generated: '2026-08-12' method: derived source: >- openapi/flare-therapeutics-content-openapi.yml + live probes of https://www.flaretx.com on 2026-08-12 note: >- Cross-cutting standards conformance for the only public API surface Flare Therapeutics exposes. Flare Therapeutics makes no published compliance claims of any kind — no trust center, no SOC 2 / ISO 27001 / HIPAA statement, no certifications page — so no `Compliance` and no `TrustCenter` pointer is emitted in apis.yml. Every entry below is derived from the deployed contract, not from a provider assertion. standards: - id: openapi-3.1 conforms: true evidence: >- openapi/flare-therapeutics-content-openapi.yml is an API Evangelist derivation, not a provider publication. Flare Therapeutics itself publishes no OpenAPI. published_by_provider: false - id: wordpress-rest-api-v2 conforms: true evidence: >- The /wp-json/ index declares the wp/v2 namespace (106 routes) and every modelled route matches the upstream WordPress REST contract documented at https://developer.wordpress.org/rest-api/. - id: oembed-1.0 conforms: true evidence: >- /oembed/1.0/embed returns a valid oEmbed 1.0 rich response with version, provider_name "Flare Therapeutics", provider_url, author_name, title, html and thumbnail fields. - id: rfc8288-web-linking conforms: true evidence: >- Collection responses carry a Link header with rel="next"/rel="prev"; objects carry HAL-style _links relations to self, author, replies and terms. - id: rfc9457-problem-details conforms: false evidence: >- Errors use the WordPress envelope {code, message, data:{status}} served as application/json. No type URI, no application/problem+json. See errors/flare-therapeutics-problem-types.yml. - id: oauth2 conforms: false evidence: >- No oauth2 security scheme. The only provider advertised in the /wp-json/ index authentication object is WordPress application passwords over HTTP Basic. - id: oidc conforms: false evidence: /.well-known/openid-configuration returned 404. - id: rfc8414-oauth-authorization-server-metadata conforms: false evidence: /.well-known/oauth-authorization-server returned 404. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returned 404 (bare nginx 404, not the WordPress 404 handler). - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog returned 404. - id: a2a-agent-card conforms: false evidence: >- Both /.well-known/agent-card.json (A2A 1.0.0 canonical) and /.well-known/agent.json (pre-0.3 legacy) returned 404. No a2a/ artifact is written. - id: llms-txt conforms: false evidence: >- /llms.txt returned 404. The llms/flare-therapeutics-llms.txt in this repo is an API Evangelist generation, not a provider publication. - id: model-context-protocol conforms: false gated: true evidence: >- The site registers the WordPress core Abilities API at /wp-json/wp-abilities/v1/ (6 routes), which is the closest thing on the deployment to an agent surface. Every route returned 401 rest_forbidden anonymously, and a JSON-RPC {"jsonrpc":"2.0","id":1,"method":"tools/list"} POST returned 404 rest_no_route. /mcp and /wp-json/graphql both returned 404. It is a WordPress core administrative surface bound to an authenticated user, not an agent endpoint Flare Therapeutics publishes for consumers. No MCPServer pointer is emitted and no tool list is derived — the live schema is auth-gated and inventing one would fabricate an agent posture this provider does not have. - id: graphql conforms: false evidence: /graphql, /wp-json/graphql and /wp-json/wp/v2/graphql all returned 404. No GraphQL namespace is registered. - id: rate-limit-headers conforms: false evidence: No RateLimit-* or X-RateLimit-* headers on any /wp-json response; no 429 observed. - id: idempotency conforms: false evidence: No idempotency key, no request deduplication contract, no anonymous write surface. - id: cors conforms: partial evidence: >- Access-Control-Allow-Headers advertises Authorization, X-WP-Nonce, Content-Disposition, Content-MD5 and Content-Type; Access-Control-Expose-Headers advertises X-WP-Total, X-WP-TotalPages and Link. No Access-Control-Allow-Origin is emitted on an anonymous cross-origin GET, so a browser client cannot actually read the response. - id: tls-1.3 conforms: true evidence: TLSv1.3 negotiated on www.flaretx.com; see security/flare-therapeutics-domain-security.yml. - id: hsts conforms: true evidence: Strict-Transport-Security present with max-age 63072000 (two years). - id: dnssec conforms: false evidence: No DNSSEC on flaretx.com. - id: caa conforms: false evidence: No CAA records on flaretx.com. - id: spf conforms: true evidence: SPF record published for flaretx.com. - id: dmarc conforms: partial evidence: >- A DMARC record is published with p=quarantine — enforcing, but not the p=reject end state. See security/flare-therapeutics-domain-security.yml. rejected_contracts: - url: https://raw.githubusercontent.com/FlareTx/api/master/src/specs/api.v2.yaml http_status: 200 parses_as: OpenAPI 3.0.0 decision: NOT SAVED — ownership check failed evidence: >- info.contact.name is "Cellenics"; the license URL is https://github.com/hms-dbmi-cellenics/api/blob/master/LICENSE; servers is `- url: /v2`, a relative path naming no host. FlareTx/api is a stale fork of hms-dbmi-cellenics/api, the open-source Cellenics/Biomage single-cell analysis platform. No Flare host serves it (api.flaretx.com is NXDOMAIN). Recorded here so a later round does not re-discover and adopt it. regulatory_context: note: >- Flare Therapeutics is a clinical-stage biotechnology company. It is subject to FDA regulation of its investigational products — FX-111 received IND clearance ahead of a Q3 2026 clinical start, and FX-909 is in clinical development in advanced urothelial cancer — but that is drug-development regulation, not API or data-processing regulation, and it confers nothing on the public content API catalogued here. The site publishes a Privacy Policy and Terms of Use; neither describes an API, a data-processing agreement or a compliance certification. No HIPAA, GDPR, SOC 2 or ISO 27001 claim is published anywhere on the public surface, and none is asserted on the company's behalf.