generated: '2026-08-17' method: derived source: >- openapi/habiteo-*-openapi.yml, conventions/habiteo-conventions.yml, errors/habiteo-problem-types.yml, security/habiteo-domain-security.yml and live anonymous probes of www.habiteo.com run 2026-08-17. Habiteo publishes no conformance, certification or compliance claims of its own on any public page. scope: >- Assertions about the WordPress REST surface Habiteo's marketing site exposes. Habiteo's own products have no published contract, so nothing here speaks to myHabiteo, the Configurateur or the MegaWidget. standards: - id: openapi conforms: false evidence: >- No OpenAPI is published by Habiteo at any probed location on www.habiteo.com, api.habiteo.com, my.habiteo.com or megawidget.habiteo.com. The OpenAPI documents in this repo were derived by API Evangelist from the live WordPress route index and are marked x-provider-published: false. - id: rest conforms: true evidence: >- Resource-oriented paths, HTTP verbs, JSON representations, HTTP status semantics, and a HAL-like _links block on every resource (WordPress REST API defaults). - id: rfc9457 conforms: false evidence: >- Errors use the WordPress envelope {"code","message","data":{"status"}} with content-type application/json, not application/problem+json. See errors/habiteo-problem-types.yml. - id: rfc8288 conforms: true evidence: >- 'Observed on GET /wp-json/wp/v2/posts?per_page=1: link: <...page=2>; rel="next".' - id: pagination conforms: true evidence: >- page + per_page (max 100) with X-WP-Total and X-WP-TotalPages response headers, both exposed cross-origin via Access-Control-Expose-Headers. - id: idempotency conforms: false evidence: No Idempotency-Key header or idempotent-retry contract is offered or documented. - id: oauth2 conforms: false evidence: >- No oauth2 securityScheme anywhere; /.well-known/oauth-authorization-server 404s on every host (see well-known/habiteo-well-known.yml). Writes use HTTP Basic Application Passwords. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on www.habiteo.com and my.habiteo.com. - id: asyncapi conforms: false evidence: >- No event, streaming or webhook surface is published. /asyncapi.yaml 404s. N/A rather than a failure — a 3D visualization and CMS surface has no advertised event stream. - id: mcp conforms: false evidence: >- No MCP server is published or advertised. No /mcp endpoint, no llms.txt tool list, no provider-published agent surface of any kind. - id: a2a conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json return 404 on www.habiteo.com and my.habiteo.com, and a soft-200 SPA shell on megawidget.habiteo.com. No agent card exists. - id: tls conforms: true evidence: 'TLS 1.3 on www.habiteo.com; certificate valid to 2026-12-16 (probed).' - id: hsts conforms: false evidence: No Strict-Transport-Security header on www.habiteo.com (probed 2026-08-17). - id: dnssec conforms: false evidence: habiteo.com is not DNSSEC-signed (probed). - id: caa conforms: false evidence: No CAA record on habiteo.com (probed). - id: spf conforms: true evidence: SPF record present on habiteo.com (probed). - id: dmarc conforms: partial evidence: 'DMARC record present with p=none — reporting only, no enforcement (probed).' - id: security-txt conforms: false evidence: /.well-known/security.txt returns 404 on every Habiteo host probed. compliance_claims: published: false detail: >- No SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP claim, no trust centre and no security page were found on any Habiteo property. GDPR is addressed only in the French mentions-legales and CGV pages as legal prose, with no certification named. NO `Compliance` pointer is wired in apis.yml, because there is no published programme to point at.