generated: '2026-08-17' method: derived source: >- openapi/heuritech-*-api-openapi.yml, https://heuritech.com/.well-known/oauth-authorization-server, https://heuritech.com/.well-known/oauth-protected-resource and live response headers description: >- Standards conformance asserted only where evidence exists. The interesting result is that the strongest standards posture on the Heuritech estate belongs to surfaces Heuritech did not author: the WordPress.com platform emits RFC 8414 and RFC 9728 metadata and an RFC 9728-compliant 401 challenge. Heuritech publishes no compliance program, no certifications and no trust centre, so no `Compliance` pointer is emitted. standards: - id: oauth2 conforms: true evidence: >- RFC 6749 authorization-code flow advertised at https://heuritech.com/.well-known/oauth-authorization-server (authorization, token and revocation endpoints, code response type, refresh_token grant). - id: oauth2-pkce conforms: true evidence: 'code_challenge_methods_supported: [S256] — RFC 7636 PKCE required for the public client.' - id: rfc8414-authorization-server-metadata conforms: true evidence: /.well-known/oauth-authorization-server returns a valid RFC 8414 document, HTTP 200. - id: rfc9728-protected-resource-metadata conforms: true evidence: >- /.well-known/oauth-protected-resource returns a valid RFC 9728 document, and the MCP endpoint's 401 carries WWW-Authenticate with a resource_metadata parameter pointing at it. - id: mcp conforms: true evidence: >- Live JSON-RPC 2.0 MCP endpoint at https://heuritech.com/wp-json/mcp/mcp-oauth-server; anonymous tools/list returns the MCP-specific 401 mcp_unauthorized rather than a generic REST rejection. - id: rfc8288-web-linking conforms: true evidence: 'Collection responses carry Link: <…&page=2>; rel="next".' - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on every host. - id: rfc9457-problem-details conforms: false evidence: >- Errors are application/json with the WordPress {code, message, data:{status}} envelope, not application/problem+json. See errors/heuritech-problem-types.yml. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on every host. - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog returns 404 on every host. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header observed; no deprecation policy published. - id: a2a conforms: false evidence: >- No agent card at /.well-known/agent-card.json or /.well-known/agent.json on any host (404 on heuritech.com and api.heuritech.com; SPA catch-all rejected on market-trends.heuritech.com). - id: openapi conforms: false evidence: >- Heuritech publishes no OpenAPI. The documents in openapi/ are API Evangelist derivations of the live WordPress route index and are marked x-provider-published: false. - id: asyncapi conforms: false evidence: >- No event, streaming or webhook surface is documented or discoverable. Not penalised — Heuritech has no event surface to describe. - id: idempotency conforms: false evidence: No Idempotency-Key header or retry-safety contract anywhere on the estate. - id: pagination conforms: true evidence: >- page/per_page/offset with X-WP-Total and X-WP-TotalPages response headers, exposed to browsers via Access-Control-Expose-Headers. compliance_program: published: false certifications: [] trust_center: null note: >- No SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP claim appears anywhere on heuritech.com. The privacy policy (last updated 25 November 2018) cites French law n° 78-17 of 6 January 1978 rather than the GDPR, names no DPO and states no retention periods. trust.heuritech.com and /security/ both 404. Recorded as an absence; no `Compliance` or `TrustCenter` pointer is emitted. x-evidence: fetched: '2026-08-17' probes: - url: https://heuritech.com/.well-known/oauth-authorization-server/ status: 200 - url: https://heuritech.com/.well-known/oauth-protected-resource/ status: 200 - url: https://heuritech.com/.well-known/openid-configuration status: 404 - url: https://trust.heuritech.com/ status: 404 - url: https://heuritech.com/privacy-policy/ status: 200