generated: '2026-08-02' method: searched source: Aqtual public site, newsroom and publications plus trade-press coverage (2026-08-02 web search and probes) scope: >- Aqtual publishes no API, so there are no API or cross-cutting technical standards to assert. What it is actually measured against is the US clinical-laboratory and in-vitro-diagnostic regulatory pathway for a blood-based therapy-selection test. That pathway is recorded here as the applicable regime, with status stated honestly as pre-commercial / not publicly evidenced rather than achieved. The API/protocol standards block below is recorded as not-applicable rather than false, so this file is never mistaken for a compliance posture the company does not claim. regulatory_regime: - id: clia-88 name: Clinical Laboratory Improvement Amendments (CLIA '88), CMS conforms: unknown applicable: true evidence: >- Aqtual's lead product is a blood-based therapy-response prediction test for rheumatoid arthritis, which in the US would be run as a laboratory developed test in a CLIA-certified high-complexity laboratory. As of 2026-08-02 no CLIA certificate number, CLIA-lab statement or CAP accreditation claim appears on aqtual.com or in any press release found by search. note: >- Recorded as unknown rather than false - absence of a public claim is not evidence of absence of certification. Re-probe on the next pass and on commercial launch. - id: cap-accreditation name: College of American Pathologists laboratory accreditation conforms: unknown applicable: true evidence: no CAP accreditation claim published on the company site or in press releases - id: fda-ldt-oversight name: FDA oversight of laboratory developed tests / IVD premarket pathway conforms: false status: pre-commercial applicable: true evidence: >- Aqtual has no FDA-cleared or FDA-approved product. Its RA therapy-selection test is still in prospective clinical evaluation (PRIMA-102, NCT05936970, >1,300 patients enrolled, completion targeted Q4 2025), and its oncology programs (leiomyosarcoma immunotherapy response, early colorectal cancer detection) are at conference-abstract and journal-publication stage. note: recorded as conforms:false because no clearance exists, not because a check failed - id: hipaa name: HIPAA Privacy and Security Rules conforms: unknown applicable: true evidence: >- Aqtual handles patient specimens and clinical trial data, so HIPAA applies to it as a covered entity or business associate. No HIPAA statement, notice of privacy practices, privacy policy or terms of service is published anywhere on aqtual.com - the entire site is five pages plus a two-post blog, with no legal or policy section at all. - id: gcp-ich-e6 name: ICH E6 Good Clinical Practice (prospective observational trial conduct) conforms: unknown applicable: true evidence: >- PRIMA-102 is registered on ClinicalTrials.gov as NCT05936970; registration is consistent with GCP-governed conduct, but no sponsor GCP statement is published. api_standards: - id: openapi conforms: false applicable: false evidence: no public API contract published (see well-known/aqtual-well-known.yml) - id: asyncapi conforms: false applicable: false - id: graphql conforms: false applicable: false - id: oauth2 conforms: false applicable: false - id: openid-connect conforms: false applicable: false - id: rfc9457-problem-details conforms: false applicable: false - id: mcp conforms: false applicable: false - id: a2a conforms: false applicable: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json both 404 on aqtual.com - id: rfc9727-api-catalog conforms: false applicable: true evidence: /.well-known/api-catalog returns 404 on aqtual.com - id: rfc9116-security-txt conforms: false applicable: true evidence: /.well-known/security.txt returns 404 on aqtual.com health_data_standards: - id: hl7-fhir conforms: false applicable: false evidence: >- No FHIR endpoint, no results-delivery API and no EHR-integration surface is published. Relevant to watch on commercial launch of a clinical test, when result delivery to ordering providers typically needs an interface. - id: loinc conforms: unknown applicable: true evidence: no published test-code or LOINC mapping (test is pre-commercial) information_security_compliance: found: false note: >- No trust center, SOC 2, ISO 27001 or equivalent information-security certification page was found by probe-security-programs.py (vdp=none trust=none) or by search. trust.aqtual.com and status.aqtual.com do not resolve. No `Compliance` and no `TrustCenter` pointer is wired in apis.yml. vulnerability_disclosure: found: false note: >- No security.txt, no /security or /responsible-disclosure page, no bug bounty program on HackerOne, Bugcrowd or Intigriti. No `Security` or `VulnerabilityDisclosure` pointer is wired. domain_security_observed: source: security/aqtual-domain-security.yml summary: >- aqtual.com serves TLS 1.3 with HSTS (max-age 31536000, one year) and publishes SPF and a DMARC record at policy p=quarantine. DNSSEC is not enabled and no CAA record is published. Certificate expires 2026-10-27.