Evidence, not decoration

Trust signals should be inspectable, current, and narrow

This page links each Slidesfly trust signal to public evidence and states what that evidence does not prove. A directory listing is not a security audit, and a first-party status probe is not independent uptime history.

Last tested: August 2, 2026

Evidence register

External listings and interoperability records

SignalCurrent evidenceBoundary
SaaSHub
Approved listing
SaaSHub approved the Slidesfly directory listing and issued its approval badge. View SaaSHub listing.Directory approval is not a security audit, certification, or uptime guarantee.
oEmbed provider registry
Listed provider
The public registry lists Slidesfly reader URLs, the JSON oEmbed endpoint, and discovery support. Inspect provider registry.A provider record verifies interoperability metadata; it is not an endorsement.
Official MCP Registry
Active · v0.1.0
The registry has an active record for com.slidesfly/slidesfly and its hosted Streamable HTTP endpoint. Inspect registry record.The MCP Registry is in preview, and a listing is not a partnership or security review.
GitHub Marketplace
Action listed · v0.2.0
GitHub Marketplace lists the public Slidesfly publishing Action maintained by rare. View Marketplace Action.Marketplace availability does not certify the Action for every production policy.
Gemini CLI Extension Gallery
Extension listed
The Gemini CLI gallery lists rare/slidesfly-integrations with its public installation command. View Extension Gallery.Gallery inclusion verifies discoverability, not a security or compliance certification.
OpenSSF Scorecard
6.2 / 10 · Scorecard v5.5.0
OpenSSF Scorecard published an automated 6.2 result for the public Slidesfly integrations repository, whose README displays the live badge. View live Scorecard.The automated score is not an OpenSSF certification, endorsement, or review of the private Slidesfly SaaS runtime.

Verifiable public distribution

Slidesfly's SaaS source and infrastructure are private. Reusable integration code, package records, release artifacts, and checksums are public so builders can inspect the distribution boundary without assuming the whole service is open source.

ArtifactStatusHow to verify
Public integrations sourceMIT · v0.3.1GitHub Action, Agent Skill, MCP metadata, extension packages, and reproducible framework examples. Review public source.
Release verification assetsSHA-256 and SHA-512 receiptsRelease assets include npm tarball mirrors plus SHA256SUMS and SHA512SUMS verification files. Inspect v0.3.1 release.
@slidesfly/clinpm · v0.1.3The npm registry publishes package integrity metadata and a registry signature. View npm package.
@slidesfly/mcpnpm · v0.1.0The npm registry publishes package integrity metadata and a registry signature. View npm package.

Security, disclosure, and operations

Security acknowledgments: no public acknowledgments have been published yet. After a valid report is remediated, Slidesfly may credit the reporter here with their permission.

Claims we do not make

  • Slidesfly does not currently claim SOC 2, ISO 27001, CSA STAR, or third-party WCAG certification.
  • Registry and marketplace listings do not mean partnership, endorsement, or universal production suitability.
  • SaaSHub approval is a directory signal, not an independent security or availability assessment.
  • The OpenSSF Scorecard badge reports automated checks on the public integrations repository. It is not a certification or an audit of Slidesfly's private service.
  • A planned submission, pending review, or self-assessment will remain absent from the evidence table until its stated acceptance threshold is met.

Questions about this register: support@slidesfly.com. Security reports: security@slidesfly.com.