generated: '2026-08-12'
method: probed
source: live GET of /.well-known/* across every Elephas host discovered in STEP 0b
summary: 'One real hit. The corporate site and the portal SPA serve nothing at
/.well-known/ — and the portal is an Angular catch-all that answers HTTP 200 with
the same 20,679-byte HTML shell for EVERY path, which is a false positive, not a
document. The one genuine well-known document is the OpenID Connect discovery
metadata published by the company-controlled Azure AD B2C identity host
na.login.elephas.com, found by reading the portal''s runtime config at
/assets/config/config.json.'
hosts:
- host: https://elephas.com
documents:
- path: /.well-known/security.txt
status: 404
- path: /.well-known/openid-configuration
status: 404
- path: /.well-known/oauth-authorization-server
status: 404
- path: /.well-known/api-catalog
status: 404
- path: /.well-known/ai-plugin.json
status: 404
- path: /.well-known/agent-card.json
status: 404
- path: /.well-known/agent.json
status: 404
- path: /llms.txt
status: 404
- host: https://portal.elephas.com
note: 'ANGULAR SPA CATCH-ALL — every path below returned HTTP 200 with the
identical text/html application shell (20,679 bytes,
Elephas
Portal). NONE of these is a document. Recorded as misses.'
documents:
- path: /.well-known/security.txt
status: 200
served: html-spa-shell
document: false
- path: /.well-known/openid-configuration
status: 200
served: html-spa-shell
document: false
- path: /.well-known/oauth-authorization-server
status: 200
served: html-spa-shell
document: false
- path: /.well-known/agent-card.json
status: 200
served: html-spa-shell
document: false
- path: /.well-known/agent.json
status: 200
served: html-spa-shell
document: false
- path: /assets/config/config.json
status: 200
served: application/json
document: true
note: 'Not a well-known path, but the real discovery lead — the SPA''s runtime
config names the API host (portal.elephasapis.com) and the Azure AD B2C
tenant, policy and identity host.'
- host: https://portal.elephasapis.com
note: 'Every path, including /.well-known/*, returns HTTP 401 with
WWW-Authenticate: Bearer. The API is auth-gated end to end.'
documents:
- path: /.well-known/security.txt
status: 401
- path: /.well-known/openid-configuration
status: 401
- path: /.well-known/oauth-authorization-server
status: 401
- path: /.well-known/oauth-protected-resource
status: 401
- path: /.well-known/api-catalog
status: 401
- path: /.well-known/agent-card.json
status: 401
- path: /.well-known/agent.json
status: 401
- host: https://na.login.elephas.com
note: Azure AD B2C custom-domain identity host for the Elephas tenant.
documents:
- path: /bf865bf1-740f-49ec-922c-9b2c233faa13/B2C_1A_SMART_HRD_SUSI/v2.0/.well-known/openid-configuration
status: 200
content_type: application/json
document: true
file: elephas-biosciences-openid-configuration.json
- path: /.well-known/openid-configuration
status: 404
note: B2C requires the tenant + policy prefix; the bare root path is not served.
hits: 1
security_txt: false
agent_card: false