generated: '2026-08-12' method: derived source: >- openapi/_original/ethyreal-bio-content-openapi.yml, live response headers, and the /.well-known/ probe recorded in well-known/ethyreal-bio-well-known.yml, 2026-08-12. note: >- Every assertion below is derived from the observed surface. Ethyreal Bio publishes no compliance claims, no certifications and no trust centre, so NO Compliance pointer was written into apis.yml — Conformance here asserts protocol behaviour, not a published compliance programme. standards: - id: openapi-3.1 conforms: true evidence: >- openapi/_original/ethyreal-bio-content-openapi.yml is a valid OpenAPI 3.1.0 document; the per-tag documents in openapi/ are OpenAPI 3.2.0. Both were derived by API Evangelist from the provider's route descriptor — Ethyreal Bio itself publishes no OpenAPI. provider_published: false - id: rfc8288-web-linking conforms: true evidence: >- Link header with rel="next" observed on /wp/v2/posts?per_page=1, and Access-Control-Expose-Headers advertises Link for cross-origin readers. - id: hal-style-hypermedia conforms: partial evidence: >- Resources carry a _links object with self/collection/about relations and targetHints.allow. This is WordPress's own convention, close to but not formally HAL. - id: rfc9457-problem-details conforms: false evidence: >- Errors use the WordPress WP_Error envelope ({code, message, data.status}) with content-type application/json. No application/problem+json, no type URI, no title member. - id: rfc7617-http-basic conforms: true evidence: >- Write operations authenticate with WordPress Application Passwords over HTTP Basic; the authorization endpoint is advertised in the route index at /wp-json/. - id: oauth2 conforms: false evidence: No oauth2 securityScheme in any spec; /.well-known/oauth-authorization-server returns 404. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on both www and apex hosts. - id: rfc8615-well-known conforms: false evidence: >- No /.well-known/ document is served at all — ten paths probed, ten 404s. See well-known/ethyreal-bio-well-known.yml. - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog returns 404. - id: a2a-agent-card conforms: false evidence: >- Both /.well-known/agent-card.json and the legacy /.well-known/agent.json return 404. No a2a/ artifact was written, as this pipeline never authors an agent card on a provider's behalf. - id: mcp conforms: false evidence: >- No "mcp" namespace in the route index and no MCP endpoint on any host. The adjacent wp-abilities/v1 registry is present but returns 401 anonymously. - id: llms-txt conforms: false evidence: >- /llms.txt returns 404. The file in llms/ was generated by API Evangelist, not published by Ethyreal Bio. - id: asyncapi conforms: false evidence: >- No event, streaming or webhook surface exists on this host, so there is nothing an AsyncAPI could describe. Not a gap — a clinical-stage biotech marketing site has no events to emit. applicable: false - id: rate-limit-headers conforms: false evidence: No RateLimit-* or X-RateLimit-* headers observed on any response. - id: cors conforms: true evidence: >- Access-Control-Allow-Headers and Access-Control-Expose-Headers are returned, exposing X-WP-Total, X-WP-TotalPages and Link to browser clients. - id: hsts conforms: false evidence: >- No Strict-Transport-Security header on www.ethyrealbio.com. See security/ethyreal-bio-domain-security.yml. - id: dnssec conforms: false evidence: ethyrealbio.com is not DNSSEC-signed; no CAA records are published. - id: spf conforms: true evidence: An SPF record is published for ethyrealbio.com. - id: dmarc conforms: false evidence: No DMARC record is published for ethyrealbio.com. regulatory_context: note: >- Ethyreal Bio operates in a regulated sector (US clinical-stage biopharma, FDA-regulated investigational products), and it publishes the disclosure this stage requires — an Expanded Access Policy, as expected of a sponsor of investigational drugs. That is a regulatory disclosure on the website, NOT an API compliance programme, and it is deliberately not counted as one here. expanded_access_policy: https://www.ethyrealbio.com/expanded-access-policy/ certifications_published: [] certifications_note: >- No SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP or GDPR attestation is published anywhere on ethyrealbio.com, and probe-security-programs.py found no trust centre (trust.ethyrealbio.com and security.ethyrealbio.com are both NXDOMAIN).