generated: '2026-09-13' method: probed source: >- Live probes of hpsf.io on 2026-09-13 and the two OpenAPI documents the host serves at /wp-json/tribe/events/v1/doc and /wp-json/tec/v1/docs. name: HPSF conformance conformance: - id: openapi-3.0 standard: OpenAPI Specification 3.0 conforms: true evidence: >- https://hpsf.io/wp-json/tribe/events/v1/doc declares openapi 3.0.0 with 14 paths / 30 operations; https://hpsf.io/wp-json/tec/v1/docs declares openapi 3.0.4 with 8 paths / 17 operations. Both were fetched, parsed and saved verbatim to openapi/_original/. note: >- Generated and maintained by The Events Calendar plugin, served live by HPSF's own host, and self-describing as HPSF's - servers[] names https://hpsf.io in both documents. - id: rfc9727-api-catalog standard: 'RFC 9727 - /.well-known/api-catalog and the api-catalog link relation' conforms: true evidence: >- GET https://hpsf.io/.well-known/api-catalog returns HTTP 200 with content-type application/linkset+json and a valid linkset carrying anchor, service-desc, service-doc and status members. Saved verbatim to well-known/hpsf-api-catalog.json. note: >- Confirmed to be a real document, not a catch-all 200 - every other /.well-known/ path on this host, including a negative-control path that cannot exist, returns 404. - id: rfc5545-icalendar standard: 'RFC 5545 - iCalendar' conforms: true evidence: >- GET https://hpsf.io/events/?ical=1 returns HTTP 200, content-type text/calendar, a VCALENDAR with VERSION:2.0 and PRODID naming the High Performance Software Foundation. Saved to examples/hpsf-events.ics. An Outlook-flavoured variant is served at ?outlook-ical=1. note: >- The events data is published in the interoperable calendar format for its domain as well as in JSON. A consumer that speaks iCalendar needs no bespoke connector to subscribe to HPSF's conference calendar. Recorded as a real conformance; not claimed as a contract-level domain-standard signature, because the feed is a serialization of the data, not the API contract. - id: rfc8288-web-linking standard: 'RFC 8288 - Web Linking' conforms: partial evidence: >- Responses carry Link: ; rel="https://api.w.org/", and the tec/v1 contract declares a Link response header with rel="next"/rel="prev" for pagination. note: >- Partial. The stable tribe/events/v1 surface returns pagination in the JSON body (next_rest_url), not in a Link header, so the linking convention the contract describes is not the one the live surface uses. - id: rfc7617-basic-auth standard: 'RFC 7617 - HTTP Basic authentication' conforms: true evidence: >- components.securitySchemes.BasicAuth (type http, scheme basic) in openapi/hpsf-tec-events-api-openapi.yml; the route index at https://hpsf.io/wp-json/ declares the WordPress Application Passwords authorization endpoint. note: Applies to the write half only. There is no public path to a credential. - id: rfc9457-problem-details standard: 'RFC 9457 - Problem Details for HTTP APIs' conforms: false evidence: >- Error bodies are the WordPress envelope { code, message, data.status }, served as application/json. No application/problem+json response is declared in either contract or observed on any live call. - id: llms-txt standard: llms.txt conforms: true evidence: >- GET https://hpsf.io/llms.txt returns HTTP 200, text/plain, 4135 bytes, in llms.txt format - H1 title then H2 sections for Posts, Pages, Projects, Venues, Organizers, Events, Categories, Project Stages and Optional. Saved verbatim to llms/hpsf-llms.txt. - id: content-signals standard: Content Signals Policy (robots.txt AI usage preferences) conforms: true evidence: >- https://hpsf.io/robots.txt carries "Content-Signal: ai-train=yes, search=yes, ai-input=yes". note: >- A machine-readable AI usage preference expressed by the provider. HPSF grants all three signals. - id: sitemaps-0.9 standard: 'sitemaps.org 0.9' conforms: true evidence: https://hpsf.io/wp-sitemap.xml returns HTTP 200 with a valid sitemapindex. - id: rss-2.0 standard: 'RSS 2.0' conforms: true evidence: >- https://hpsf.io/feed/ and https://hpsf.io/events/feed/ both return HTTP 200 with application/rss+xml. - id: oauth2 standard: 'OAuth 2.0 / RFC 8414' conforms: false evidence: >- https://hpsf.io/.well-known/oauth-authorization-server returns 404; https://hpsf.io/.well-known/oauth-protected-resource returns 404. No oauth2 securityScheme in either contract. - id: oidc standard: OpenID Connect Discovery conforms: false evidence: https://hpsf.io/.well-known/openid-configuration returns 404. - id: rfc9116-security-txt standard: 'RFC 9116 - security.txt' conforms: false evidence: https://hpsf.io/.well-known/security.txt returns 404 on both hpsf.io and www.hpsf.io. - id: a2a-agent-card standard: 'A2A 1.0.0 agent card' conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json both return 404 on both hosts. No a2a/ artifact was written and no AgentCard pointer is emitted. - id: apis-json standard: APIs.json conforms: false evidence: '/apis.json, /apis.yml and /.well-known/apis.json all return 404 on both hosts.' domain_standard: claimed: false note: >- REWARD-ONLY and honestly empty at contract level. HPSF operates in high performance computing, which has no REST interoperability standard an events contract could declare, and the contract is a generic WordPress events contract in any case. The iCalendar feed above is a genuine domain-format conformance for the events data and is recorded as such, but it is a serialization, not a signature inside the contract, so nothing is claimed here rather than stretching the definition to fill the slot. compliance_certifications: published: false note: >- No SOC 2, ISO 27001, PCI, HIPAA or FedRAMP claim, no audit report and no trust center. HPSF is a nonprofit foundation with no customer data platform. No Compliance or TrustCenter pointer is emitted. Verified by 0-working/probe-security-programs.py, which returned vdp=none trust=none.