generated: '2026-08-13' method: searched source: >- https://appsamurai.com/information-security-policy/ + https://docs.storyly.io/.well-known/api-catalog + openapi/appsamurai-storyly-external-api-openapi.json + live probes of api.storyly.io and mcp.storyly.io (2026-08-13) docs: https://appsamurai.com/information-security-policy/ notes: >- Two genuine conformance wins were found in round 2, and both come from the Storyly side: docs.storyly.io serves an RFC 9727 /.well-known/api-catalog linkset, and mcp.storyly.io implements MCP protocol version 2025-06-18 over both streamable-HTTP and SSE. Everything else is unmet, and the honest reading is that App Samurai's conformance posture is organisational (ISO 27001) rather than protocol-level. standards: - id: iso-27001 conforms: true evidence: >- App Samurai states it is ISO 27001 certified for information security. The Information Security Policy (HTTP 200) describes the ISMS and names the legal entity, Apps Medya Teknoloji A.S. source: https://appsamurai.com/information-security-policy/ certificate_published: false certificate_note: The certificate itself, its scope and its issuing body are not published. - id: rfc9727-api-catalog conforms: true evidence: >- https://docs.storyly.io/.well-known/api-catalog returns HTTP 200 with content-type application/linkset+json and a valid linkset naming service-desc (application/vnd.oai.openapi+json) and service-doc for the Storyly External API. method: probed checked: '2026-08-13' caveat: >- One of the three linkset entries (6493ee43ef401503d6962fdd) resolves to a 404, so the catalog advertises a specification that is not served. artifact: well-known/appsamurai-storyly-api-catalog.json - id: mcp conforms: true version: '2025-06-18' evidence: >- https://mcp.storyly.io/mcp answered initialize with protocolVersion 2025-06-18, serverInfo placement-mcp/1.0.0 and capabilities {prompts, resources, tools}; tools/list returned 5 tools with complete JSON Schema inputSchemas. /sse serves the legacy HTTP+SSE transport. method: probed checked: '2026-08-13' artifact: mcp/appsamurai-storyly-mcp-tools.json - id: openapi conforms: partial version: 3.0.3 evidence: >- The Storyly External API IS published as OpenAPI 3.0.3 by the provider (via its ReadMe hub) - a genuine upgrade on round 1. But it declares no components/schemas, inlines every shape, states parameter constraints as free text in `description` ("required=False, min_value=1, max_value=100") instead of schema keywords, and declares only 200 responses on all 18 operations. The Campaign Spend API has no provider-published spec; API Evangelist authored one from the Help Center article. - id: json-schema conforms: partial evidence: >- The MCP server's tool inputSchemas are correct JSON Schema with types, enums, defaults, minLength/minimum/maximum and additionalProperties:false. The REST OpenAPI, by contrast, types every query parameter as `string` including integers and dates, and carries no schema constraints at all. The agent surface is better typed than the API surface. - id: oauth2 conforms: false evidence: >- No OAuth anywhere. Storyly uses a bearer JWT with no documented issuance or authorization endpoint; the Campaign Spend API uses a path-embedded key. No /.well-known/oauth-authorization-server on any host (all 404). - id: oidc conforms: false evidence: No /.well-known/openid-configuration on any App Samurai or Storyly host. - id: rfc9457-problem-details conforms: false evidence: >- Storyly returns a vendor envelope {"status","request","error":{"message","code"}} with content-type application/json, not application/problem+json. The Campaign Spend API returns bare status codes. - id: rfc9331-ratelimit-headers conforms: false evidence: >- No RateLimit-* or X-RateLimit-* headers observed on api.storyly.io, and no limits documented. See rate-limits/appsamurai-rate-limits.yml. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header and no deprecation policy published. - id: rfc9116-security-txt conforms: false evidence: >- No security.txt on any App Samurai or Storyly host. The document harvested in round 1 is Intercom's, served through the help-centre CNAME, and is explicitly not credited. See security/appsamurai-vulnerability-disclosure.yml. - id: idempotency conforms: false evidence: >- No Idempotency-Key support on any of the four Storyly create operations. See conventions/appsamurai-conventions.yml. - id: a2a conforms: false evidence: >- No /.well-known/agent-card.json and no legacy /.well-known/agent.json on any of the nine hosts probed. The 200s returned by dashboard.storyly.io and dashboard.appsamurai.com are SPA catch-all HTML, not agent cards. - id: llmstxt conforms: true evidence: >- https://docs.storyly.io/llms.txt (HTTP 200, text/plain, 17 KB) indexes 35 guides plus the External API reference in the llms.txt format, with .md variants of every page. Saved to llms/appsamurai-storyly-llms.txt. method: probed checked: '2026-08-13' caveat: >- appsamurai.com serves no llms.txt (404), and the help-centre llms.txt captured in round 1 now 308-redirects away. - id: asyncapi conforms: false applicable: false evidence: >- No event, streaming or outbound-webhook surface is published by either brand, so there is nothing an AsyncAPI would describe. Not a penalty. - id: graphql conforms: false applicable: false evidence: No /graphql endpoint on any probed host. compliance_claims: - name: ISO 27001 published: true url: https://appsamurai.com/information-security-policy/ - name: SOC 2 published: false - name: GDPR published: true url: https://appsamurai.com/privacy-policy/ note: Privacy policy only; no DPA or subprocessor list found. trust_center: none