust_center: https://security.synthflow.ai/ docs: https://docs.synthflow.ai/security certifications: ['ISO 27001:2022', 'SOC 2', 'GDPR', 'HIPAA', 'PCI DSS v4.0.1'] baa_available: true see: security/synthflow-trust-center.yml vulnerability_disclosure: published: false evidence: - {url: 'https://synthflow.ai/.well-known/security.txt', status: 404} - {url: 'https://synthflow.ai/security', status: 404} - {url: 'https://synthflow.ai/responsible-disclosure', status: 404} - {url: 'https://docs.synthflow.ai/responsible-disclosure', status: 404} - {url: 'https://hackerone.com/synthflow', status: 404} - {url: 'https://bugcrowd.com/engagements/synthflow.json', status: 404} note: >- https://bugcrowd.com/synthflow answers 200 but redirects to the /h/ hacker-portal SPA, which returns a byte-identical 6110-byte shell for a deliberately nonsense slug. It is a soft-404, not a program. Bugcrowd's own engagements API returns 404 for synthflow. No VulnerabilityDisclosure or Security artifact/pointer was emitted — a documented absence, not a miss. x-evidence: fetched: '2026-08-13'