generated: '2026-09-12' method: probed source: >- Live probes on 2026-09-12 of https://docs.afterquery.com/mcp, https://docs.afterquery.com/.well-known/agent-card.json, https://docs.afterquery.com/.well-known/mcp.json, https://www.afterquery.com/llms.txt and the /.well-known/ path set across every AfterQuery host. note: >- AfterQuery ships no API contract, so there is no OpenAPI, no securitySchemes and no domain standard declared in a contract to assess. What can be asserted is confined to the agent-surface standards it actually serves, each with the probe that established it. The AI training-data / evaluation market this company sells into has no machine-readable domain standard analogous to SCIM, FHIR or ISO 20022, so domain_standard_conformance is not applicable here - and, being reward-only, is left unclaimed rather than invented. conformance: - id: mcp name: Model Context Protocol (JSON-RPC 2.0, streamable HTTP) conforms: true evidence: >- POST https://docs.afterquery.com/mcp with {"jsonrpc":"2.0","id":1,"method":"tools/list"} returned HTTP 200 text/event-stream carrying a well-formed JSON-RPC result with three tools, each with a JSON Schema inputSchema and MCP tool annotations. - id: a2a name: A2A Agent Card conforms: true version_declared: '0.3' grade: conformant evidence: >- GET https://docs.afterquery.com/.well-known/agent-card.json returned HTTP 200 application/json parsing as an AgentCard object; graded against A2A 1.0.0 hard checks in a2a/afterquery-a2a.yml. - id: llms-txt name: llms.txt conforms: true evidence: >- GET https://www.afterquery.com/llms.txt returned HTTP 200 in llms.txt format (H1, blockquote summary, sectioned link lists); a second, separate llms.txt is served for the help centre at https://docs.afterquery.com/llms.txt. - id: agent-skills name: Agent Skills (well-known skill.md) conforms: true evidence: >- GET https://docs.afterquery.com/.well-known/agent-skills/afterqueryexperts/skill.md returned HTTP 200 with YAML frontmatter (name, description, metadata) over markdown instructions. - id: openapi name: OpenAPI conforms: false evidence: >- No OpenAPI is published. /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs and /redoc were probed on www.afterquery.com, docs.afterquery.com and api.afterquery.com on 2026-09-12 - every one 404 - and a tree of the documentation MCP's own virtual filesystem shows no api-reference directory. - id: rfc9116-security-txt name: RFC 9116 security.txt conforms: false evidence: /.well-known/security.txt returned 404 on every AfterQuery host probed. - id: rfc9727-api-catalog name: RFC 9727 api-catalog conforms: false evidence: /.well-known/api-catalog returned 404 on every AfterQuery host probed. - id: oauth2 name: OAuth 2.0 / RFC 8414 / RFC 9728 conforms: false evidence: >- No authorization-server or protected-resource metadata is served; the one callable surface is anonymous (see authentication/afterquery-authentication.yml). domain_standard: applicable: false note: >- No published domain standard governs the expert-data / model-evaluation market AfterQuery sells into. Its benchmarks (IDE-Bench, App-Bench, Market-Bench, FinanceArena, FinanceQA) are de-facto evaluation formats it authors itself, not a standard it conforms TO, and its harness work runs on Harbor, an upstream framework it forks rather than owns. certifications: published: [] note: >- No SOC 2, ISO 27001, HIPAA, PCI or FedRAMP claim appears on the website, in either llms.txt, or on the privacy or terms pages, and there is no trust centre. No Compliance pointer is emitted.