generated: '2026-08-13' method: searched source: >- openapi/_original/hilos-openapi-original.yml + https://hilos.io/docs/developer/getting-started/* + live probes of /.well-known/* and https://hilos-40.mintlify.app/mcp standards: - id: oauth2 conforms: false evidence: 'API uses a static API key (Authorization: Token), no oauth2 securityScheme' - id: openid-connect conforms: false evidence: /.well-known/openid-configuration 404s on api.hilos.io and hilos.io - id: api-key-auth conforms: true evidence: 'securitySchemes.tokenAuth: apiKey in header Authorization with Token prefix' - id: rfc9457-problem-details conforms: false evidence: errors returned as plain JSON, not application/problem+json - id: offset-pagination conforms: true evidence: page + page_size query parameters documented at /docs/developer/getting-started/pagination - id: idempotency conforms: false evidence: no idempotency-key header documented and none present in the OpenAPI - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt 404s on every Hilos host - id: openapi-3 conforms: true evidence: provider publishes OpenAPI 3.0.3 at /docs/developer/apidocs/schema.yml via Mintlify - id: llms-txt conforms: true evidence: 'https://hilos-40.mintlify.app/llms.txt returns 200 text/plain, 162 lines, full docs index' - id: mcp conforms: true partial: true evidence: >- Anonymous MCP server at https://hilos-40.mintlify.app/mcp answers tools/list with 3 tools, and /.well-known/mcp.json declares it. Documentation scope only — the REST API is not exposed over MCP. - id: a2a conforms: false partial: true evidence: >- An A2A agent card is served at https://hilos-40.mintlify.app/.well-known/agent-card.json but grades `flavored` against A2A 1.0.0 (supportedInterfaces instead of additionalInterfaces, zero skills). See a2a/hilos-a2a.yml. - id: asyncapi conforms: false evidence: no AsyncAPI document and no first-party webhook surface; see asyncapi/hilos-events.yml - id: whatsapp-cloud-api conforms: true evidence: built on WhatsApp Cloud API; template send + management endpoints, Meta messaging limits documented compliance_program: published: false certifications: [] note: >- No trust center, no security page and no named certifications (SOC 2 / ISO 27001 / PCI / HIPAA / GDPR) were found by probe-security-programs.py or by search. hilos.io/security and hilos.io/trust both 404. No `Compliance` pointer is wired.