generated: '2026-08-01' method: searched source: Finless Foods public statements and trade-press coverage (2026-08-01 web search) scope: >- Finless Foods publishes no API, so there are no API or cross-cutting technical standards to assert. What it is actually measured against is the US food-safety regulatory pathway for cell-cultivated food. That pathway is recorded here as the applicable regime, with its status stated honestly as in-progress rather than achieved. The API/protocol standards block below is recorded as not-applicable rather than false, so this file is never mistaken for a compliance posture the company does not claim. regulatory_regime: - id: fda-cell-cultured-food-premarket-consultation name: >- US FDA premarket consultation for food made from cultured animal cells (FDA/USDA 2019 joint framework; seafood other than Siluriformes sits with FDA) conforms: false status: in-review evidence: >- Finless Foods has been in FDA review for its cell-cultivated sashimi-grade bluefin tuna. The company had targeted clearance in 2024; as of 2026 the review is still reported as ongoing, and a June 2025 USD 1.8M note financing was raised specifically to pursue FDA approval and finalize partnerships. No FDA "no questions" letter for Finless Foods has been published. note: >- Recorded as conforms:false because clearance has not been granted, not because the company failed a check. Re-probe on the next pass. - id: usda-fsis-labeling name: USDA FSIS labeling jurisdiction for cell-cultivated products conforms: false applicable: false evidence: >- Under the 2019 FDA/USDA joint framework, USDA-FSIS labeling authority covers cell-cultured meat and poultry; seafood other than catfish remains under FDA, so this does not apply to a tuna product. api_standards: - id: openapi conforms: false applicable: false evidence: no public API contract published (see well-known/finless-foods-well-known.yml) - id: oauth2 conforms: false applicable: false - id: openid-connect conforms: false applicable: false - id: rfc9457-problem-details conforms: false applicable: false - id: asyncapi conforms: false applicable: false - id: mcp conforms: false applicable: false - id: a2a conforms: false applicable: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json both 404 on finlessfoods.com and www.finlessfoods.com - id: rfc9116-security-txt conforms: false applicable: true evidence: /.well-known/security.txt returns 404 on finlessfoods.com information_security_compliance: found: false note: >- No trust center, SOC 2, ISO 27001 or equivalent information-security certification page was found by probe-security-programs.py (vdp=none trust=none) or by search. No `Compliance` pointer is wired in apis.yml - and the FDA pathway above is a food-safety regime, not a published infosec compliance program, so it does not earn one either. domain_security_observed: source: security/finless-foods-domain-security.yml summary: >- finlessfoods.com serves TLS 1.3 with HSTS (max-age 15552000) and has DNSSEC, SPF and DMARC records present; DMARC policy is p=none (monitor only) and no CAA record is published.