generated: '2026-08-04' method: derived source: mcp/doctor-anywhere-mcp.yml, well-known/doctor-anywhere-well-known.yml, https://doctoranywhere.com/privacy-policy/ note: 'Doctor Anywhere publishes no API specification, so most cross-cutting standards cannot be evidenced either way. Only observed facts are recorded; absence is recorded as conforms: false rather than left blank.' standards: - id: mcp name: Model Context Protocol conforms: true evidence: 'Three hosts serve a JSON-RPC 2.0 MCP endpoint at /_api/mcp; anonymous tools/list returned HTTP 200 with 9 tools and an Mcp-Session-Id header on 2026-08-04.' - id: llms-txt name: llms.txt conforms: true evidence: 'doctoranywhere.co.th, www.doctoranywhere.my and doctoranywhere.co.id each serve a well-formed llms.txt (H1 + blockquote + link sections) as text/plain.' - id: openapi name: OpenAPI conforms: false evidence: 'No OpenAPI/Swagger document at /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs or /redoc on api.doctoranywhere.com or any web host.' - id: graphql name: GraphQL conforms: false evidence: '/graphql returned 404 on api.doctoranywhere.com and a catch-all redirect on the marketing hosts; no GraphQL surface found.' - id: asyncapi name: AsyncAPI conforms: false evidence: 'No public event, streaming or webhook surface is documented, so there is no event contract to describe.' - id: a2a name: A2A Agent Card conforms: false evidence: '/.well-known/agent-card.json and /.well-known/agent.json missed on every host (404/301/302/400) — see well-known/doctor-anywhere-well-known.yml.' - id: rfc9116-security-txt name: RFC 9116 security.txt conforms: false evidence: 'No /.well-known/security.txt on any Doctor Anywhere host.' - id: oauth2 name: OAuth 2.0 conforms: false evidence: 'No /.well-known/oauth-authorization-server, no documented OAuth flow, no public credential issuance.' - id: oidc name: OpenID Connect conforms: false evidence: 'No /.well-known/openid-configuration on any host.' - id: rfc9457-problem-details name: RFC 9457 Problem Details conforms: false evidence: 'No public error contract published; the MCP layer uses the JSON-RPC 2.0 error object.' - id: fhir name: HL7 FHIR conforms: false evidence: 'No FHIR endpoint, CapabilityStatement or FHIR resource shapes found on any public host, despite the healthcare domain.' - id: rfc8594-sunset name: RFC 8594 Sunset header conforms: false evidence: 'No deprecation or sunset policy published.' regulatory_posture: - id: pdpa-singapore name: Singapore Personal Data Protection Act 2012 claimed: true evidence: 'The privacy policy states personal data is handled "in accordance with the Personal Data Protection Act 2012 (\"PDPA\")" and names a data protection officer at dpo@doctoranywhere.com.' source: https://doctoranywhere.com/privacy-policy/ certifications_published: [] certifications_note: 'No SOC 2, ISO 27001, HIPAA, PCI DSS or FedRAMP claim appears on any Doctor Anywhere property. Search results asserting ISO 27001 refer to Doctor Care Anywhere (UK), a different company — not recorded here. No Compliance pointer is emitted.'