generated: '2026-08-25' method: probed source: >- https://traced.life/.well-known/ucp, https://traced.life/.well-known/openid-configuration, https://traced.life/.well-known/oauth-authorization-server, https://traced.life/.well-known/oauth-protected-resource, https://traced.life/api/ucp/mcp, https://www.clearstrandasd.com/hcps/hcps summary: >- Two separate conformance stories. LinusBio's corporate and clinical surface conforms to healthcare LABORATORY regulation (CLIA) and publishes its certificate number, but publishes no API standard of any kind because it publishes no API. The Traced storefront conforms to a real, current agentic-commerce domain standard — Universal Commerce Protocol 2026-04-08 over MCP — plus the OAuth/OIDC discovery RFC stack, all inherited from the Shopify platform. standards: - id: ucp name: Universal Commerce Protocol version: '2026-04-08' conforms: true domain_standard: true market: agentic commerce / retail checkout evidence: location: https://traced.life/.well-known/ucp http_status: 200 signature: >- ucp.version = "2026-04-08"; services["dev.ucp.shopping"] declares transport "mcp" with endpoint https://traced-life.myshopify.com/api/ucp/mcp; capabilities declare dev.ucp.shopping.checkout, .cart, .fulfillment, .discount, .order, .catalog.search and .catalog.lookup, each bound to a published ucp.dev schema URL. saved: well-known/linusbio-traced-ucp.json note: >- This is the domain-standard signature for this provider's commerce surface. An agent that already speaks UCP can transact with the Traced store with no bespoke connector. - id: mcp name: Model Context Protocol conforms: true evidence: location: https://traced.life/api/ucp/mcp http_status: 200 signature: >- Anonymous JSON-RPC 2.0 POST of {"method":"tools/list"} returned a well-formed MCP result with 13 tools, each carrying name, description and inputSchema. saved: mcp/linusbio-traced-mcp-tools-list.json - id: json-schema-2020-12 name: JSON Schema 2020-12 conforms: true evidence: location: https://traced.life/api/ucp/mcp signature: >- Every tool inputSchema declares "$schema": "https://json-schema.org/draft/2020-12/schema". - id: oauth2 name: OAuth 2.0 conforms: true evidence: location: https://traced.life/.well-known/oauth-authorization-server http_status: 200 signature: >- authorization_code and refresh_token grants, S256 PKCE, client_secret_basic and client_secret_post token endpoint auth. - id: oidc name: OpenID Connect Discovery 1.0 conforms: true evidence: location: https://traced.life/.well-known/openid-configuration http_status: 200 signature: >- issuer https://shopify.com/authentication/70566805578, RS256 id_token signing, jwks_uri published, claims_supported includes sub/iss/aud/exp/iat/nonce/sid. - id: rfc8414 name: 'RFC 8414: OAuth 2.0 Authorization Server Metadata' conforms: true evidence: location: https://traced.life/.well-known/oauth-authorization-server http_status: 200 - id: rfc9728 name: 'RFC 9728: OAuth 2.0 Protected Resource Metadata' conforms: true evidence: location: https://traced.life/.well-known/oauth-protected-resource http_status: 200 signature: >- resource = https://traced.life; authorization_servers lists account.traced.life and shopify.com; bearer_methods_supported = ["header"]. - id: rfc9457 name: 'RFC 9457: Problem Details for HTTP APIs' conforms: false evidence: note: >- No application/problem+json surface published. Errors on the MCP endpoint follow the JSON-RPC 2.0 error object shape. - id: rfc9116 name: 'RFC 9116: security.txt' conforms: false evidence: note: >- /.well-known/security.txt returned 404 on www.linusbio.com, www.clearstrandasd.com and traced.life. - id: rfc8594 name: 'RFC 8594: Sunset header' conforms: false evidence: note: No Sunset or Deprecation header observed; no deprecation policy published. - id: hl7-fhir name: HL7 FHIR conforms: false evidence: note: >- LinusBio is a CLIA laboratory producing test results, which is exactly the market where FHIR (DiagnosticReport / Observation) is the domain standard. No FHIR endpoint, resource profile or implementation guide is published on any probed host, and results are delivered to caregivers through a telehealth patient portal rather than an interoperable interface. Recorded as an honest miss, not a penalty. compliance: - id: clia name: Clinical Laboratory Improvement Amendments (CLIA) status: certified identifier: 'CLIA #31d2307499' scope: The LinusBio laboratory performing ClearStrand-ASD. evidence: url: https://www.clearstrandasd.com/hcps/hcps http_status: 200 quote: 'The test is performed by the LinusBio CLIA-certified laboratory (CLIA #31d2307499)' - id: fda-breakthrough-device name: FDA Breakthrough Device Designation status: designated scope: StrandDx-ASD (now ClearStrand-ASD) exposome sequencing diagnostic. evidence: url: https://www.linusbio.com/news/linus-biotechnology-inc-receives-fda-breakthrough-device-designation-for-stranddx-asd-exposome-sequencing-diagnostic caveat: >- Breakthrough Device Designation is not clearance or approval. The provider's own HCP page states ClearStrand-ASD "has not been cleared or approved by the US Food and Drug Administration (FDA)" and is "Rx only". Both facts are recorded so neither is overstated. - id: ldt name: Laboratory Developed Test status: operating-as evidence: url: https://www.clearstrandasd.com/hcps/hcps note: >- Run as an LDT in a CLIA-certified lab, ordered by a licensed health care provider. not_published: - SOC 2 - ISO 27001 - HITRUST - HIPAA attestation or business associate agreement terms on any public page - Any trust center (trust.linusbio.com returns the wildcard marketing homepage, not a trust page)