generated: '2026-08-05' method: searched source: https://trust.truveta.com/ description: >- Standards and compliance posture Truveta actually publishes. Truveta ships no OpenAPI, so nothing here is derived from a spec — the identity entries come from its anonymous OIDC discovery document and the certification entries from its SafeBase-hosted trust center, where each report is named and available on request. standards: - id: openid-connect-discovery-1.0 conforms: true evidence: >- login.truveta.com serves a valid RFC-shaped OIDC discovery document at /.well-known/openid-configuration (HTTP 200, application/json). source: well-known/truveta-openid-configuration.json - id: oauth2 conforms: true evidence: >- Discovery advertises authorization_code, client_credentials, refresh_token, device_code, token-exchange and jwt-bearer grants. source: well-known/truveta-openid-configuration.json - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: >- /.well-known/oauth-authorization-server returns 200 with the authorization server metadata document. source: https://login.truveta.com/.well-known/oauth-authorization-server - id: rfc7636-pkce conforms: true evidence: 'code_challenge_methods_supported includes S256.' - id: rfc8628-device-authorization-grant conforms: true evidence: 'device_authorization_endpoint present; device_code grant advertised.' - id: rfc8693-token-exchange conforms: true evidence: 'grant_types_supported includes urn:ietf:params:oauth:grant-type:token-exchange.' - id: rfc9449-dpop conforms: true evidence: "dpop_signing_alg_values_supported: [ES256]." - id: oidc-backchannel-logout-1.0 conforms: true evidence: 'backchannel_logout_supported and backchannel_logout_session_supported are true.' - id: hitrust-r2 conforms: true evidence: 'HITRUST R2 Certification report listed on the Truveta trust center.' source: https://trust.truveta.com/ - id: iso-iec-27001 conforms: true evidence: 'ISO/IEC 27001 certificate listed on the Truveta trust center.' source: https://trust.truveta.com/ - id: iso-iec-27018 conforms: true evidence: 'ISO/IEC 27018:2019 certification listed on the Truveta trust center.' source: https://trust.truveta.com/ - id: iso-iec-27701 conforms: true evidence: 'ISO/IEC 27701 certification listed on the Truveta trust center.' source: https://trust.truveta.com/ - id: soc2-type-2 conforms: true evidence: >- SOC 2 Type 2 attestation report covering 2025-02-01 to 2026-01-31, listed on the Truveta trust center. source: https://trust.truveta.com/ - id: hipaa-de-identification conforms: true evidence: >- Truveta states throughout its public site and llms.txt that it delivers de-identified EHR data in a HIPAA-compliant environment. Self-asserted on the marketing surface; no certificate is published for this item. confidence: medium source: https://www.truveta.com/ - id: openapi conforms: false evidence: 'No OpenAPI or Swagger document found on any Truveta-controlled host.' - id: asyncapi conforms: false evidence: 'No event, streaming or webhook surface is published.' - id: rfc9457-problem-details conforms: false evidence: 'No public API, therefore no observable error envelope.' - id: rfc9116-security-txt conforms: false evidence: '/.well-known/security.txt returns 404 on www.truveta.com.' - id: rfc9727-api-catalog conforms: false evidence: '/.well-known/api-catalog is not served (301 to homepage on www, SPA shell on api host).' - id: a2a conforms: false evidence: >- No agent card. The HTTP 200 at api.truveta.com/.well-known/agent-card.json is the Studio SPA HTML shell, confirmed against a control path. x-evidence: fetched: '2026-08-05' urls: - {url: 'https://trust.truveta.com/', status: 200} - {url: 'https://login.truveta.com/.well-known/openid-configuration', status: 200}