generated: '2026-08-11' method: derived source: >- openapi/alphaai-rest-api-openapi.yml, well-known/ documents probed 2026-08-11, https://alphai.io/developers, and the live 401/429 behaviour observed on api.alphai.io and mcp.alphai.io. description: >- Cross-cutting standards conformance. AlphaAI's strongest conformance is on the agent side — OpenAPI 3.1, MCP with a correct OAuth 2.1 / RFC 8414 / RFC 9728 / RFC 7591 stack, and RFC 9116 — while the REST API deliberately declines the usual REST error and rate-limit standards in favour of its own shapes. standards: - id: openapi-3.1 conforms: true evidence: >- openapi: 3.1.0 served anonymously at https://api.alphai.io/api/schema/ as application/yaml. 15 operations, 39 component schemas, 64 inline examples, global security requirement, tags declared and applied. - id: rfc9116-security-txt conforms: true evidence: >- https://api.alphai.io/.well-known/security.txt returns 200 text/plain with Contact, Expires (2027-07-04), Preferred-Languages and a correct self-referential Canonical. - id: oauth2 conforms: true scope: MCP server only evidence: >- Authorization-code flow with PKCE S256 and refresh tokens advertised at https://mcp.alphai.io/.well-known/oauth-authorization-server. The REST API uses a static bearer key and has no OAuth surface. - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: well-known/alphaai-oauth-authorization-server.json (HTTP 200) - id: rfc9728-oauth-protected-resource-metadata conforms: true evidence: >- well-known/alphaai-oauth-protected-resource.json (HTTP 200), and the 401 on POST /mcp returns a WWW-Authenticate naming the resource_metadata URL, which itself resolves 200. - id: rfc7591-dynamic-client-registration conforms: true evidence: >- registration_endpoint https://mcp.alphai.io/oauth/register advertised, with token_endpoint_auth_methods_supported [none] for public clients. - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported [S256] - id: mcp-streamable-http conforms: true evidence: >- Registered in the official MCP registry as io.github.makeev/alphai-mcp with remote type streamable-http at https://mcp.alphai.io/mcp; status active. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on all three hosts. - id: rfc9457-problem-details conforms: false evidence: >- Errors are application/json with a message/detail/error + extra envelope. No application/problem+json anywhere in the spec, and no type/title/status/ instance members. See errors/alphaai-problem-types.yml — the extra block is genuinely machine-readable, it simply is not RFC 9457. - id: rfc9331-ratelimit-headers conforms: false evidence: >- Uses the legacy X-RateLimit-Limit/Remaining/Reset trio, not the RateLimit / RateLimit-Policy fields of the IETF draft. Retry-After (RFC 9110) IS used correctly on 429. - id: rfc8594-sunset-header conforms: false evidence: >- No Sunset or Deprecation header support documented or observed, and no deprecation policy is published. See lifecycle/alphaai-lifecycle.yml. - id: json-api conforms: false evidence: Plain JSON responses; no JSON:API document structure. - id: cursor-pagination conforms: true evidence: >- Opaque cursor + next_cursor on every feed endpoint, with next_cursor null at end of feed. GET /api/symbols/ is the documented exception (limit/offset). - id: idempotency conforms: false evidence: >- No idempotency-key mechanism. All 15 REST operations are GET, so there is no unsafe write to protect on the REST surface. - id: hmac-webhook-signing conforms: true evidence: >- X-Alphai-Signature: t=,v1= over timestamp + "." + body, verified with constant-time comparison. The provider names the Stripe scheme as its model. See asyncapi/alphaai-webhooks.yml. - id: asyncapi conforms: false evidence: >- No AsyncAPI document published; /asyncapi.yaml returns 404 on api.alphai.io and the website host. A documented webhook surface exists without a spec. - id: llms-txt conforms: true evidence: >- https://alphai.io/llms.txt returns 200 text/plain in correct llms.txt form (H1, blockquote summary, sectioned link lists), with a companion llms-full.txt linked from it. - id: a2a conforms: false evidence: >- No agent card at /.well-known/agent-card.json or /.well-known/agent.json on any of the three hosts (all 404). See well-known/alphaai-well-known.yml. domain_standards: - id: sec-form-4 conforms: true role: consumer evidence: >- Insider data is sourced from SEC EDGAR Form 4 filings and exposed as structured InsiderEvent / InsiderTradeEvent schemas. The changelog records transaction values being validated against the filings themselves, with unverifiable figures omitted rather than estimated (2026-07-29), and a 1,489-filing backfill from the SEC indexes (2026-08-06). - id: rule-10b5-1 conforms: true role: reporting evidence: >- TickerInsiderSummary reports the share of sales made under a 10b5-1 plan — the distinction that separates scheduled from discretionary insider selling. compliance_program: published: false certifications: [] trust_center: null note: >- No SOC 2, ISO 27001, PCI, HIPAA or other certification is claimed anywhere on the public surface, and probe-security-programs.py found no trust center. Enterprise pricing mentions "security review" as a sales-stage activity, not a published attestation. No Compliance pointer is emitted for this provider.