generated: '2026-07-27' method: probed source: anonymous HTTP probes of every host in apis.yml and the OpenAPI servers[] block description: 'ISO New England serves NO /.well-known documents on any host. Twenty probes across the corporate host and the API host all returned 404 on 2026-07-27, including robots.txt. Absence is the result, and it is recorded as data: there is no security.txt (RFC 9116), no OIDC or OAuth discovery, no api-catalog (RFC 9727), and no AI-plugin or MCP descriptor. No file is saved because no document was served.' hosts_probed: - https://www.iso-ne.com - https://webservices.iso-ne.com files_saved: [] consequence: Nothing in the /.well-known space can be used to discover ISO New England's API, its auth server, or a vulnerability-disclosure contact. Discovery is entirely through the human documentation at https://www.iso-ne.com/participate/support/web-services-data and https://webservices.iso-ne.com/docs/v1.1/. hosts: - host: '' documents: - path: /.well-known/security.txt status: www.iso-ne.com: 404 webservices.iso-ne.com: 404 - path: /.well-known/openid-configuration status: www.iso-ne.com: 404 webservices.iso-ne.com: 404 - path: /.well-known/oauth-authorization-server status: www.iso-ne.com: 404 webservices.iso-ne.com: 404 - path: /.well-known/oauth-protected-resource status: www.iso-ne.com: 404 webservices.iso-ne.com: 404 - path: /.well-known/api-catalog status: www.iso-ne.com: 404 webservices.iso-ne.com: 404 - path: /.well-known/ai-plugin.json status: www.iso-ne.com: 404 webservices.iso-ne.com: 404 - path: /.well-known/mcp.json status: www.iso-ne.com: 404 webservices.iso-ne.com: 404 - path: /.well-known/dnt-policy.txt status: www.iso-ne.com: 404 webservices.iso-ne.com: 404 x-shape-fix: converted: '2026-08-20' from: documents note: Rewritten into hosts[] -> documents[], the only shape well_known_docs() in score.rb reads. A served .well-known surface recorded in any other shape scores as absent.