generated: '2026-08-02' method: searched source: >- https://www.thoughtmachine.net/ (published accreditation badges), https://www.thoughtmachine.net/vault-core, https://www.thoughtmachine.net/vaultpayments, well-known/thought-machine-openid-configuration.json standards: - id: iso-27001 name: ISO/IEC 27001 Information Security Management conforms: true evidence: >- ISO 27001 accreditation badge published in the footer of every page on www.thoughtmachine.net (asset 6371f3e94a6459a7563e259a_download-2.png, verified visually); corroborated by Elastic's published customer story on Thought Machine's ISO 27001 and SOC 2 Type 1 programme. - id: soc-2 name: AICPA SOC 2 conforms: true evidence: >- AICPA SOC accreditation badge published in the footer of every page on www.thoughtmachine.net (asset 6371f3e94a64590ee03e2595_download.png, verified visually). Report type/period is not published publicly. - id: iso-22301 name: ISO 22301 Business Continuity Management conforms: true evidence: >- ISO 22301 accreditation badge published in the footer of every page on www.thoughtmachine.net (asset 652e9cce7789b432c498b798_ISO22301_Logo_1.avif). - id: iso-20022 name: ISO 20022 financial messaging conforms: true evidence: >- Vault Payments "natively represents payments as ISO 20022 messages" per https://www.thoughtmachine.net/vaultpayments. Thought Machine also publishes an open-source Go library of standard financial messages including ISO 20022 at https://github.com/thought-machine/finance-messaging. - id: oauth2 name: OAuth 2.0 conforms: true evidence: >- auth.thoughtmachine.net advertises authorization_code, refresh_token, client_credentials, password, implicit and device_code grants (probed OIDC discovery document). - id: oidc name: OpenID Connect Core / Discovery conforms: true evidence: >- OIDC discovery document served at https://auth.thoughtmachine.net/application/o/vault-portal/.well-known/openid-configuration with issuer, jwks_uri, userinfo, RS256 id_token signing, and back/front-channel logout. - id: rfc7636-pkce name: PKCE (RFC 7636) conforms: true evidence: code_challenge_methods_supported includes S256 in the probed OIDC discovery document. - id: rfc9116-security-txt name: security.txt (RFC 9116) conforms: false evidence: >- No Thought Machine-authored security.txt. The only 200 is the upstream Authentik product default on auth.thoughtmachine.net, which is expired (Expires 2024-01-01) and points at security@goauthentik.io. - id: rfc8615-well-known name: Well-Known URIs (RFC 8615) discovery surface conforms: false evidence: No /.well-known/api-catalog, ai-plugin.json or agent-card.json on any host. - id: openapi name: OpenAPI Specification conforms: false evidence: >- No public OpenAPI/Swagger document found. Probed /openapi.json, /openapi.yaml, /swagger.json, /api-docs, /docs and /redoc on www., docs., portal. and api. hosts; the documentation host redirects every path to partner SSO and api.thoughtmachine.net does not resolve. The API reference is real but gated. - id: asyncapi name: AsyncAPI Specification conforms: false evidence: >- Vault Core and Vault Payments both ship real Kafka streaming event surfaces (see asyncapi/thought-machine-streaming-events.yml) but no AsyncAPI document is published publicly. - id: a2a name: A2A Agent Card conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json miss on every host. - id: mcp name: Model Context Protocol conforms: false evidence: No hosted or remote MCP server published as of 2026-08-02. compliance_program: published: true url: https://www.thoughtmachine.net/ form: accreditation badges in the site footer certifications: - ISO/IEC 27001 - AICPA SOC 2 - ISO 22301 trust_center: null x-note: >- Thought Machine publishes certification badges but no dedicated trust centre, compliance page, or certificate/report request flow was found (trust., security., /trust, /compliance, /security all miss).