generated: '2026-09-06' method: probed source: live probes of https://www.acernatec.com (2026-09-06) scope: >- aceRNA Technologies publishes no OpenAPI, AsyncAPI, GraphQL SDL or developer documentation, so there is no contract to assert API-design standards against. The entries below are limited to what was directly observed on the live host. standards: - id: mcp name: Model Context Protocol conforms: true evidence: >- POST https://www.acernatec.com/_api/mcp with method tools/list returned HTTP 200 and a valid JSON-RPC 2.0 result containing 9 tools, each with a JSON Schema inputSchema. The server issued an mcp-session-id response header. - id: jsonrpc-2.0 name: JSON-RPC 2.0 conforms: true evidence: The MCP endpoint accepts and answers JSON-RPC 2.0 envelopes (id and jsonrpc echoed on the result). - id: llmstxt name: llms.txt conforms: true evidence: >- https://www.acernatec.com/llms.txt returns HTTP 200 with a conforming llms.txt document (H1, blockquote summary, sectioned link lists). Auto-generated by the Wix platform, in Japanese. - id: sitemaps-xml name: sitemaps.org XML sitemap conforms: true evidence: >- https://www.acernatec.com/sitemap.xml returns HTTP 200 with a sitemapindex pointing at pages-sitemap.xml, which enumerates 12 crawlable pages. - id: openapi name: OpenAPI conforms: false evidence: >- /openapi.json, /openapi.yaml and /swagger.json return HTTP 400 and /v1/openapi.json, /api-docs, /docs, /redoc return HTTP 404 on both www.acernatec.com and acernatec.com. No api./developer./docs. subdomain is published or linked. - id: graphql name: GraphQL conforms: false evidence: /graphql returns HTTP 404 on www.acernatec.com. - id: a2a name: A2A Agent Card conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json both return HTTP 400 (the Wix catch-all). - id: oauth2 name: OAuth 2.0 conforms: false evidence: >- No authorization server metadata is published; the MCP endpoint uses an anonymous GenerateVisitorToken session instead of OAuth. - id: rfc9116-security-txt name: RFC 9116 security.txt conforms: false evidence: /.well-known/security.txt and /security.txt both return HTTP 400. - id: soap-wsdl name: SOAP / WSDL conforms: false evidence: >- /soap and /services return HTTP 404. https://www.acernatec.com/?wsdl and /?singleWsdl return HTTP 200 text/html — that is the Wix homepage ignoring an unknown query string, not a WSDL, and is recorded here so the 200 is not later mistaken for a SOAP contract. - id: rfc9457-problem-details name: RFC 9457 Problem Details conforms: false evidence: No API error contract is published. domain_standards: probed: true found: [] note: >- aceRNA is a pre-clinical RNA therapeutics developer, not a health-IT or data-exchange vendor. The life-sciences domain standards this pipeline looks for in a contract (HL7v2, FHIR, CDISC SDTM/ODM, PhUSE) have no surface here to declare them — there is no contract at all, so this is recorded as "no domain standard signature found", not as a failure. x-notes: - >- No Compliance pointer is wired. aceRNA publishes no certifications, trust centre or compliance programme page; probe-security-programs.py found none. - >- The conforming surfaces above are Wix platform defaults, not choices aceRNA made. Read them as "the host platform is agent-aware", not "the company runs an API programme".