generated: '2026-08-08' method: derived source: >- openapi/ specs in this repo plus live anonymous probes of https://www.burgersinghonline.com/wp-json/ (2026-08-08) note: >- Burger Singh publishes no conformance, certification or compliance claims of any kind. Every entry below is an observation about the deployed WordPress REST surface, not a claim by the company. No Compliance pointer is emitted for this provider. standards: - id: openapi-3.1 conforms: true evidence: >- Six OpenAPI 3.1.0 documents in openapi/, derived by API Evangelist from the live route index. Burger Singh itself publishes no OpenAPI. published_by_provider: false - id: rest conforms: true evidence: Resource-oriented URIs, HTTP verbs, JSON representations, HTTP status semantics. - id: rfc8288-web-linking conforms: true evidence: >- Link header with rel="next"/"prev" observed on /wp/v2/pages?per_page=1. - id: rfc9457-problem-details conforms: false evidence: >- Errors are application/json with the WordPress {code, message, data} envelope, not application/problem+json. See errors/burger-singh-problem-types.yml. - id: oauth2 conforms: false evidence: No oauth2 security scheme; no OAuth endpoints in the route table. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on this host. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on www.burgersinghonline.com. - id: rfc8615-well-known conforms: false evidence: >- No /.well-known/ document of any kind resolves - security.txt, api-catalog, agent-card.json, agent.json, openid-configuration, oauth-authorization-server and ai-plugin.json all return 404. - id: a2a-agent-card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json both return 404 with the site 404 body. No agent card is published, so no a2a/ artifact was written. - id: mcp conforms: false evidence: No MCP server is published. mcp/burger-singh-mcp.yml is a derived candidate only. - id: asyncapi conforms: false evidence: >- No event, streaming or webhook surface exists. Not applicable rather than failing - the provider is not penalized for an event surface it does not have. - id: llms-txt conforms: false evidence: >- GET https://www.burgersinghonline.com/llms.txt returns 404. (The separate parked domain burgersingh.com serves an llms.txt, but that host is a domain-parking lander, not the company site - see well-known/burger-singh-well-known.yml.) - id: sitemaps-0.9 conforms: true evidence: >- Yoast sitemap index at /sitemap_index.xml with six child sitemaps (page, store_locator, inthenews, medialist, hotdeals, category). HTTP 200. - id: rss-2.0 conforms: true evidence: >- Valid RSS 2.0 document at /feed/ (HTTP 200), though it currently carries zero items - the site publishes no posts. - id: schema-org conforms: true evidence: >- Yoast emits a schema.org JSON-LD graph in yoast_head_json on every page/term record and via /yoast/v1/get_head. - id: oembed-1.0 conforms: false evidence: >- The oembed/1.0 namespace is registered, but GET /oembed/1.0/embed for the site home returned 404 on this host - the provider endpoint does not resolve site URLs. - id: cors conforms: true evidence: >- Access-Control-Expose-Headers and Access-Control-Allow-Headers present; Vary: Origin observed. - id: tls-1.3 conforms: true evidence: security/burger-singh-domain-security.yml - TLSv1.3 negotiated on www.burgersinghonline.com. - id: hsts conforms: false evidence: No Strict-Transport-Security header on www.burgersinghonline.com. - id: dnssec conforms: false evidence: No DNSSEC on burgersinghonline.com. - id: dmarc conforms: false evidence: No DMARC record on burgersinghonline.com (SPF is present). compliance_program: published: false certifications: [] evidence: >- No trust center, no compliance page, no named certification (SOC 2 / ISO 27001 / PCI DSS / HIPAA / FedRAMP) found on burgersinghonline.com. probe-security-programs.py returned vdp=none trust=none. x-evidence: fetched: '2026-08-08' host: https://www.burgersinghonline.com