generated: '2026-08-05' method: searched source: https://www.tredence.com/certifications note: >- Tredence publishes no OpenAPI, AsyncAPI, GraphQL SDL or any other machine-readable contract, so no protocol-level conformance can be derived. What it does publish is a named certification posture on its corporate certifications page. Every entry below is either a published claim on that page or an honest false where the standard was probed for and not found. standards: - id: iso-27001 conforms: true evidence: 'ISO 27001:2022 (and prior ISO 27001:2013) named on https://www.tredence.com/certifications' - id: iso-27701 conforms: true evidence: 'ISO 27701:2019 Privacy Information Management System named on https://www.tredence.com/certifications' - id: soc2-type2 conforms: true evidence: 'SOC 2 Type-2 across all five AICPA Trust Services Principles named on https://www.tredence.com/certifications' - id: gdpr conforms: true evidence: GDPR named as an addressed regulatory framework on the certifications page - id: ccpa conforms: true evidence: CCPA named as an addressed regulatory framework on the certifications page - id: oauth2 conforms: false evidence: no OAuth surface published; /.well-known/oauth-authorization-server returned 404 - id: oidc conforms: false evidence: /.well-known/openid-configuration returned 404 on www.tredence.com - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returned 404 on www.tredence.com - id: rfc9457-problem-details conforms: false evidence: no API or specification published to assert an error format against - id: openapi conforms: false evidence: no OpenAPI found on any Tredence host; /openapi.json returned 404 x-evidence: fetched: '2026-08-05' probes: - url: https://www.tredence.com/certifications http_status: 200 - url: https://www.tredence.com/.well-known/openid-configuration http_status: 404 - url: https://www.tredence.com/openapi.json http_status: 404