generated: '2026-08-09' method: derived source: >- openapi/catalog-guard-api-catalog-check-openapi.json, live response headers and bodies, and https://catalogguard.noahcortezj-c.workers.dev/ documentation pages standards: - id: openapi-3.1 conforms: true evidence: >- Live document at /openapi.json declares openapi 3.1.0 with servers[] and 2 paths; parses cleanly. Saved verbatim to openapi/catalog-guard-api-catalog-check-openapi.json. - id: apisjson-0.21 conforms: true evidence: >- The provider publishes its own APIs.json 0.21 index at /apis.json declaring OpenAPI, Documentation, GettingStarted, PrivacyPolicy and TermsOfService properties. Self-published, not authored by API Evangelist. Saved to well-known/catalog-guard-api-apis-json.json. - id: json-schema-2020-12 conforms: true evidence: >- Request bodies are constrained by inline JSON Schema (oneOf, required, additionalProperties false, maxLength, maxItems) under OpenAPI 3.1, which uses JSON Schema 2020-12. - id: rfc4180-csv conforms: true evidence: >- Documented on the homepage and the UTF-8 guide as "RFC4180-style CSV: quoted commas, quotes, and multiline fields supported", with unclosed quotes and inconsistent rows failing closed rather than being coerced. - id: rfc9457-problem-details conforms: false evidence: >- Errors are application/json with a flat {schemaVersion, error:{code,message}} envelope. No application/problem+json, no type URI, title, detail or instance. - id: oauth2 conforms: false evidence: No securitySchemes in the OpenAPI; the API is unauthenticated by design. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 (control probe confirms no catch-all 200). - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation headers observed; no deprecation policy published. - id: rfc6749-idempotency-key conforms: false evidence: >- No Idempotency-Key header is accepted or documented. The endpoint is retry-safe by virtue of being stateless, but no idempotency contract is published. - id: hsts conforms: partial evidence: >- API routes return strict-transport-security max-age=31536000; includeSubDomains. The HTML routes return no HSTS header at all. - id: a2a conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json both 404. - id: mcp conforms: false evidence: No MCP endpoint; /mcp and /sse both 404. - id: llms-txt conforms: false evidence: /llms.txt returns 404. A generated one is kept at llms/catalog-guard-api-llms.txt. - id: asyncapi conforms: not-applicable evidence: >- No event, streaming or webhook surface exists. Both operations are synchronous request/response and the service holds no state to emit events about (storage "none"). This is a genuine N/A, not a gap. compliance_program: published: false certifications: [] detail: >- No SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP or comparable certification is claimed, and no trust centre exists. The provider's compliance posture is instead expressed as scope refusal: it states, in terms and inline in every API response, that it handles no credentials, no payment data, no customer data and no store connection, and that it makes no outcome guarantee. Recorded here rather than as a `type: Compliance` pointer, which would misrepresent a disclosure posture as a certification programme.