generated: '2026-08-06' method: derived source: >- openapi/alloplex-biotherapeutics-content-openapi.yml, live response headers from https://alloplexbio.com/wp-json/, and a search of alloplexbio.com for published compliance or certification claims, 2026-08-06. api: alloplex-biotherapeutics-content-api summary: >- Standards conformance of the Alloplex Biotherapeutics content API, derived from the observed contract. No compliance program, certification or attestation is published by the company for this surface, so NO `Compliance` pointer is emitted. Note that Alloplex Biotherapeutics operates under FDA and TGA clinical-trial regulation as a drug developer — that is regulatory oversight of its therapeutics, not of this content API, and it is deliberately not asserted here as API compliance. standards: - id: openapi-3.1 conforms: true evidence: This repo's derived description validates as OpenAPI 3.1.0. Note the provider itself publishes no OpenAPI. authored_by: api-evangelist - id: rest conforms: true evidence: Resource-oriented URIs, GET semantics, JSON representations, correct 200/400/401/404 status usage. - id: hal-style-hypermedia conforms: partial evidence: >- Every object carries a `_links` map with self/collection/about/up/wp:term relations and targetHints.allow. It is HAL-like in shape but does not declare application/hal+json, so it is not HAL conformant. - id: rfc8288-web-linking conforms: true evidence: 'Collection responses return a Link header with rel="next" / rel="prev".' - id: rfc9457-problem-details conforms: false evidence: >- Errors use the bespoke WordPress envelope {code, message, data.status} served as application/json. No type URI, no title, no instance, no application/problem+json. see: errors/alloplex-biotherapeutics-problem-types.yml - id: oembed-1.0 conforms: true evidence: /oembed/1.0/embed is a registered oEmbed 1.0 provider endpoint returning a rich response; verified 200 anonymously. - id: schema-org conforms: true evidence: >- The site emits a schema.org JSON-LD @graph (Person/Organization, WebSite, WebPage, ImageObject, Article) generated by Rank Math SEO. Present in HTML only — not projected into the REST API. see: json-ld/alloplex-biotherapeutics-json-ld.yml - id: sitemaps-0.9 conforms: true evidence: /sitemap_index.xml is a valid sitemaps.org 0.9 sitemap index with seven child sitemaps. - id: rss-2.0 conforms: true evidence: /feed/ returns a valid RSS 2.0 document (application/rss+xml) carrying the post collection. - id: oauth2 conforms: false evidence: No OAuth2 endpoints, no /.well-known/oauth-authorization-server (404), no client registration. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header observed on any response; no deprecation policy published. - id: mcp conforms: unknown evidence: >- A WordPress MCP adapter endpoint is registered at POST /wp-json/mcp/mcp-adapter-default-server, but both `initialize` and `tools/list` return 401 rest_forbidden anonymously, so protocol conformance cannot be assessed and no MCP server is claimed for this provider. - id: a2a conforms: false evidence: Both /.well-known/agent-card.json and /.well-known/agent.json return 404. No agent card is published. - id: http-caching conforms: true evidence: >- 'cache-control: max-age=600, must-revalidate' plus Last-Modified and Age are returned, so conditional requests and shared-cache reuse are supported. Uncommon for a WordPress REST deployment and worth noting. - id: cors conforms: true evidence: >- Access-Control-Allow-Headers and Access-Control-Expose-Headers (X-WP-Total, X-WP-TotalPages, Link) are returned, so pagination totals are readable from a browser client. compliance_program: published: false certifications: [] trust_center: null detail: >- No SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP or GDPR attestation is published for this surface, and no trust center exists — trust.alloplexbio.com does not resolve and /security, /trust and /compliance all return 404. The site publishes a Privacy Policy and Terms of use, which are legal notices rather than a compliance program. No `Compliance` pointer is emitted.