generated: '2026-08-12' method: probed source: live GET of /.well-known/* across every Elephas host discovered in STEP 0b summary: 'One real hit. The corporate site and the portal SPA serve nothing at /.well-known/ — and the portal is an Angular catch-all that answers HTTP 200 with the same 20,679-byte HTML shell for EVERY path, which is a false positive, not a document. The one genuine well-known document is the OpenID Connect discovery metadata published by the company-controlled Azure AD B2C identity host na.login.elephas.com, found by reading the portal''s runtime config at /assets/config/config.json.' hosts: - host: https://elephas.com documents: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - path: /llms.txt status: 404 - host: https://portal.elephas.com note: 'ANGULAR SPA CATCH-ALL — every path below returned HTTP 200 with the identical text/html application shell (20,679 bytes, Elephas Portal). NONE of these is a document. Recorded as misses.' documents: - path: /.well-known/security.txt status: 200 served: html-spa-shell document: false - path: /.well-known/openid-configuration status: 200 served: html-spa-shell document: false - path: /.well-known/oauth-authorization-server status: 200 served: html-spa-shell document: false - path: /.well-known/agent-card.json status: 200 served: html-spa-shell document: false - path: /.well-known/agent.json status: 200 served: html-spa-shell document: false - path: /assets/config/config.json status: 200 served: application/json document: true note: 'Not a well-known path, but the real discovery lead — the SPA''s runtime config names the API host (portal.elephasapis.com) and the Azure AD B2C tenant, policy and identity host.' - host: https://portal.elephasapis.com note: 'Every path, including /.well-known/*, returns HTTP 401 with WWW-Authenticate: Bearer. The API is auth-gated end to end.' documents: - path: /.well-known/security.txt status: 401 - path: /.well-known/openid-configuration status: 401 - path: /.well-known/oauth-authorization-server status: 401 - path: /.well-known/oauth-protected-resource status: 401 - path: /.well-known/api-catalog status: 401 - path: /.well-known/agent-card.json status: 401 - path: /.well-known/agent.json status: 401 - host: https://na.login.elephas.com note: Azure AD B2C custom-domain identity host for the Elephas tenant. documents: - path: /bf865bf1-740f-49ec-922c-9b2c233faa13/B2C_1A_SMART_HRD_SUSI/v2.0/.well-known/openid-configuration status: 200 content_type: application/json document: true file: elephas-biosciences-openid-configuration.json - path: /.well-known/openid-configuration status: 404 note: B2C requires the tenant + policy prefix; the bare root path is not served. hits: 1 security_txt: false agent_card: false