generated: '2026-09-05' method: probed source: openapi/ + live responses from https://www.3barbiologics.com/wp-json/ description: >- Cross-cutting standards this surface does and does not conform to, derived from the nine OpenAPI documents in openapi/ and from responses observed live on 2026-09-05. 3Bar Biologics makes no compliance or conformance claims of its own — it publishes no trust center, no certifications page, no security policy and no API documentation — so nothing recorded here is a provider assertion. standards: - id: json-schema conforms: true evidence: >- Every route serves a JSON Schema for its resource via HTTP OPTIONS (post 27 properties, page 25, attachment 33, category 9, tag 8, user 20, search-result 5, type 16, taxonomy 11, status 8). These published schemas are what every OpenAPI in this repository was derived from. url: https://www.3barbiologics.com/wp-json/wp/v2/posts - id: rfc8288-web-linking conforms: true evidence: 'Link header with rel="next" observed on GET /wp/v2/posts?per_page=1 (X-WP-Total 51).' url: https://www.3barbiologics.com/wp-json/wp/v2/posts?per_page=1 - id: oembed-1.0 conforms: true evidence: >- Provider endpoint GET /oembed/1.0/embed returned 200 with a well-formed oEmbed 1.0 rich-type response for https://www.3barbiologics.com/why-3bar/. url: https://www.3barbiologics.com/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fwww.3barbiologics.com%2Fwhy-3bar%2F - id: schema-org-json-ld conforms: true evidence: >- GET /yoast/v1/get_head returns a rendered head containing a schema.org JSON-LD @graph for any site URL. Yoast SEO v28.1 at capture. url: https://www.3barbiologics.com/wp-json/yoast/v1/get_head?url=https%3A%2F%2Fwww.3barbiologics.com%2Fwhy-3bar%2F - id: rfc7617-basic-auth conforms: true evidence: >- WordPress application passwords, declared in the API root document, are Basic over TLS. Applies only to the non-public write surface; there is no public issuance path. url: https://www.3barbiologics.com/wp-json/ - id: cors conforms: true evidence: >- Access-Control-Expose-Headers (X-WP-Total, X-WP-TotalPages, Link) and Access-Control-Allow-Headers present on responses, so the pagination counters are readable from a browser. url: https://www.3barbiologics.com/wp-json/wp/v2/posts?per_page=1 - id: pagination conforms: true evidence: >- page/per_page/offset parameters plus X-WP-Total and X-WP-TotalPages response headers. Note the counter is unreliable on the media collection — see errors/3bar-biologics-problem-types.yml. url: https://www.3barbiologics.com/wp-json/wp/v2/posts?per_page=1 - id: rfc9457-problem-details conforms: false evidence: >- Errors use the WordPress envelope {code, message, data:{status}} served as application/json, not application/problem+json. The media 500 does not use any JSON envelope at all — it returns HTML. - id: oauth2 conforms: false evidence: >- No oauth2 securityScheme in any spec, and /.well-known/oauth-authorization-server returned 404 on every host probed. - id: oidc conforms: false evidence: /.well-known/openid-configuration returned 404 on www.3barbiologics.com. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returned 404 on www.3barbiologics.com. - id: rfc8594-sunset conforms: false evidence: No Sunset or Deprecation header observed on any response; no deprecation policy published. - id: idempotency-keys conforms: false evidence: >- No Idempotency-Key header or parameter is accepted or documented. Recorded as non-conforming rather than inapplicable for the standards register, though the public surface has no reachable write operations for it to apply to. - id: rfc9728-oauth-protected-resource conforms: false evidence: /.well-known/oauth-protected-resource returned 404. - id: a2a-agent-card conforms: false evidence: >- /.well-known/agent-card.json and the pre-0.3 /.well-known/agent.json both returned 404 on www.3barbiologics.com. No agent card is published. - id: llms-txt conforms: false evidence: /llms.txt returned 404 on www.3barbiologics.com. domain_standards: applicable: false detail: >- Agricultural biologicals and contract biomanufacturing do have domain data standards — AgGateway ADAPT for field-operations data, ISOBUS/ISO 11783 for machine data, and GS1 identifiers for product and logistics units are the ones a company in this market would plausibly speak. None of them appears anywhere in this contract, and none would be expected to: the surface captured here is a website content API, not a product, supply-chain or field-data interface. This is recorded as inapplicable rather than as a failure. The domain_standard_conformance check is reward-only, so no conformance is invented to fill the slot. candidates_checked: - {standard: AgGateway ADAPT, found: false} - {standard: ISO 11783 / ISOBUS, found: false} - {standard: GS1 GTIN / GLN, found: false} - {standard: OGC API / WMS / WFS, found: false, note: 'No geospatial surface; no evidence pointed at one, so no blind probing was performed.'} compliance_program: published: false certifications: [] detail: >- No SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP or CSA STAR claim appears anywhere on www.3barbiologics.com, no trust center is published, and trust.3barbiologics.com returns no A record (NOERROR/NODATA), so there is no trust host to reach. The company's public quality story is agricultural biomanufacturing capability rather than information-security certification, and no such claim is made. No Compliance pointer is emitted in apis.yml because there is no compliance program to point at.