generated: '2026-09-13' method: probed source: live discovery documents fetched from hearthnhome.com on 2026-09-13 note: >- Every entry below is asserted from a document fetched live, not from a marketing claim. HNI Corporation makes no compliance or certification claims on any public host we could reach, so no Compliance pointer was emitted. conformance: - id: mcp name: Model Context Protocol (JSON-RPC 2.0 tools transport) conforms: true evidence: >- POST https://hearthnhome.com/api/ucp/mcp with {"jsonrpc":"2.0","id":1,"method":"tools/list"} returned HTTP 200 and a well-formed JSON-RPC result containing 13 tools, each with a 2020-12 JSON Schema inputSchema. probed: '2026-09-13' - id: oidc name: OpenID Connect Discovery 1.0 conforms: true evidence: >- https://hearthnhome.com/.well-known/openid-configuration returned HTTP 200 with issuer, authorization_endpoint, token_endpoint, jwks_uri, response_types_supported and id_token_signing_alg_values_supported. probed: '2026-09-13' - id: oauth2 name: OAuth 2.0 Authorization Code with PKCE conforms: true evidence: >- Authorization server metadata advertises response_types_supported ["code"], code_challenge_methods_supported ["S256"] and grant_types_supported including authorization_code and refresh_token. probed: '2026-09-13' - id: rfc8414 name: RFC 8414 OAuth 2.0 Authorization Server Metadata conforms: true evidence: https://hearthnhome.com/.well-known/oauth-authorization-server returned HTTP 200 with a conformant metadata document. probed: '2026-09-13' - id: rfc9728 name: RFC 9728 OAuth 2.0 Protected Resource Metadata conforms: true evidence: >- https://hearthnhome.com/.well-known/oauth-protected-resource returned HTTP 200 with resource https://hearthnhome.com, authorization_servers naming the Shopify issuer, and bearer_methods_supported ["header"]. probed: '2026-09-13' - id: json-schema-2020-12 name: JSON Schema draft 2020-12 conforms: true evidence: >- Every one of the 13 MCP tool inputSchema objects declares $schema https://json-schema.org/draft/2020-12/schema. probed: '2026-09-13' - id: iso4217 name: ISO 4217 currency minor units conforms: true evidence: >- All UCP money values are integers in ISO 4217 minor units paired with a currency code, stated in every price-bearing tool description. probed: '2026-09-13' - id: iso3166-1-alpha-2 name: ISO 3166-1 alpha-2 country codes conforms: true evidence: Billing and shipping address schemas require address_country in 2-letter ISO 3166-1 alpha-2 format. probed: '2026-09-13' - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: >- No application/problem+json surface exists. Errors are JSON-RPC 2.0 error objects and in-band UCP error arrays on the tool result. - id: openapi name: OpenAPI conforms: false evidence: >- No OpenAPI or Swagger document was found on www.hnicorp.com, www.hon.com, www.allsteeloffice.com, www.gunlocke.com or hearthnhome.com. The UCP service does publish an OpenRPC schema at https://ucp.dev/2026-08-25/services/shopping/mcp.openrpc.json, but that document belongs to the UCP specification, not to HNI. domain_standard: id: ucp name: Universal Commerce Protocol (ucp.dev) market: agent-driven retail commerce conforms: true declared_in_contract: true evidence: >- https://hearthnhome.com/.well-known/ucp returns a UCP merchant profile declaring ucp.version 2026-08-25, supported_versions 2026-04-08 and 2026-01-23, a dev.ucp.shopping service with transport "mcp", and the capability URNs dev.ucp.shopping.checkout, dev.ucp.shopping.fulfillment, dev.ucp.shopping.discount, dev.ucp.shopping.cart, dev.ucp.shopping.order, dev.ucp.shopping.catalog.search and dev.ucp.shopping.catalog.lookup. This is the contract declaring the standard for its own market, not a prose claim. file: well-known/hni-hearthnhome-ucp.json probed: '2026-09-13' compliance: certifications: [] note: >- No SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP claim is published on any HNI Corporation host we could reach. probe-security-programs.py returned vdp=none trust=none on 2026-09-13. No Compliance or TrustCenter pointer was emitted.