generated: '2026-09-19' method: derived source: >- openapi/bmcxiv-com-openapi.yml (verbatim provider spec, 12 operations), the live MCP initialize/tools/list responses, the A2A agent card, and the provider's trust.md — all fetched 2026-09-19. standards: - id: x402 conforms: true evidence: >- runOwnerBreachExposureCheck declares a 402 "x402 payment required" response; PreparedCheck.expected_initial_status is const 402 with asset const USDC and network/price fields; llms.txt and the landing page state "$1.00 USDC on Solana through x402". - id: mcp conforms: true evidence: >- POST /mcp answered initialize with protocolVersion 2025-11-25, tools/list with 8 tools carrying inputSchema and annotations, resources/list with 5 resources; /.well-known/mcp-server.json is a registry server manifest (server.schema 2025-12-11). - id: a2a conforms: true evidence: >- /.well-known/agent-card.json parses as an A2A 0.3.0 card (capabilities object, skills array, preferredTransport JSONRPC); graded conformant in a2a/bmcxiv-com-a2a.yml. - id: json-rpc-2.0 conforms: true evidence: Both /mcp and /a2a answer JSON-RPC 2.0 envelopes (observed error -32601 on an unknown A2A method). - id: http-bearer-auth conforms: true evidence: components.securitySchemes.bearerAuth is type http / scheme bearer / bearerFormat opaque-token; applied on 4 operations. - id: idempotency-key conforms: true scope: partial evidence: >- Idempotency-Key header (must equal body idempotency_key, 8-128 chars) on prepareOwnerBreachExposurePayment and runOwnerBreachExposureCheck; responses carry idempotent_replay. Not declared on the enrollment writes. - id: oauth2 conforms: false evidence: no oauth2 securityScheme; /.well-known/oauth-authorization-server and oauth-protected-resource 404. - id: oidc conforms: false evidence: /.well-known/openid-configuration 404. - id: rfc9457-problem-details conforms: false evidence: 'errors use application/json with an {error: {code, message, details}} envelope, not application/problem+json.' - id: rfc8594-sunset conforms: false evidence: no Deprecation or Sunset headers declared anywhere in the spec. - id: pagination conforms: false evidence: no list operations exist; every resource is fetched by id. - id: llms-txt conforms: true evidence: /llms.txt served (994 bytes) in llmstxt.org shape — H1, blockquote summary, link list. domain_standard: none domain_standard_note: >- Breach-intelligence has no cross-vendor interchange standard the contract could declare (no HIBP-style schema, no STIX/TAXII surface, no CTI namespace in the spec). Reward-only dimension; nothing asserted. notes: - No published compliance programme (SOC 2, ISO 27001 etc.) was found — see security/ — so no Compliance pointer is emitted.