[Go to site: main page, start]

Evidence, not decoration

Trust signals should be inspectable, current, and narrow

This page links each Slidesfly trust signal to public evidence and states what that evidence does not prove. A badge or directory listing is not a security audit, and a first-party status probe is not independent uptime history.

Last tested: August 3, 2026

Evidence register

Verified badges

These locally cached badge images keep the product site fast and avoid a third-party image request. Each badge links to the live public record used for verification.

OpenSSF Best Practices: passingPublic integrations repositoryApproved on SaaSHubSlidesfly directory listing
SignalCurrent evidenceBoundary
OpenSSF Best Practices
Passing · 100%
OpenSSF Best Practices records rare/slidesfly-integrations as Passing at 100% for the public project checklist. Inspect project 13940.This is voluntary project self-certification, not an audit of the private Slidesfly service or a certification by OpenSSF.
SaaSHub
Approved listing
SaaSHub approved the Slidesfly directory listing and issued its approval badge. View SaaSHub listing.Directory approval is not a security audit, certification, or uptime guarantee.

Automated repository and connector checks

Automated checks provide current, repeatable signals about the public integrations repository and connector. They do not extend to the private SaaS runtime unless explicitly stated.

SignalCurrent evidenceBoundary
OpenSSF Scorecard
6.9 / 10 · Scorecard v5.5.0
OpenSSF Scorecard published an automated 6.9 result for the public Slidesfly integrations repository. View live Scorecard.The automated score is not an OpenSSF certification, endorsement, or review of the private Slidesfly SaaS runtime.
Glama MCP connector
Verified · Healthy
Glama marks the com.slidesfly/slidesfly MCP connector as Verified and Healthy. Inspect connector status.Glama status is a platform-specific connector signal, not a security audit, certification, or uptime guarantee for the SaaS.

Ecosystem listings and interoperability records

SignalCurrent evidenceBoundary
Official MCP Registry
Active · v0.1.0
The registry has an active record for com.slidesfly/slidesfly and its hosted Streamable HTTP endpoint. Inspect registry record.The MCP Registry is in preview, and a listing is not a partnership or security review.
GitHub Marketplace
Action listed · v0.3.1
GitHub Marketplace lists the public Slidesfly publishing Action maintained by rare. View Marketplace Action.Marketplace availability does not certify the Action for every production policy.
Gemini CLI Extension Gallery
Extension listed
The Gemini CLI gallery lists rare/slidesfly-integrations with its public installation command. View Extension Gallery.Gallery inclusion verifies discoverability, not a security or compliance certification.
oEmbed provider registry
Listed provider
The public registry lists Slidesfly reader URLs, the JSON oEmbed endpoint, and discovery support. Inspect provider registry.A provider record verifies interoperability metadata; it is not an endorsement.

Verifiable public distribution

Slidesfly's SaaS source and infrastructure are private. Reusable integration code, package records, release artifacts, checksums, and a Sigstore bundle are public so builders can inspect the distribution boundary without assuming the whole service is open source.

ArtifactStatusHow to verify
Public integrations sourceMIT · v0.3.1GitHub Action, Agent Skill, MCP metadata, extension packages, and reproducible framework examples. Review public source.
Release verification assetsSHA-256 · SHA-512 · Sigstore bundleThe release includes npm tarball mirrors, SHA256SUMS, SHA512SUMS, and slidesfly-integrations-v0.3.1.sigstore.json. Inspect v0.3.1 release.
@slidesfly/clinpm · v0.1.3The npm registry publishes package integrity metadata and a registry signature. View npm package.
@slidesfly/mcpnpm · v0.1.0The npm registry publishes package integrity metadata and a registry signature. View npm package.

First-party security, disclosure, and operations

Security acknowledgments: no public acknowledgments have been published yet. After a valid report is remediated, Slidesfly may credit the reporter here with their permission.

Certifications and claims not held

  • Slidesfly does not currently claim SOC 2, ISO 27001, CSA STAR, or third-party WCAG certification.
  • Registry and marketplace listings do not mean partnership, endorsement, or universal production suitability.
  • SaaSHub approval is a directory signal, not an independent security or availability assessment.
  • OpenSSF Best Practices is voluntary self-certification for the public integrations repository, not an audit or certification of Slidesfly's private service.
  • The OpenSSF Scorecard result reports automated checks on the public integrations repository. It is not a certification or an audit of Slidesfly's private service.
  • A planned submission, pending review, or self-assessment will remain absent from the evidence table until its stated acceptance threshold is met.

Questions about this register: support@slidesfly.com. Security reports: security@slidesfly.com.