generated: '2026-09-19' method: probed source: >- Live probes of https://agentcheck.care on 2026-09-19 (agent card, /a2a JSON-RPC, /openapi.json, /.well-known/*), read against openapi/_original/agentcheck-care-openapi.json and the terms/privacy pages. No compliance or certification claim is published anywhere on the site; every entry below is a contract or wire observation. standards: - id: a2a name: Agent2Agent Protocol (A2A) 0.3.0 conforms: true grade: conformant evidence: >- https://agentcheck.care/.well-known/agent-card.json (200, application/json) is a 0.3.0-shaped card - top-level url and protocolVersion "0.3.0", capabilities as an object, skills as an array of two, defaultInputModes and defaultOutputModes declared. POST https://agentcheck.care/a2a with an unsupported JSON-RPC method returned a JSON-RPC 2.0 error object (code -32601), so the endpoint speaks the transport the card implies. Graded in a2a/agentcheck-care-a2a.yml. - id: json-rpc-2.0 name: JSON-RPC 2.0 conforms: true evidence: >- The /a2a endpoint echoed {"jsonrpc":"2.0","id":1,"error":{"code":-32601,"message":"Method not found: ..."}} - the standard "Method not found" code and envelope. - id: rfc8615 name: RFC 8615 Well-Known URIs conforms: true evidence: The agent card is served at the registered-style /.well-known/agent-card.json path; unknown /.well-known paths return a real 404 rather than a catch-all 200. - id: openapi-3.1 name: OpenAPI 3.1.0 conforms: true evidence: >- https://agentcheck.care/openapi.json declares "openapi":"3.1.0", 32 paths, 35 operations, 4 component schemas, generated by FastAPI; Swagger UI at /docs and ReDoc at /redoc render it. caveat: No servers[], no securitySchemes, no tags, auto-generated operationIds, and six trailing-slash duplicate operations. - id: openai-chat-completions name: OpenAI Chat Completions API shape (de facto) conforms: true domain_standard: true evidence: >- POST /exam/{token}/v1/chat/completions - the operation description in the served contract reads "OpenAI-compatible chat endpoint that bridges bot answers to the orchestrator", and the path mirrors the OpenAI /v1/chat/completions route so a customer's bot can be pointed at it as if it were a model provider. This is the domain interface signature for the LLM-tooling market; it is a vendor de-facto shape, not a standards-body specification, and is recorded on that basis. caveat: The request and response schemas are not declared in the contract (the operation has no requestBody schema), so compatibility is asserted by the provider's description rather than by the spec. - id: sse name: Server-Sent Events (WHATWG) conforms: true evidence: GET /api/checkup/{checkup_id}/stream ("Stream Progress") backs the /checkup/{checkup_id} page, whose description says it "connects to the SSE stream for live progress". caveat: The contract declares the response as application/json; the media type text/event-stream is not declared. - id: rfc9457 name: RFC 9457 Problem Details conforms: false evidence: >- Errors are FastAPI-shaped {"detail": ...} (422 HTTPValidationError, observed 401/404) and one {"error":"Unauthorized"}; no application/problem+json anywhere. - id: oauth2 name: OAuth 2.0 conforms: false evidence: No oauth2 securityScheme; /.well-known/oauth-authorization-server and /.well-known/oauth-protected-resource return 404. - id: oidc name: OpenID Connect conforms: false evidence: /.well-known/openid-configuration returns 404; the product has no login. - id: rfc9116 name: RFC 9116 security.txt conforms: false evidence: /.well-known/security.txt returns 404 on all three hosts. The privacy policy asks that vulnerabilities be reported by email; that is a sentence, not a security.txt. - id: rfc9727 name: RFC 9727 API Catalog conforms: false evidence: /.well-known/api-catalog returns 404. - id: apis-json name: APIs.json conforms: false evidence: /apis.json, /apis.yml and /.well-known/apis.json return 404. - id: pagination name: Collection pagination conforms: false evidence: No list operation exists; every read is by id or is a singleton (tiers, pool, stats, health). Not applicable rather than missing. - id: idempotency name: Idempotency-Key replay protection conforms: false evidence: No Idempotency-Key header or idempotency field on POST /api/checkup or POST /api/checkout; see conventions/agentcheck-care-conventions.yml. compliance_claims: published: false note: >- No SOC 2, ISO 27001, HIPAA, GDPR-certification or similar claim is made. The terms (5.4) state plainly that AgentCheck "is not a compliance certification body" and its reports are not compliance certification, even though the $75 tier is marketed toward regulated practices. No Compliance pointer is emitted.