generated: '2026-08-01' method: derived source: openapi/emulate-content-api-openapi.yml docs: null note: >- Derived from the observed surface. Emulate publishes no compliance or certification page — probe-security-programs.py found no trust center and no vulnerability-disclosure program — so no Compliance or TrustCenter pointer is wired in apis.yml. standards: - id: openapi conforms: false evidence: >- Emulate publishes no OpenAPI. The spec in openapi/ is derived by API Evangelist from the live route index, not published by the provider. - id: wordpress-rest-api conforms: true evidence: >- Routes are registered through the WordPress REST API framework and discoverable at /wp-json/; six first-party namespaces are declared in the index. - id: oauth2 conforms: false evidence: No oauth2 security scheme; /.well-known/oauth-authorization-server returned 404. - id: oidc conforms: false evidence: /.well-known/openid-configuration returned 404. - id: rfc9457-problem-details conforms: false evidence: >- Errors are returned as a bare {status, error} object over HTTP 200; no application/problem+json media type anywhere. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returned 404. - id: rfc8615-well-known conforms: false evidence: No /.well-known/ document of any kind returned 200. - id: rfc8594-sunset-header conforms: false evidence: No deprecation or sunset policy published; no Sunset header observed. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface found. Not applicable to this provider. - id: json-api conforms: false evidence: Responses are ad-hoc arrays and two-element envelopes, not JSON:API documents. - id: pagination conforms: false evidence: >- Collection routes accept no arguments and return whole collections (up to ~1 MB); no page/per_page/cursor parameter, no Link header, no total-count header. - id: idempotency conforms: false evidence: Read-only surface; no idempotency key contract documented. - id: hsts conforms: true evidence: >- emulatebio.com returns Strict-Transport-Security with max-age 63072000 (two years). See security/emulate-domain-security.yml. - id: dnssec conforms: false evidence: emulatebio.com is not DNSSEC-signed. - id: caa conforms: false evidence: No CAA record on emulatebio.com. - id: dmarc conforms: true evidence: emulatebio.com publishes DMARC with policy quarantine. regulatory_context: note: >- Emulate operates in preclinical drug development and markets its Organ-Chip platform as a New Approach Methodology aligned with the FDA Modernization Act 2.0 and the FDA and NIH programs to reduce animal testing. That is a laboratory and regulatory-science posture, not an API compliance program, and no certification (SOC 2, ISO 27001, HIPAA, GDPR statement of controls) is published on the site. Recorded here as context only — it is not asserted as API conformance.