generated: '2026-08-07' method: derived source: >- openapi/bioflyte-content-openapi.yml, openapi/bioflyte-portal-openapi-original.json, live headers, well-known/bioflyte-well-known.yml and security/bioflyte-domain-security.yml standards: - id: openapi-3.0 conforms: true evidence: >- openapi/bioflyte-portal-openapi-original.json — OpenAPI 3.0.1, PUBLISHED by BioFlyte at https://portal.bioflyte.com/swagger/v1/swagger.json and saved verbatim. Generated by Swashbuckle from the ASP.NET Core controllers. provider_published: true - id: openapi-3.1 conforms: true evidence: >- openapi/bioflyte-content-openapi.yml — DERIVED by API Evangelist from the provider's live WordPress route-discovery document, not published by BioFlyte. provider_published: false - id: json-schema conforms: true evidence: >- WordPress REST route args are JSON Schema fragments (type/enum/default/minimum/maximum); the AdminWeb document declares 8 components.schemas. - id: rfc7617-http-basic conforms: true evidence: securitySchemes.applicationPassword — http/basic (WordPress Application Passwords) - id: rfc8288-web-linking conforms: true evidence: 'link: <...>; rel="next" observed on GET /wp-json/wp/v2/posts; resources carry _links relations' - id: rfc9457-problem-details conforms: false evidence: >- Content API uses the WordPress {code,message,data.status} envelope; the portal API declares no error responses at all and answers unauthenticated calls with a 302 to an HTML login page. - id: oauth2 conforms: false evidence: >- No oauth2 securityScheme in either document; /.well-known/oauth-authorization-server 404 on both hosts. The portal uses ASP.NET Core Identity cookie sessions. - id: openid-connect conforms: false evidence: /.well-known/openid-configuration 404 on www.bioflyte.com, portal.bioflyte.com and portal.bioflyte.com/identity - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt 404 on every host - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog 404 - id: a2a conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json both 404 on www.bioflyte.com and portal.bioflyte.com (the apex 301s to www) - id: model-context-protocol conforms: false evidence: >- No MCP endpoint. No `mcp` namespace in the WordPress route index, /.well-known/mcp.json 404, and the wp-abilities/v1 registry returns 401 anonymously. - id: asyncapi conforms: false evidence: >- No AsyncAPI document and no published webhook catalogue. The portal API does expose sample/alert event SCHEMAS (NewSampleReceived, AlertsUpdated) and Test operations named TestOnSampleReceived / TestOnAlertsUpdated / TestOnSampleStatusUpdated, which strongly imply an internal event surface — but nothing about it is published, so no AsyncAPI or Webhooks pointer was wired. See asyncapi/bioflyte-event-surface.yml for what is observable. - id: graphql conforms: false evidence: no /graphql route on either host (404 on portal.bioflyte.com, no namespace in the WordPress route index) - id: llms-txt conforms: false evidence: >- https://www.bioflyte.com/llms.txt returns 404. The file at llms/bioflyte-llms.txt was GENERATED by API Evangelist from this repo, not harvested. provider_published: false - id: dnssec conforms: false evidence: security/bioflyte-domain-security.yml — no DNSKEY on bioflyte.com - id: spf conforms: true evidence: SPF record present on bioflyte.com - id: dmarc conforms: partial evidence: DMARC record present but policy is p=none — monitoring only, no enforcement - id: caa conforms: false evidence: no CAA record on bioflyte.com - id: hsts conforms: true evidence: >- 'strict-transport-security: max-age=31536000; includeSubDomains; preload' on www.bioflyte.com; max-age=2592000 (30 days, no includeSubDomains, no preload) on portal.bioflyte.com - id: tls-1.3 conforms: true evidence: TLSv1.3 negotiated on both www.bioflyte.com and portal.bioflyte.com compliance_program: published: false certifications: [] note: >- No trust center and no SOC 2 / ISO 27001 / HIPAA / FedRAMP / CMMC compliance page found on bioflyte.com (/security/, /trust/, /compliance/, /responsible-disclosure/ all 404; trust.bioflyte.com does not resolve; probe-security-programs.py returned vdp=none trust=none). No Compliance or TrustCenter pointer wired. regulatory_context: note: >- Informational only, derived from BioFlyte's own newsroom — not an API conformance claim. BioFlyte holds a U.S. Department of Homeland Security SAFETY Act designation as a Qualified Anti-Terrorism Technology and a U.S. Air Force SBIR Phase II contract, and sells into airports, federal buildings and mailrooms. That is a product designation, not a published security or compliance program for its software, and none of it is expressed in any machine-readable artifact on either host.