generated: '2026-07-21' method: searched source: openapi/topograph-openapi-original.json + well-known/ + https://trust.topograph.co/ standards: - id: oauth2 conforms: true evidence: MCP/designer surface uses OAuth 2.1 via Clerk; /.well-known/oauth-authorization-server present on api.topograph.co - id: oidc conforms: true evidence: Clerk authorization server advertises openid scope and id_token_signing_alg_values (RS256) - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: /.well-known/oauth-authorization-server returns valid RFC 8414 metadata - id: rfc9727-api-catalog conforms: true evidence: /.well-known/api-catalog returns an RFC 9727 linkset advertising service-desc/service-doc/status - id: x402-agentic-commerce conforms: true evidence: Publishes an x402 OpenAPI and an x402 discovery resource catalog (HTTP 402 pay-per-resource on Base network) - id: rfc9457-problem-details conforms: false evidence: Errors use a custom '{statusCode,error{code,message}}' envelope, not application/problem+json - id: soc2-type2 conforms: true evidence: SOC 2 Type 2 report listed on trust.topograph.co - id: iso-27001 conforms: true evidence: ISO 27001:2022 certification listed on trust.topograph.co - id: gdpr conforms: true evidence: GDPR compliance stated on site and trust center; EU business-register data platform compliance_program: published: true url: https://trust.topograph.co/ certifications: [SOC 2 Type 2, ISO 27001:2022, Penetration test, GDPR]