generated: '2026-09-04' method: probed source: >- Live probes of https://api.groupon.com and every Groupon host, 2026-09-04. No readable contract exists to assert conformance from, so every entry below is an observation, and the false ones are observed-false, not assumed-false. description: >- Cross-cutting and domain standards conformance for Groupon. Groupon's market — local-commerce marketplace, bookable appointments, tours and attractions — does have candidate domain standards (OCTO, the Open Connectivity for Tours, Activities and Attractions bookings API, is the obvious one for the Tours and Attractions integration). NONE could be checked: Groupon's own OpenAPI is published only behind a Cloudflare managed bot challenge that returns 403 to every automated client, including the Internet Archive. domain_standard_conformance is therefore left UNASSERTED rather than declared false or invented — the check is reward-only and an unverifiable claim would be worse than a gap. conformance: - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: >- https://api.groupon.com/v2/deals.json returns content-type "application/json; charset=utf-8" with body {"error":{"httpCode":401,"message":"'client_id' is invalid"}} — not application/problem+json, and carrying none of type/title/detail/status/instance. Observed 2026-09-04. - id: oauth2 name: OAuth 2.0 conforms: false evidence: >- No /.well-known/oauth-authorization-server on any host (404 on www and apex, 401 on the gateway), no WWW-Authenticate challenge on any 401, and the gateway names a client_id query parameter rather than a bearer token. Observed 2026-09-04. - id: oidc name: OpenID Connect conforms: false evidence: >- https://www.groupon.com/.well-known/openid-configuration returns 404; https://api.groupon.com/.well-known/openid-configuration returns the gateway 401. Observed 2026-09-04. - id: rfc8594 name: RFC 8594 Sunset HTTP Header conforms: false evidence: >- No Sunset or Deprecation header on any observed response, including on the retired partner-api.groupon.com host, which simply 522s. Observed 2026-09-04. - id: content-signals name: Cloudflare Content Signals Policy (robots.txt AI-use signalling) conforms: true evidence: >- https://www.groupon.com/robots.txt (HTTP 200, fetched 2026-09-04) serves a full Content Signals preamble and the directive "Content-Signal: search=yes,ai-train=no" for User-agent: *, with an explicit Article 4 EU DSM reservation of rights. Saved verbatim at well-known/groupon-robots.txt. - id: llmstxt name: llms.txt conforms: true evidence: >- https://www.groupon.com/llms.txt (HTTP 200, fetched 2026-09-04) is a well-formed llms.txt — H1 title, blockquote summary, sectioned link lists, and a "Last updated: 2026-09-01" line. Saved verbatim at llms/groupon-llms.txt. unasserted: - id: domain_standard_conformance reason: >- Groupon's Tours and Attractions integration is in OCTO's market, and its Bookable Appointments integration is in the scheduling-standards market, but the contracts that would carry a standard's signature (a schema URN, a declared conformance class, a standard-shaped path or message type) are published only behind a bot challenge. Not checkable, therefore not asserted in either direction. probed: - url: https://www.groupon.com/developers/api-reference http_status: 403 fetched: '2026-09-04' - url: https://www.groupon.com/developers-docs/tours-and-attractions http_status: 403 fetched: '2026-09-04' compliance_certifications: published: false note: >- No trust center and no published certification list (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP) was found on any Groupon host. probe-security-programs.py returned trust=none for this slug on 2026-09-04. No Compliance pointer is emitted.