generated: '2026-09-02' method: searched source: https://verily.com/platform, https://github.com/verily-src/fhirpath-go, https://github.com/verily-src/fsh-lint, https://verily.com/security-trust name: Verily Life Sciences — standards conformance summary: >- Verily's standards posture is genuinely strong in the health-data domain and genuinely thin at the API layer. It builds on HL7 FHIR as its core data model and ships open-source FHIRPath and FHIR Shorthand tooling; it publishes no OpenAPI, no JSON:API/RFC 9457 error envelope, and no conformance statement for its own REST surface. Every `conforms: true` below is evidenced from something Verily published — a product page, an open-source repository, or a generated client in its own Terraform provider. Nothing is asserted from a marketing claim alone. entries: - id: fhir name: HL7 FHIR conforms: true evidence: - type: product-documentation url: https://verily.com/platform detail: >- "Syntax, a clinically-informed, FHIR-native data model" is named as the data layer of the Verily Pre platform, organizing all ingested information into a common ontology. - type: open-source url: https://github.com/verily-src/fhirpath-go detail: >- A Go implementation of FHIRPath, built directly on the google/fhir protobuf definitions. v1.5.0, published 2025-11-20. - type: open-source url: https://github.com/verily-src/fsh-lint detail: >- A linter for FHIR Shorthand (FSH), plus an official GitHub Action wrapper. v0.1.0, 2025-05-30. scope: data model and tooling caveat: >- Verily is FHIR-native in its data layer, but it does not expose a public FHIR REST endpoint or a published CapabilityStatement, so this is not FHIR REST API conformance. - id: fhirpath name: HL7 FHIRPath conforms: true evidence: - type: open-source url: https://github.com/verily-src/fhirpath-go detail: A first-party Go implementation of the FHIRPath specification. - id: fhir-shorthand name: HL7 FHIR Shorthand (FSH) conforms: true evidence: - type: open-source url: https://github.com/verily-src/fsh-lint detail: A first-party FSH linter checking common errors and best practices. - id: oauth2 name: OAuth 2.0 conforms: true evidence: - type: generated-client url: https://github.com/verily-src/terraform-provider-workbench detail: >- The oapi-codegen generated clients declare a `bearerAuth` HTTP bearer scheme; the CLI obtains a Google OAuth 2.0 access token (`wb auth login`, `wb auth print-access-token`). caveat: >- Authorization is delegated entirely to Google. Verily operates no authorization server of its own and serves no /.well-known/oauth-authorization-server. - id: oidc name: OpenID Connect conforms: true evidence: - type: provider-documentation url: https://github.com/verily-src/terraform-provider-workbench/blob/main/docs/index.md detail: >- The Terraform provider's `use_id_token` option sends a Google-signed OIDC ID token. Account creation is via Gmail or Google Workspace identity. caveat: Relying party only; no discovery document is served on any Verily host. - id: openapi name: OpenAPI conforms: partial evidence: - type: generated-client url: https://github.com/verily-src/terraform-provider-workbench detail: >- internal/openapi/wsm/types.go and internal/openapi/user/types.go carry the header "Code generated by github.com/deepmap/oapi-codegen version v1.16.3", proving the Workbench API IS described by OpenAPI internally. - type: probe url: https://workbench.verily.com/api/wsm/v3/api-docs status: 403 detail: >- Every spec path probed (/v3/api-docs, /openapi.json, /openapi.yml, /api-docs, /swagger.json, /swagger-ui.html, /swagger-ui/index.html) returns HTTP 403 from the edge on all three services. caveat: The description exists but is not published. A consumer cannot read it. - id: rfc9457 name: RFC 9457 Problem Details conforms: false evidence: - type: absence detail: No error schema of any kind is published; no application/problem+json is documented. - id: json-api name: JSON:API conforms: false evidence: - type: absence detail: Not claimed and not observed. - id: idempotency name: Idempotency keys conforms: false evidence: - type: absence detail: >- No idempotency header or retry-safety statement anywhere in the docs. Verily's own Terraform provider carries a client-side retry implementation instead. - id: pagination name: Documented pagination conforms: false evidence: - type: absence detail: List operations exist but no page/cursor/limit contract is published. - id: scim name: SCIM conforms: false evidence: - type: absence detail: >- Organization/group/user management exists (`wb organization user invite|list|disable|revoke`) but is a proprietary surface; no SCIM schema URN appears anywhere. - id: hipaa name: HIPAA conforms: unknown evidence: - type: provider-statement url: https://verily.com/security-trust detail: >- Verily states it "adheres to several industry-recognized frameworks, standards, and regulatory requirements" and that independent firms assess its compliance, but NAMES NONE publicly and directs prospects to info@verily.com for attestation reports, which may require an NDA. - type: provider-statement url: https://verily.com/me+lightpath/hipaa-privacy detail: A HIPAA privacy notice is published for the Verily Me + Lightpath consumer products. caveat: >- Recorded as unknown, not true. Verily publishes a HIPAA notice for a consumer product; it does not publish a HIPAA attestation covering Workbench. - id: soc2 name: SOC 2 conforms: unknown evidence: - type: provider-statement url: https://verily.com/security-trust detail: >- No certification is named. Because no certification is published by name, no `Compliance` pointer is emitted in apis.yml. domain_standard: claimed: HL7 FHIR declared_in_contract: false note: >- This is the reward-only `domain_standard_conformance` signal, and Verily half-earns it. FHIR is unambiguously its domain standard and it invests in the ecosystem with first-party open source. But the check reads the CONTRACT, and there is no readable contract here to carry a FHIR resource shape, a CapabilityStatement or a FHIR base URL. Recorded honestly rather than credited. regulatory_regime: healthcare