Verified badges
These locally cached badge images keep the product site fast and avoid a third-party image request. Each badge links to the live public record used for verification.
Slidesfly directory listing| Signal | Current evidence | Boundary |
|---|---|---|
| OpenSSF Best Practices Passing · 100% | OpenSSF Best Practices records rare/slidesfly-integrations as Passing at 100% for the public project checklist. Inspect project 13940. | This is voluntary project self-certification, not an audit of the private Slidesfly service or a certification by OpenSSF. |
| SaaSHub Approved listing | SaaSHub approved the Slidesfly directory listing and issued its approval badge. View SaaSHub listing. | Directory approval is not a security audit, certification, or uptime guarantee. |
Automated repository and connector checks
Automated checks provide current, repeatable signals about the public integrations repository and connector. They do not extend to the private SaaS runtime unless explicitly stated.
| Signal | Current evidence | Boundary |
|---|---|---|
| OpenSSF Scorecard 6.9 / 10 · Scorecard v5.5.0 | OpenSSF Scorecard published an automated 6.9 result for the public Slidesfly integrations repository. View live Scorecard. | The automated score is not an OpenSSF certification, endorsement, or review of the private Slidesfly SaaS runtime. |
| Glama MCP connector Verified · Healthy | Glama marks the com.slidesfly/slidesfly MCP connector as Verified and Healthy. Inspect connector status. | Glama status is a platform-specific connector signal, not a security audit, certification, or uptime guarantee for the SaaS. |
Ecosystem listings and interoperability records
| Signal | Current evidence | Boundary |
|---|---|---|
| Official MCP Registry Active · v0.1.0 | The registry has an active record for com.slidesfly/slidesfly and its hosted Streamable HTTP endpoint. Inspect registry record. | The MCP Registry is in preview, and a listing is not a partnership or security review. |
| GitHub Marketplace Action listed · v0.3.1 | GitHub Marketplace lists the public Slidesfly publishing Action maintained by rare. View Marketplace Action. | Marketplace availability does not certify the Action for every production policy. |
| Gemini CLI Extension Gallery Extension listed | The Gemini CLI gallery lists rare/slidesfly-integrations with its public installation command. View Extension Gallery. | Gallery inclusion verifies discoverability, not a security or compliance certification. |
| oEmbed provider registry Listed provider | The public registry lists Slidesfly reader URLs, the JSON oEmbed endpoint, and discovery support. Inspect provider registry. | A provider record verifies interoperability metadata; it is not an endorsement. |
Verifiable public distribution
Slidesfly's SaaS source and infrastructure are private. Reusable integration code, package records, release artifacts, checksums, and a Sigstore bundle are public so builders can inspect the distribution boundary without assuming the whole service is open source.
| Artifact | Status | How to verify |
|---|---|---|
| Public integrations source | MIT · v0.3.1 | GitHub Action, Agent Skill, MCP metadata, extension packages, and reproducible framework examples. Review public source. |
| Release verification assets | SHA-256 · SHA-512 · Sigstore bundle | The release includes npm tarball mirrors, SHA256SUMS, SHA512SUMS, and slidesfly-integrations-v0.3.1.sigstore.json. Inspect v0.3.1 release. |
| @slidesfly/cli | npm · v0.1.3 | The npm registry publishes package integrity metadata and a registry signature. View npm package. |
| @slidesfly/mcp | npm · v0.1.0 | The npm registry publishes package integrity metadata and a registry signature. View npm package. |
First-party security, disclosure, and operations
- Security architecture documents the dual-domain, iframe, storage, browser-control, and abuse-response boundaries.
- security.txt publishes the canonical security contact and disclosure policy in a machine-readable format.
- Service status performs first-party, point-in-time production probes. It does not yet provide independent historical uptime.
- Service Providers and Subprocessors, Privacy, and Termsstate the service's current operating and data-processing boundaries.
Security acknowledgments: no public acknowledgments have been published yet. After a valid report is remediated, Slidesfly may credit the reporter here with their permission.
Certifications and claims not held
- Slidesfly does not currently claim SOC 2, ISO 27001, CSA STAR, or third-party WCAG certification.
- Registry and marketplace listings do not mean partnership, endorsement, or universal production suitability.
- SaaSHub approval is a directory signal, not an independent security or availability assessment.
- OpenSSF Best Practices is voluntary self-certification for the public integrations repository, not an audit or certification of Slidesfly's private service.
- The OpenSSF Scorecard result reports automated checks on the public integrations repository. It is not a certification or an audit of Slidesfly's private service.
- A planned submission, pending review, or self-assessment will remain absent from the evidence table until its stated acceptance threshold is met.
Questions about this register: support@slidesfly.com. Security reports: security@slidesfly.com.