generated: '2026-09-06' method: probed source: >- Live probes of https://www.activemembrane.com/_api/mcp, /llms.txt, /robots.txt and /.well-known/* on 2026-09-06. note: >- Active Membranes is a water-technology hardware company. It publishes no API contract, claims no security or privacy certification anywhere on its site, and operates in a market (membrane desalination) whose standards are ASTM/AWWA material and test standards rather than data-interchange standards — so the domain_standard_conformance slot has nothing legitimate to fill and is left empty rather than invented. conformance: - id: mcp name: Model Context Protocol conforms: true evidence: >- https://www.activemembrane.com/_api/mcp answered an anonymous JSON-RPC 2.0 tools/list with HTTP 200, a well-formed result.tools array of 9 tools each carrying a JSON Schema inputSchema, and an mcp-session-id header. Served by the Wix Site MCP runtime on the provider's own hostname. fetched: '2026-09-06' - id: json-rpc-2.0 name: JSON-RPC 2.0 conforms: true evidence: >- Responses carry "jsonrpc":"2.0" and echo the request id. Observed on both tools/list and tools/call. fetched: '2026-09-06' - id: llms-txt name: llms.txt convention conforms: true evidence: >- https://www.activemembrane.com/llms.txt returns HTTP 200, 10,764 bytes of Markdown following the llms.txt shape (H1 name, blockquote summary, H2 sections, canonical link list). Referenced from robots.txt. fetched: '2026-09-06' deviations: - >- The "Canonical links" section points at https://www.activemembrane.com/insights, which returns HTTP 404. The live page is /reverse-osmosis-insights. An agent following the provider's own map hits a dead link. - id: content-signals name: Cloudflare Content Signals Policy (robots.txt) conforms: true evidence: >- https://www.activemembrane.com/robots.txt carries "Content-Signal: search=yes,ai-train=no,use=reference" in the Cloudflare managed block. fetched: '2026-09-06' deviations: - >- The file contradicts itself. The Cloudflare-managed block Disallows ClaudeBot, GPTBot, CCBot, Google-Extended, Applebot-Extended and others; a later hand-added block re-Allows the same agents for "LLM visibility". Two groups for the same user-agent with opposite directives means an agent's behaviour depends on which group its parser honours. This is stated policy that does not resolve, not a violation of the convention itself. - id: rfc9116-security-txt name: RFC 9116 security.txt conforms: false evidence: >- /.well-known/security.txt returns HTTP 400 (Wix edge error shell) on both www.activemembrane.com and activemembrane.com. fetched: '2026-09-06' - id: rfc9727-api-catalog name: RFC 9727 /.well-known/api-catalog conforms: false evidence: '/.well-known/api-catalog returns HTTP 400 on both hosts.' fetched: '2026-09-06' - id: oauth2 name: OAuth 2.0 conforms: false evidence: >- No authorization server metadata (RFC 8414) and no protected resource metadata (RFC 9728); the MCP endpoint issues no WWW-Authenticate challenge because it requires no authentication. fetched: '2026-09-06' - id: openapi name: OpenAPI conforms: false evidence: >- No OpenAPI document at any probed location on either host: /openapi.json, /openapi.yaml, /swagger.json (HTTP 400), /api-docs, /docs, /redoc, /api, /developers, /developer (HTTP 404). fetched: '2026-09-06' - id: a2a-agent-card name: A2A Agent Card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json both return HTTP 400 on both hosts. No card is published, so none is recorded. fetched: '2026-09-06' domain_standards: [] domain_standards_note: >- No data-interchange standard applies to this company's market that it declares in a contract. Nothing is asserted. certifications: [] certifications_note: >- No SOC 2, ISO 27001, PCI, HIPAA or FedRAMP claim appears anywhere on the public site; /trust, /security and /compliance all return HTTP 404. No Compliance pointer is wired.