generated: '2026-08-07' method: derived source: openapi/bluejay-therapeutics-content-openapi.yml + live anonymous probes on 2026-08-07 scope: >- Standards conformance for the Bluejay Therapeutics Content API only. Bluejay Therapeutics published no compliance program, no certifications, no trust center and no security policy, so no `Compliance` pointer is emitted for this provider — see the compliance_program block below. standards: - id: rest name: REST over HTTP conforms: true evidence: >- Resource-oriented paths, GET semantics, standard status codes, JSON representations. Inherited from the WordPress REST contract. - id: openapi name: OpenAPI 3.1 conforms: false evidence: >- The provider publishes NO OpenAPI. Probes of /openapi.json, /openapi.yaml, /swagger.json and /api-docs on bluejaytx.com all returned 404, and no api., developer., docs. or portal. subdomain resolves. What the site DOES publish is the WordPress route index at /wp-json/, a self-describing document carrying all 372 routes with their methods and argument schemas — machine-readable, but not OpenAPI. The spec in this repository is derived from that index by API Evangelist; it is not a provider artifact. - id: hal name: HAL-style hypermedia conforms: partial evidence: >- Every object carries a `_links` block with self/collection/about/author/curies and next/prev on collections, and the `curies` entry expands the `wp:` prefix. The media type is application/json rather than application/hal+json, so this is HAL-shaped rather than HAL. - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: >- Errors use the WordPress {code, message, data.status} envelope over application/json. No `type` URI, no `title`/`detail`/`instance` fields, never application/problem+json. - id: rfc8594 name: RFC 8594 Sunset header conforms: false evidence: >- No Sunset or Deprecation header on any response, and no deprecation policy published — which is materially relevant here, because the company was absorbed by an acquirer in January 2026 and this surface has no announced end date. See lifecycle/. - id: rfc9116 name: RFC 9116 security.txt conforms: false evidence: 'GET https://bluejaytx.com/.well-known/security.txt returned 404.' - id: rfc8615 name: RFC 8615 well-known URIs conforms: false evidence: >- Every /.well-known/ path probed returned 404 — security.txt, openid-configuration, oauth-authorization-server, api-catalog, ai-plugin.json, agent-card.json, agent.json. The site answers them with the WordPress HTML 404 page, not a JSON error, and the two paths returning a 146-byte text/html body (security.txt, llms.txt) are served by the edge rather than WordPress. - id: rfc8414 name: RFC 8414 OAuth 2.0 Authorization Server Metadata conforms: false evidence: '/.well-known/oauth-authorization-server returned 404.' - id: oauth2 name: OAuth 2.0 conforms: false evidence: >- No OAuth of any kind. The route index advertises exactly one mechanism — WordPress Application Passwords, an HTTP Basic credential issued from wp-admin. - id: oidc name: OpenID Connect conforms: false evidence: '/.well-known/openid-configuration returned 404.' - id: oembed name: oEmbed 1.0 conforms: true evidence: >- /oembed/1.0/embed is a working oEmbed 1.0 provider endpoint returning version, provider_name, provider_url, author_name, title, type and html for any bluejaytx.com URL. Verified live. The sibling /oembed/1.0/proxy consumer endpoint returns 401. - id: rss name: RSS 2.0 conforms: true evidence: 'https://bluejaytx.com/feed/ returns 200 with 10 items and a valid RSS 2.0 document.' - id: sitemaps name: sitemaps.org XML Sitemap conforms: true evidence: >- https://bluejaytx.com/sitemap.xml returns a valid sitemap index (post, page, category and post_tag children) generated by All in One SEO; post-sitemap.xml lists all 35 posts. Declared in robots.txt. - id: schema-org name: schema.org structured data conforms: true evidence: >- The homepage embeds a JSON-LD @graph with Organization, WebSite, WebPage and BreadcrumbList nodes, including the organisation logo and a sameAs link to LinkedIn. Captured verbatim in json-ld/. - id: robots-txt name: robots.txt conforms: true evidence: >- Present and permissive — disallows only /wp-admin/, allows admin-ajax.php, sets Crawl-delay 10 and declares both sitemaps. Notably it does NOT disallow /wp-json/, so the REST surface is explicitly crawlable. - id: llms-txt name: llms.txt conforms: false evidence: 'GET https://bluejaytx.com/llms.txt returned 404.' - id: mcp name: Model Context Protocol conforms: false evidence: >- No MCP server. The site does register the WordPress Abilities API (wp-abilities/v1), the agent-facing capability registry that MCP bridges typically expose, but /abilities, /abilities/{name} and /categories all return 401 rest_forbidden anonymously, so nothing is exposed. - id: a2a name: A2A Agent Card conforms: false evidence: >- /.well-known/agent-card.json returned 404 and /.well-known/agent.json returned 404. No card is published, and none is authored on the provider's behalf. - id: asyncapi name: AsyncAPI conforms: false applicable: false evidence: >- No event, streaming or webhook surface of any kind exists on this provider, so there is nothing an AsyncAPI could describe. Recorded as not applicable rather than as a failure. - id: json-schema name: JSON Schema conforms: partial evidence: >- The route index publishes per-argument schemas (type, default, enum, required) for every endpoint, which is genuine JSON Schema-shaped validation metadata. Response schemas are not published at the index level; they are only exposed per-controller under an authenticated `edit` context. - id: cors name: CORS conforms: true evidence: >- Responses carry Access-Control-Allow-Headers listing Authorization, X-WP-Nonce and Content-Type, so browser clients can call the read surface directly. - id: tls name: TLS 1.3 conforms: true evidence: >- bluejaytx.com negotiates TLSv1.3; certificate valid to 2026-10-23. HSTS is NOT set. See security/bluejay-therapeutics-domain-security.yml. - id: dnssec name: DNSSEC conforms: true evidence: 'DNSSEC is enabled on bluejaytx.com. CAA records are absent and DMARC is not published.' compliance_program: published: false certifications: [] trust_center: null security_policy: null detail: >- No SOC 2, ISO 27001, HIPAA, GDPR or other compliance posture is published anywhere on bluejaytx.com. No trust., security. or compliance host resolves; /security, /security/responsible-disclosure and /privacy-policy/ all return 404 — the privacy policy was removed along with the rest of the page tree during the acquisition teardown. The mechanical probe-security-programs.py pass returned vdp=none trust=none. No `Compliance`, `TrustCenter`, `Security` or `VulnerabilityDisclosure` pointer is emitted, because there is nothing to point at. A clinical-stage biopharmaceutical company would ordinarily be expected to publish at least a privacy policy; its absence is a consequence of the wind-down, not of the company's posture while operating. x-evidence: fetched: '2026-08-07' probes: - {url: 'https://bluejaytx.com/wp-json/', status: 200} - {url: 'https://bluejaytx.com/openapi.json', status: 404} - {url: 'https://bluejaytx.com/.well-known/security.txt', status: 404} - {url: 'https://bluejaytx.com/.well-known/agent-card.json', status: 404} - {url: 'https://bluejaytx.com/.well-known/agent.json', status: 404} - {url: 'https://bluejaytx.com/llms.txt', status: 404} - {url: 'https://bluejaytx.com/feed/', status: 200} - {url: 'https://bluejaytx.com/sitemap.xml', status: 200} - {url: 'https://bluejaytx.com/wp-json/oembed/1.0/embed?url=https://bluejaytx.com/', status: 200} - {url: 'https://bluejaytx.com/wp-json/wp-abilities/v1/abilities', status: 401} - {url: 'https://bluejaytx.com/privacy-policy/', status: 404}