generated: '2026-08-17' method: derived source: https://nap.launchmetrics.com/docs note: >- Derived from the published NAP reference and live probes on 2026-08-17. There is no OpenAPI, vocabulary or tag set to compute against, so every assertion below is grounded in the documented prose or an observed response. `conforms: false` here means "not conformant / not present", which is a measurement, not a criticism — most of these standards are simply not applicable to a publication-search API. standards: - id: openapi conforms: false evidence: >- No OpenAPI or Swagger document is published. /openapi.json, /openapi.yaml, /swagger.json, /api-docs, /docs, /redoc and /v1/openapi.json were probed on nap., api-ter., discover-admin. and the apex host. A real OpenAPI does exist at https://api-ter.launchmetrics.com/v1/openapi.json but an anonymous GET returns HTTP 401 APP_ID_NOT_VALID, so the contract is gated, not published. - id: graphql conforms: false evidence: No /graphql surface on any Launchmetrics host; introspection could not be attempted. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface is documented anywhere in the NAP reference. - id: oauth2 conforms: false evidence: >- Authentication is an app_id query parameter plus an optional HMAC-SHA1 request signature. No authorization server, no token endpoint, no scopes. /.well-known/oauth-authorization-server 404s on nap. and 400s (MISSING_TENANT) on api-ter. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on every Launchmetrics API host. - id: rfc9457-problem-details conforms: false evidence: >- Errors use a proprietary envelope with error.code / error.message and content type application/json; charset=utf-8. No application/problem+json response was documented or observed. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 or a bot challenge on every host probed. - id: rfc9727-api-catalog conforms: partial evidence: >- https://careers.launchmetrics.com/.well-known/api-catalog returns HTTP 200 with a valid application/linkset+json document. It is generated by the Teamtailor ATS and describes the careers job feed, not the NAP APIs. See well-known/launchmetrics-well-known.yml. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header support is documented; there is no deprecation policy. - id: pagination conforms: true evidence: >- Consistent offset-based paging via start and limit across the Search and Medias services; limit_facets bounds facet buckets. No cursor paging and no documented page-size ceiling. - id: idempotency conforms: false evidence: No idempotency key, deduplication contract or retry guidance is published. - id: rate-limit-headers conforms: false evidence: >- No RateLimit-*, X-RateLimit-* or Retry-After headers are documented, and none were returned on the live /ping probes. - id: iso8601 conforms: true evidence: >- begin_date and end_date are documented as ISO 8601 with a trailing Z for UTC or an explicit UTC offset. - id: a2a conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json probed on nine hosts; every result was a 404, a 400 MISSING_TENANT, a bot challenge, or a single-page-app HTML shell. No agent card exists. - id: mcp conforms: false evidence: No MCP server; tools/list POSTs to the plausible endpoints returned 404 or did not resolve. compliance_program: published: false certifications: [] trust_center: null evidence: >- trust.launchmetrics.com and security.launchmetrics.com do not resolve. The General Terms of Use at connect.launchmetrics.com/Home/en/GeneralTerms name no SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP certification. The automated trust-center probe returned no hit. No Compliance pointer is emitted. caveat: >- The marketing site (www.launchmetrics.com) is behind a SiteGround bot challenge for our egress IP and returns HTTP 202 on every path, so a compliance page hosted only there could not be read.