generated: '2026-09-02' method: searched source: https://cloud.trisotech.com/help/ name: Trisotech Standards Conformance and Compliance summary: >- Trisotech's product line is built on open standards — the company's founder chairs OMG BPMN/CMMN/DMN work — and its integration surface declares a long list of them in the documentation itself rather than only on marketing pages. Healthcare is the sector where its domain-standard signature is strongest: the Service Library ships a CDS Hooks discovery endpoint and SMART on FHIR launch support as first-class service endpoints. domain_standard_signature: market: Healthcare / clinical decision support declared_in_contract: true standards: - id: cds-hooks conforms: true evidence: location: >- Service Library endpoint type "CDS Hooks" — "An endpoint to describe the CDS Service definition including the prefetch information required to invoke it according to the CDS Hooks standard. This endpoint implements the standard CDS Hooks discovery endpoint." url: https://cloud.trisotech.com/help/service-library/cds-hooks.html status: 200 detail: >- The discovery endpoint returns the JSON CDS service description; the prefetch queries are declared per service input via a FHIR custom attribute (e.g. "Patient/{{context.patientId}}"). Output maps to CDS cards. Marked by the provider as incubating and gated behind the Healthcare Feature Set subscription. - id: smart-on-fhir conforms: true evidence: location: >- Service Library "Smart On FHIR Applications" — services launched with SMART context (context.patientId, context.userId, context.encounterId) and equipped with authorization to call the FHIR server. url: https://cloud.trisotech.com/help/service-library/smart-on-fhir.html status: 200 detail: Marked incubating; requires the Healthcare Feature Set subscription. - id: fhir conforms: true evidence: location: FHIR data types usable as model inputs; a dedicated FHIR connector product page. url: https://www.trisotech.com/fhir/ status: 200 - id: cql conforms: true evidence: location: Clinical Quality Language support documented in the Workflow Modeler. url: https://cloud.trisotech.com/help/workflow-modeler/cql.html status: 200 standards: - id: bpmn-2.0 body: OMG conforms: true evidence: location: Workflow Modeler; BPMN services deployed and executed via POST /deployments/bpmn/... url: https://cloud.trisotech.com/help/workflow-modeler/workflow-modeler.html - id: dmn body: OMG conforms: true evidence: location: Decision Modeler; DMN services deployed via POST /deployments/dmn/... url: https://cloud.trisotech.com/help/decision-modeler/decision-modeler.html - id: cmmn-1.1 body: OMG conforms: true evidence: location: Case Modeler; CMMN services deployed via POST /deployments/cmmn/... url: https://cloud.trisotech.com/help/case-modeler/cmmn.html - id: feel body: OMG (DMN) conforms: true evidence: location: >- FEEL is the expression language throughout, including the event emitter `filter` attribute evaluated against message data. url: https://cloud.trisotech.com/help/des/system-integration/asynchronous-events.html - id: dmn-tck body: DMN Technology Compatibility Kit conforms: true evidence: location: >- The Test Endpoint accepts external test cases "defined using the DMN TCK format" against the published XSD, and Trisotech maintains the dmn-tck-runner-trisotech runner. url: https://cloud.trisotech.com/help/service-library/test-endpoint.html - id: cloudevents version: 1.0.1 body: CNCF conforms: true evidence: location: >- "Event messages are serialized to text using the Cloud Events standard in JSON", with the attribute mapping table for id/time/source/type/data/specversion/subject. url: https://cloud.trisotech.com/help/des/system-integration/asynchronous-events.html - id: oauth2 body: IETF conforms: true evidence: location: >- "The REST API is protected using the OAuth 2 standard"; authorization code (standard and PKCE) and client credentials flows, published authorize/token endpoints, 20 grants. url: https://cloud.trisotech.com/help/admin/client-apps.html - id: oidc body: OpenID Foundation conforms: true evidence: location: OpenID Connect user provider for suite sign-in; `openid` grant for container identity. url: https://www.trisotech.com/security/ caveat: >- No /.well-known/openid-configuration is served on www.trisotech.com or cloud.trisotech.com (both 404, probed 2026-09-02) — the suite is an OIDC relying party, not an OIDC provider. - id: saml-2.0 body: OASIS conforms: true evidence: location: '"SAML2 and OpenID Connect (OIDC) authentication available"' url: https://www.trisotech.com/security/ - id: scim body: IETF conforms: true evidence: location: >- SCIM provisioning documented for Azure AD / Entra ID; SCIM defects are tracked in the dated release notes (e.g. 13.0.11, "SCIM integration did not properly handle missing attributes or groups not found"). url: https://cloud.trisotech.com/help/admin/scim-aad.html - id: openapi body: OpenAPI Initiative conforms: true evidence: location: >- Every published service generates its own OpenAPI document from the service's inputs and outputs, served in JSON or YAML for import into API gateways. url: https://cloud.trisotech.com/help/service-library/openapi-endpoint.html caveat: >- The provider's own two pages disagree on the version: the OpenAPI Endpoint page says "Open API version 3", the Endpoints overview says "Open API (v2, also often referred to as Swagger)". Both statements are quoted rather than resolved. - id: mcp body: Model Context Protocol conforms: true evidence: location: >- Service Library MCP endpoint over Streamable HTTP or SSE, per service or per environment. Marked incubating. url: https://cloud.trisotech.com/help/service-library/mcp.html - id: sparql-1.1 body: W3C conforms: true evidence: location: >- The Digital Enterprise Graph is queried with SPARQL at /ds/query, read-only, gated on the graph_r grant. url: https://cloud.trisotech.com/help/digital-modeling-suite/sparql.html - id: pmml body: DMG conforms: true evidence: location: PMML model import documented in the Decision Modeler and Workflow Modeler. url: https://cloud.trisotech.com/help/decision-modeler/pmml.html - id: opentelemetry body: CNCF conforms: true evidence: location: OpenTelemetry configuration documented for client-hosted deployments. url: https://cloud.trisotech.com/help/client-hosting/open-telemetry.html - id: mismo body: MISMO conforms: true evidence: location: >- MISMO XML parsing of Data Type Metadata Attributes is a shipped, defect-tracked capability (release notes 13.0.12); Trisotech contributed to the MISMO BPM Reference Model Toolkit. url: https://www.trisotech.com/mismo-releases-the-bpm-reference-model-toolkit-to-accelerate-standards-based-process-and-decision-modeling/ - id: rfc9457 conforms: false evidence: location: >- Errors use a proprietary {"error":[{code,systemMessage,userMessage}]} envelope with content-type application/json, not application/problem+json. url: https://cloud.trisotech.com/publicapi/user status: 500 - id: idempotency conforms: false evidence: location: >- No Idempotency-Key header, idempotent-retry guidance, or duplicate-suppression semantics appears anywhere in the System Integration or API reference documentation. url: https://cloud.trisotech.com/help/des/system-integration/rest-api-documentation.html - id: rate-limit-headers conforms: false evidence: location: >- No RateLimit-*, X-RateLimit-* or Retry-After header observed on any live response; no published limits. url: https://cloud.trisotech.com/publicapi/login status: 200 compliance: certifications: - name: SOC 2 Type II scope: Trisotech Cloud statement: >- "achieved SOC 2 Type II compliance in accordance with American Institute of Certified Public Accountants (AICPA) standards for SOC for Service Organizations also known as SSAE 18" source: https://www.trisotech.com/security/ self_attested: true report_public: false - name: ISO/IEC 27001:2013 scope: Data center provider (Google Cloud) statement: >- "Trisotech guarantees that its data center provider complies with the ISO 27001:2013 norm" source: https://www.trisotech.com/security/ note: >- Inherited from the hosting provider, not a certification of Trisotech itself. - name: SOC 3 scope: Data center provider (Google Cloud) source: https://www.trisotech.com/security/ note: Inherited from the hosting provider. data_residency: region: Quebec, Canada provider: Google Cloud statement: >- Compliant with Canadian federal privacy law and the Quebec provincial privacy act. source: https://www.trisotech.com/security/ not_claimed: - HIPAA BAA (not stated on the security page despite a healthcare product line) - FedRAMP - PCI DSS - GDPR certification (a privacy statement is published; no certification is claimed) evidence: - url: https://www.trisotech.com/security/ status: 200 - url: https://cloud.trisotech.com/help/service-library/cds-hooks.html status: 200 - url: https://cloud.trisotech.com/help/service-library/smart-on-fhir.html status: 200 - url: https://cloud.trisotech.com/help/admin/client-apps.html status: 200 - url: https://cloud.trisotech.com/help/service-library/test-endpoint.html status: 200 - url: https://cloud.trisotech.com/help/client-hosting/open-telemetry.html status: 200 - url: https://cloud.trisotech.com/help/admin/scim-aad.html status: 200