generated: '2026-08-08' method: probed source: >- https://primelabs.org/.well-known/ucp, mcp/boosted-commerce-ucp-tools-list.json, https://primelabs.org/agents.md, security/boosted-commerce-domain-security.yml note: >- Conformance claims below are drawn from documents the provider's own hosts serve. Boosted Commerce publishes no certifications, audit reports, or trust center, so no `Compliance` pointer is wired in apis.yml — see the compliance section at the end. standards: - id: ucp-2026-04-08 name: Universal Commerce Protocol, version 2026-04-08 conforms: true evidence: >- /.well-known/ucp returns HTTP 200 with ucp.version "2026-04-08" and declares the dev.ucp.shopping service with an MCP transport endpoint. spec: https://ucp.dev/2026-04-08/specification/overview/ - id: mcp name: Model Context Protocol conforms: true evidence: >- POST /api/ucp/mcp with method "tools/list" returned HTTP 200 and a JSON-RPC 2.0 result containing 13 tools, each with a name, description and inputSchema. - id: jsonrpc-2.0 name: JSON-RPC 2.0 conforms: true evidence: >- Both success and error responses carry "jsonrpc":"2.0" plus the matching request id; errors use the standard {code, message, data} error object. - id: json-schema-2020-12 name: JSON Schema draft 2020-12 conforms: true evidence: >- Every one of the 13 tool inputSchemas declares "$schema":"https://json-schema.org/draft/2020-12/schema". - id: rfc8615-well-known name: RFC 8615 well-known URIs conforms: partial evidence: >- The four brand storefronts serve /.well-known/ucp (HTTP 200). The corporate host boostedcommerce.com returns HTTP 403 from origin nginx for every /.well-known/* path, including security.txt. - id: rfc9116-security-txt name: RFC 9116 security.txt conforms: false evidence: >- /.well-known/security.txt returns 403 on boostedcommerce.com and 404 on all four brand hosts. - id: a2a name: A2A Agent Card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json miss on every Boosted Commerce host (403 on the corporate site, 404 on the brand storefronts). No agent card artifact was written. - id: rfc9457-problem-details name: RFC 9457 Problem Details conforms: false evidence: >- Errors are JSON-RPC 2.0 error objects, not application/problem+json. See errors/boosted-commerce-problem-types.yml. - id: oauth2 name: OAuth 2.0 conforms: false evidence: >- No OAuth metadata is served; the MCP endpoint accepts anonymous calls and no token is issued. /.well-known/oauth-authorization-server returns 403 (corporate) / 404 (brand hosts). - id: openapi name: OpenAPI conforms: false evidence: >- No OpenAPI or Swagger document was found on any Boosted Commerce host. The published machine contract for the shopping service is the ucp.dev OpenRPC schema referenced from /.well-known/ucp, which belongs to the protocol, not to Boosted Commerce. - id: idempotency-key name: Idempotent write semantics conforms: partial evidence: >- complete_checkout requires meta.idempotency-key. No other mutating tool declares one. See conventions/boosted-commerce-conventions.yml. - id: tls-1.3 name: TLS 1.3 conforms: true evidence: security/boosted-commerce-domain-security.yml — TLSv1.3 on all probed hosts. - id: hsts name: HTTP Strict Transport Security conforms: partial evidence: >- HSTS present on the brand storefronts (max-age 7889238) but absent on boostedcommerce.com. - id: dnssec name: DNSSEC conforms: false evidence: security/boosted-commerce-domain-security.yml — no DNSSEC on boostedcommerce.com or primelabs.org. - id: dmarc name: DMARC conforms: true evidence: >- boostedcommerce.com publishes DMARC with p=quarantine; primelabs.org publishes DMARC with p=none. compliance: published_certifications: [] trust_center: null note: >- No SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP or GDPR posture is published on any Boosted Commerce host, and no trust center exists (trust.boostedcommerce.com does not resolve). Card handling on the agent surface is delegated to UCP payment handlers (com.google.pay, dev.shopify.card), so the PCI boundary sits with those handlers rather than with Boosted Commerce. x-evidence: - url: https://primelabs.org/.well-known/ucp http_status: 200 fetched: '2026-08-08' - url: https://primelabs.org/api/ucp/mcp http_status: 200 fetched: '2026-08-08' - url: https://primelabs.org/.well-known/agent-card.json http_status: 404 fetched: '2026-08-08' - url: https://boostedcommerce.com/.well-known/security.txt http_status: 403 fetched: '2026-08-08'