generated: '2026-08-09' method: derived source: openapi/centrexion-therapeutics-content-openapi.yml + live probes of centrexion.com on 2026-08-09 note: >- Cross-cutting standards posture for the Centrexion Therapeutics content API and the centrexion.com domain. Centrexion publishes no compliance claims, no certifications and no trust centre, so every entry below is derived from an observed artifact or an observed absence — nothing is asserted on the company's behalf. A `conforms: false` here means the standard was checked and not found; it is not an accusation, and for most of these a corporate marketing site has no reason to implement them. No `Compliance` pointer is emitted in apis.yml because no compliance programme is published to point at. standards: - id: rfc8288-web-linking conforms: true evidence: >- Paginated collections emit a Link header with rel="next" — observed on /wp/v2/pages?per_page=2. Objects also carry HAL-style `_links` relations. - id: oembed-1.0 conforms: true evidence: >- /oembed/1.0/embed returns a valid oEmbed 1.0 rich response (version, provider_name, provider_url, author_name, title, type, width, height, html) for centrexion.com URLs, and 404 oembed_invalid_url for foreign URLs. - id: cors conforms: true evidence: >- Access-Control-Allow-Headers and Access-Control-Expose-Headers (X-WP-Total, X-WP-TotalPages, Link) are sent on /wp-json responses. - id: llms-txt conforms: true evidence: >- https://centrexion.com/llms.txt returns 200 text/plain and is a well-formed llms.txt (H1, summary line, sectioned link lists). Machine-generated by the All in One SEO plugin v4.9.7.2 rather than hand-authored, and it indexes site pages only — it says nothing about the API. Verified as a real document, not a soft-404, against a control path that returned an nginx 404. - id: iso8601-datetimes conforms: true evidence: All date fields (date, date_gmt, modified, modified_gmt) are ISO 8601 strings. - id: rfc9457-problem-details conforms: false evidence: >- Errors use the WordPress envelope {code, message, data.status} with Content-Type application/json, not application/problem+json. See errors/centrexion-therapeutics-problem-types.yml. - id: oauth2 conforms: false evidence: >- No oauth2 security scheme; /.well-known/oauth-authorization-server returns 404. The only advertised auth method is WordPress application passwords (HTTP Basic). - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 (control-verified genuine 404, not a soft 404). - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog returns 404. - id: rfc8594-sunset-header conforms: false evidence: >- No Sunset or Deprecation header is emitted, and no deprecation policy is published. See lifecycle/centrexion-therapeutics-lifecycle.yml. - id: openapi conforms: false evidence: >- Centrexion publishes no OpenAPI. /openapi.json, /openapi.yaml, /swagger.json, /api-docs and /api all return 404. The OpenAPI in this repo is an API Evangelist derivation of the published WordPress route index, not a provider artifact. - id: asyncapi conforms: false evidence: >- No event, streaming or webhook surface exists — the API is GET-only content retrieval. Not applicable to this provider rather than a gap. - id: mcp conforms: false evidence: >- No MCP server. The site does register the WordPress Abilities API (wp-abilities/v1), an agent-facing capability registry, but both /abilities and /categories returned 401 rest_forbidden anonymously, so no agent tool surface is publicly available. - id: a2a-agent-card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json both return 404 on centrexion.com and www.centrexion.com. - id: hsts conforms: false evidence: >- No Strict-Transport-Security header. HTTPS is enforced by 301 redirect only. See security/centrexion-therapeutics-domain-security.yml. - id: dnssec conforms: false evidence: No DNSSEC on centrexion.com (Register.com nameservers). - id: caa conforms: false evidence: No CAA records published for centrexion.com. - id: dmarc conforms: false evidence: >- No DMARC record at _dmarc.centrexion.com. SPF is present and strict (v=spf1 include:1xalkvunf.spf.checkpoint-spf.com -all). - id: tls13 conforms: true evidence: centrexion.com negotiates TLSv1.3; certificate valid to Oct 23 2026. - id: rate-limit-headers conforms: false evidence: >- No RateLimit, X-RateLimit or Retry-After headers observed on any probe. robots.txt requests Crawl-delay 10, which is the only published pacing expectation. - id: http-conditional-requests conforms: false evidence: >- No ETag and no Last-Modified header on collection responses, so conditional GET and cache revalidation are unavailable to clients.