generated: '2026-09-07' method: probed source: >- https://advancedaircraftcompany.com/.well-known/oauth-authorization-server, https://advancedaircraftcompany.com/.well-known/oauth-protected-resource, https://advancedaircraftcompany.com/wp-json name: Advanced Aircraft Company Conformance description: >- Standards this surface demonstrably conforms to, each evidenced by a document the company's own host serves. Everything here is inherited from the WordPress platform and its MCP Adapter plugin rather than authored by Advanced Aircraft Company. No compliance certifications of any kind are published, so no Compliance pointer is emitted. conformance: - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata conforms: true evidence: https://advancedaircraftcompany.com/.well-known/oauth-authorization-server note: >- Serves issuer, authorization_endpoint, token_endpoint, revocation_endpoint, response_types_supported, grant_types_supported, code_challenge_methods_supported and scopes_supported. - id: rfc9728 name: OAuth 2.0 Protected Resource Metadata conforms: true evidence: https://advancedaircraftcompany.com/.well-known/oauth-protected-resource note: >- Serves resource, authorization_servers, bearer_methods_supported and scopes_supported, correctly naming the MCP endpoint as the protected resource. - id: rfc7636 name: PKCE for OAuth Public Clients conforms: true evidence: https://advancedaircraftcompany.com/.well-known/oauth-authorization-server note: code_challenge_methods_supported is ["S256"]; token_endpoint_auth_methods_supported is ["none"]. - id: rfc9207 name: OAuth 2.0 Authorization Server Issuer Identification conforms: true evidence: https://advancedaircraftcompany.com/.well-known/oauth-authorization-server note: authorization_response_iss_parameter_supported is true. - id: mcp name: Model Context Protocol conforms: true evidence: https://advancedaircraftcompany.com/wp-json/mcp/mcp-oauth-server note: >- JSON-RPC 2.0 endpoint returning a well-formed MCP authentication challenge (mcp_unauthorized) and advertised through RFC 9728. The protocol version could not be read anonymously because initialize/tools/list are auth-gated, so the MCP revision in use is not asserted. - id: rfc8288 name: Web Linking conforms: true evidence: https://advancedaircraftcompany.com/wp-json/wp/v2/posts?per_page=1 note: Link header with rel="next"/"prev" for pagination; _links HAL-style relations on every record. - id: oembed name: oEmbed 1.0 conforms: true evidence: https://advancedaircraftcompany.com/wp-json/oembed/1.0/embed note: WordPress core oEmbed provider endpoint; returns rest_missing_callback_param without a url param. - id: sitemaps-org name: sitemaps.org XML Sitemap 0.9 conforms: true evidence: https://advancedaircraftcompany.com/sitemap.xml note: Sitemap index generated by All in One SEO v5.0.1.1. - id: llmstxt name: llms.txt conforms: true evidence: https://advancedaircraftcompany.com/llms.txt note: >- Served as text/plain and structured with the llms.txt heading convention, but plugin-generated (All in One SEO) and containing only a site content index — no API or tool information. - id: rfc9457 name: Problem Details for HTTP APIs conforms: false evidence: https://advancedaircraftcompany.com/wp-json/wp-abilities/v1/abilities note: Errors use the WordPress {code,message,data.status} envelope; no application/problem+json. - id: openapi name: OpenAPI conforms: false evidence: https://advancedaircraftcompany.com/openapi.json note: >- 404. No OpenAPI, Swagger, AsyncAPI, GraphQL SDL, gRPC/Protobuf or WSDL contract is published on any host. The route index at /wp-json is self-describing in WordPress's own schema format, which is a machine-readable contract but not an OpenAPI one. - id: oidc name: OpenID Connect Discovery conforms: false evidence: https://advancedaircraftcompany.com/.well-known/openid-configuration note: 404 returning the site's HTML theme shell. domain_standards: market: Unmanned Aircraft Systems / aerospace and defense probed: - id: astm-f3411-remote-id name: ASTM F3411 Remote ID / Network Remote ID conforms: false note: >- The obvious domain standard for this market. No Remote ID, UTM/USS, InterUSS or ASTM F3548 surface is served or referenced anywhere on the company's hosts. - id: mavlink name: MAVLink telemetry protocol conforms: false note: >- Not published. AAC ships flight hardware, but exposes no telemetry, fleet or ground-control API to the public, so no airspace or telemetry standard is declared in any contract. - id: stanag-4586 name: NATO STANAG 4586 UCS interface conforms: false note: Not referenced. Defense contracts are cited in press releases, not as published interfaces. result: >- No domain standard is declared by any contract this company publishes. REWARD-ONLY dimension — recorded as an honest absence, not a penalty, and nothing is invented to fill the slot. compliance_certifications: published: false note: >- No SOC 2, ISO 27001, PCI, HIPAA, FedRAMP or CMMC claim is published on the site or in a trust center. Press material states AAC aircraft are NDAA Sec. 848 compliant and built in the USA with qualified traceable parts — that is a hardware supply-chain compliance claim about the aircraft, not an information-security certification, and it is not carried by any machine-readable artifact. No Compliance pointer is emitted on the strength of it.