generated: '2026-08-04' method: probed source: 'anonymous HTTP probes of JobGet hosts; no OpenAPI or published compliance program exists to derive from' summary: 'JobGet asserts no standards conformance publicly and holds no published compliance program (no trust center, no SOC 2 / ISO 27001 / PCI / HIPAA claim reachable from its site). The two entries below marked conforming were established by observing JobGet''s own hosts, not by a JobGet claim. No `Compliance` pointer is wired into apis.yml because JobGet publishes no certifications or compliance posture.' standards: - id: rfc9457-problem-details name: RFC 9457 Problem Details for HTTP APIs conforms: partial evidence: 'api.jobget.com error bodies use the RFC 9457 member set (type, title, status, detail, instance) plus extensions.' deviations: - 'Served as application/json, not the registered application/problem+json media type.' - 'The `type` URI is the unreplaced placeholder https://api.example.com/errors/http-404 (IANA reserved example domain), so problem types are not dereferenceable or JobGet-identifying.' see: errors/jobget-problem-types.yml - id: mcp name: Model Context Protocol conforms: true evidence: 'JSON-RPC 2.0 tools/list against https://blog.jobget.com/_api/mcp returned HTTP 200 with a conformant result.tools array carrying inputSchema per tool.' note: 'Implemented by the Wix site platform, not authored by JobGet, but served from a JobGet host and advertised in JobGet''s llms.txt.' see: mcp/jobget-mcp.yml - id: llms-txt name: llms.txt conforms: true evidence: 'https://blog.jobget.com/llms.txt returns 200 with H1 name, blockquote summary and structured link/tool sections.' see: llms/jobget-llms.txt - id: openapi name: OpenAPI Specification conforms: false evidence: 'Probed /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs and /redoc on api.jobget.com and www.jobget.com — all 404. No spec published anywhere.' - id: graphql name: GraphQL conforms: false evidence: 'https://api.jobget.com/graphql returned 404. No GraphQL surface found.' - id: asyncapi name: AsyncAPI conforms: false evidence: No event, streaming or webhook surface is documented by JobGet. - id: a2a name: A2A Agent Card conforms: false evidence: '/.well-known/agent-card.json and /.well-known/agent.json probed on api.jobget.com, www.jobget.com, blog.jobget.com and support.jobget.com — 404 or 400 on every host. No agent card is served.' - id: oauth2 name: OAuth 2.0 conforms: false evidence: 'No oauth2 scheme documented; /.well-known/oauth-authorization-server 404.' - id: oidc name: OpenID Connect conforms: false evidence: /.well-known/openid-configuration 404 on all hosts. - id: rfc9116-security-txt name: RFC 9116 security.txt conforms: false evidence: /.well-known/security.txt absent on every host. see: well-known/jobget-well-known.yml - id: rfc9727-api-catalog name: RFC 9727 api-catalog conforms: false evidence: /.well-known/api-catalog 404 on every host. - id: rfc8594-sunset-header name: RFC 8594 Sunset header conforms: false evidence: No deprecation policy or Sunset/Deprecation header support published. - id: hsts name: HTTP Strict Transport Security conforms: partial evidence: 'HSTS present on www.jobget.com (max-age 63072000) and blog.jobget.com (max-age 31556952); absent on the API host api.jobget.com.' see: security/jobget-domain-security.yml - id: dnssec name: DNSSEC conforms: false evidence: No DNSKEY records for jobget.com. - id: dmarc name: DMARC conforms: partial evidence: 'DMARC record present but policy is p=none (monitor only), which does not enforce against spoofing.'