generated: '2026-08-23' method: derived source: >- openapi/_original/ksq-therapeutics-content-openapi.yml and live anonymous probes of ksqtx.com on 2026-08-23. The docs surface was searched for compliance and certification claims; none exists. note: >- Cross-cutting standards this surface does and does not conform to. Every "conforms: false" below is an honest measurement of a WordPress marketing site, not a criticism of a biotech company for failing to ship API infrastructure it never claimed to ship. standards: - id: oembed name: oEmbed 1.0 conforms: true evidence: >- GET https://ksqtx.com/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fksqtx.com%2F returned HTTP 200 with a valid oEmbed 1.0 payload — version "1.0", provider_name "KSQ Therapeutics", provider_url https://ksqtx.com — on 2026-08-23. Discovery links are also emitted in page HTML. - id: rfc8288 name: Web Linking (Link header pagination) conforms: true evidence: >- Collection responses emit Link headers with rel="next"/rel="prev", alongside X-WP-Total and X-WP-TotalPages, exposed to browsers via Access-Control-Expose-Headers. - id: json-schema name: JSON Schema (draft-04 style parameter schemas) conforms: true evidence: >- Every endpoint in the route index at https://ksqtx.com/wp-json/ declares its arguments with type, enum, default, minimum and maximum. Those declarations are what openapi/ was derived from. - id: rss2 name: RSS 2.0 conforms: true evidence: https://ksqtx.com/feed/ returned HTTP 200 with a valid RSS 2.0 document on 2026-08-23. - id: sitemaps-xml name: sitemaps.org XML Sitemap 0.9 conforms: true evidence: >- https://ksqtx.com/sitemap.xml returned HTTP 200 — an All in One SEO sitemap index with child sitemaps for page, pipelines, platforms, press_release, leadership and board_of_directors. - id: llmstxt name: llms.txt conforms: true evidence: >- https://ksqtx.com/llms.txt returned HTTP 200, 51,558 bytes, generated by All in One SEO 5.0.0.1. Saved verbatim to llms/ksq-therapeutics-llms.txt. Conforms structurally — H1, sitemap section, grouped page lists with links and descriptions — but the quality is poor: several page "descriptions" are raw Divi et_pb_* shortcode markup dumped straight out of the post body rather than prose, so an LLM reading it gets builder configuration instead of a summary of the page. Recorded as conforming because it is served and parseable; flagged here because it is not useful in its current state. - id: cors name: CORS conforms: true evidence: Access-Control-Allow-Origin and Access-Control-Expose-Headers emitted by WordPress core. - id: rfc9457 name: Problem Details for HTTP APIs conforms: false evidence: >- Errors are served as application/json with the WordPress {code, message, data.status} envelope, not application/problem+json. No type URI, title or instance. See errors/. - id: oauth2 name: OAuth 2.0 conforms: false evidence: >- /.well-known/oauth-authorization-server and /.well-known/oauth-protected-resource both 404. The only advertised credential is a WordPress Application Password (HTTP Basic). - id: oidc name: OpenID Connect conforms: false evidence: /.well-known/openid-configuration returned 404 on 2026-08-23. - id: rfc9116 name: security.txt conforms: false evidence: /.well-known/security.txt returned 404 on 2026-08-23. - id: rfc9727 name: API Catalog (/.well-known/api-catalog) conforms: false evidence: /.well-known/api-catalog returned 404 on 2026-08-23. - id: rfc8594 name: Sunset / Deprecation headers conforms: false evidence: No Sunset or Deprecation header observed on any response. - id: idempotency name: Idempotency-Key conforms: false evidence: >- No idempotency mechanism. na in practice — the anonymously reachable surface is read-only. See conventions/. - id: rate-limit-headers name: RateLimit header fields (draft-ietf-httpapi-ratelimit-headers) conforms: false evidence: >- A volume-triggered block was observed live, returned as HTTP 403 with an HTML body and no RateLimit-*, X-RateLimit-* or Retry-After header. See rate-limits/. - id: asyncapi name: AsyncAPI conforms: false evidence: >- No event, streaming or webhook surface exists. WordPress webhooks are not enabled on this deployment and no event catalog is published. Not penalised — there is nothing to describe. domain_standards: sector: biotechnology / clinical-stage pharmaceutical note: >- Reward-only check. The life-sciences domain standards a clinical-stage biotech could plausibly declare in a machine-readable contract — HL7 FHIR, CDISC SDTM/ODM, ClinicalTrials.gov PRS, ORCID, Crossref/DataCite DOIs, OAI-PMH — are absent, and correctly so: this contract describes a WordPress marketing site, not a clinical, research-data or publication surface. KSQ registers its trials with ClinicalTrials.gov and publishes posters and papers, but exposes neither through an API of its own. No domain standard is asserted, and none is invented to fill the slot. declared: []