generated: '2026-08-27' method: searched source: >- openapi/_original/trustarc-guardian-openapi.json, well-known/trustarc-openid-configuration.json, well-known/trustarc-oauth-authorization-server.json, and the TrustArc help center API guides at trustarchelp.zendesk.com standards: - id: oauth2 conforms: true evidence: >- OpenAPI securitySchemes declares guardianAuth type oauth2; the published /.well-known/oauth-authorization-server document advertises authorization_code, client_credentials, refresh_token and urn:ietf:params:oauth:grant-type:token-exchange at https://login.truste.com/oauth/token. - id: oidc conforms: true evidence: >- /.well-known/openid-configuration served at https://login.truste.com with issuer, authorization_endpoint, token_endpoint, jwks_uri, userinfo_endpoint, end_session_endpoint and id_token_signing_alg_values_supported [RS256]. /oauth/userinfo is a declared operation in the Guardian OpenAPI. - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: /.well-known/oauth-authorization-server returns 200 with issuer + endpoint metadata. - id: rfc7009-token-revocation conforms: true evidence: revocation_endpoint https://login.truste.com/oauth2/revoke advertised in discovery. - id: rfc7662-token-introspection conforms: true evidence: introspection_endpoint https://login.truste.com/oauth2/introspect advertised in discovery. - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported ["S256"]. - id: rfc8705-mtls-client-auth conforms: true evidence: >- token_endpoint_auth_methods_supported includes tls_client_auth and self_signed_tls_client_auth; tls_client_certificate_bound_access_tokens is true. - id: rfc9449-dpop conforms: true evidence: dpop_signing_alg_values_supported lists RS256/384/512, PS256/384/512, ES256/384/512. - id: rfc8693-token-exchange conforms: true evidence: grant_types_supported includes urn:ietf:params:oauth:grant-type:token-exchange. - id: rfc7519-jwt conforms: true evidence: >- guardianAuth declares bearerFormat JWT; the help center troubleshooting guide tells integrators to decode the token's exp claim. - id: rfc9457-problem-details conforms: false evidence: >- No application/problem+json media type appears anywhere in the Guardian OpenAPI; the documented error envelope is a plain {error, error_description} or {timestamp, status, error, path} JSON object. - id: json-api conforms: false evidence: no application/vnd.api+json media type and no JSON:API document structure. - id: pagination conforms: true evidence: >- Spring Data page envelope used consistently — page/size/sort query parameters (41/40/29 operations respectively) and a response body carrying content, totalElements, totalPages, number, size, first, last, numberOfElements, empty. The same envelope is documented for the Hub external-integration and CPM callback APIs. - id: idempotency conforms: false evidence: >- No Idempotency-Key header or equivalent appears in the Guardian OpenAPI or in any TrustArc help center API guide. Write safety is instead achieved with PUT upsert operations keyed on a caller-supplied externalId (see conventions/). - id: prometheus-openmetrics conforms: true evidence: >- Guardian exposes Spring Boot Actuator endpoints advertising application/openmetrics-text;version=1.0.0 and application/vnd.google.protobuf;proto=io.prometheus.client.MetricFamily media types. - id: fhir-r4 conforms: false - id: fapi conforms: false - id: odata conforms: false - id: psd2 conforms: false domain_standards: - id: scim-2.0 name: SCIM 2.0 (System for Cross-domain Identity Management, RFC 7643 / RFC 7644) conforms: true market: enterprise identity and user lifecycle provisioning evidence: >- The Guardian OpenAPI declares the full SCIM 2.0 resource surface under /external/api/v2/scim/ — Users, Users/{id}, Groups, Groups/{id} (GET/POST/PUT/ PATCH/DELETE), plus the three SCIM discovery resources ServiceProviderConfig, Schemas, Schemas/{resource}, ResourceTypes and ResourceTypes/{resource}. The PATCH request body schema is the SCIM PatchOp message identified by the URN urn:ietf:params:scim:api:messages:2.0:PatchOp. Resource schemas ScimUserResource and ScimGroupResource carry the SCIM shape (schemas, id, externalId, meta with resourceType/created/lastModified/location/version, userName, name, emails, active, groups, entitlements, roles, x509Certificates). spec_location: openapi/_original/trustarc-guardian-openapi.json#/paths/~1external~1api~1v2~1scim~1Users docs: - https://trustarchelp.zendesk.com/hc/en-us/articles/45629008459155-User - https://trustarchelp.zendesk.com/hc/en-us/articles/45629108192531-Group - https://trustarchelp.zendesk.com/hc/en-us/articles/45628936236307-ServiceConfig - https://trustarchelp.zendesk.com/hc/en-us/articles/45628918936723-Schema note: >- A buyer who already speaks SCIM can provision TrustArc users and groups from Okta, Entra ID or any SCIM-capable IdP with no bespoke connector. This is a contract-level declaration, not a marketing claim — the URN and the discovery resources are in the spec itself. - id: gpc-global-privacy-control name: Global Privacy Control conforms: true market: consumer privacy signals evidence: >- TrustArc publishes a GPC recognition script and documents GPC handling in Cookie Consent Manager and Individual Rights Manager, including an Enabling GPC Guide with appendices. docs: https://trustarchelp.zendesk.com/hc/en-us/sections/19171544108947-Global-Privacy-Control-Overview note: >- A published, documented implementation of a market standard. Recorded separately from SCIM because GPC is a browser/consumer signal specification rather than an API contract shape. - id: google-consent-mode-v2 name: Google Consent Mode v2 conforms: true market: adtech consent signalling evidence: >- TrustArc publishes Google Tag Manager templates for Consent Mode v2 in its own GitHub org (trustarc-gcm-template-v2, trustarc_gcm_variable_template, trustarc-cmp-gcm-template) and documents the ad_storage / analytics_storage / ad_user_data / ad_personalization signal mapping. docs: https://trustarchelp.zendesk.com/hc/en-us/articles/47015910833555-Google-Consent-Mode-TrustArc compliance_program: published: true url: https://trust.trustarc.com/en-US/ certifications: - SOC 2 Type II - ISO 27001 - GDPR evidence: >- TrustArc's own Trust Center at trust.trustarc.com (built on its own Trust Center product) publishes a Security page naming an annual AICPA SOC 2 Type II assessment by a qualified external third-party auditor, TLS 1.2 in transit / AES-256 at rest, and downloadable Technical and Organizational Measures and public SOC 2 report table of contents.