generated: '2026-08-09' method: derived source: openapi/nutrientsdb-sample-api-openapi.yml + live probes + https://www.nutrientsdb.com/api/docs description: >- Cross-cutting standards conformance for the NutrientsDB Sample API, derived from the OpenAPI and verified against live responses. No compliance certifications (SOC 2, ISO 27001, HIPAA, GDPR program) are published by this provider, so no Compliance pointer is emitted. standards: - id: openapi-3.1 conforms: true evidence: >- https://www.nutrientsdb.com/api/openapi returns a parseable OpenAPI 3.1.0 document with info, servers, paths, components.schemas, and externalDocs. - id: json conforms: true evidence: All responses are application/json; charset=utf-8. - id: rfc9457-problem-details conforms: false evidence: >- Error responses are application/json with a {sample, error} envelope, not application/problem+json. No type URI, no title/detail/instance members. - id: oauth2 conforms: false evidence: No securitySchemes declared; the API is keyless. - id: openid-connect conforms: false evidence: No /.well-known/openid-configuration; no identity surface. - id: rfc9116-security-txt conforms: false evidence: >- /.well-known/security.txt returns HTTP 200 but the body is the SPA HTML shell, byte-identical to the homepage — there is no security.txt. - id: rfc8615-well-known conforms: false evidence: >- Every /.well-known/* path is answered by a single-page-app catch-all returning 11,489 bytes of HTML with status 200. No well-known document is actually served. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation headers on live responses; no deprecation policy published. - id: cors conforms: true evidence: >- access-control-allow-origin '*', access-control-allow-methods 'GET, HEAD, OPTIONS', access-control-allow-headers 'Content-Type'. - id: http-conditional-requests conforms: true evidence: Weak ETag returned on 200 responses; cache-control public. - id: hsts conforms: true evidence: strict-transport-security max-age=63072000 on live responses. - id: tls-1.3 conforms: true evidence: TLSv1.3 negotiated on www.nutrientsdb.com; see security/nutrientsdb-domain-security.yml. - id: dnssec conforms: false evidence: No DNSSEC on nutrientsdb.com; see security/nutrientsdb-domain-security.yml. - id: caa conforms: false evidence: No CAA records published for nutrientsdb.com. - id: spf conforms: false evidence: No SPF record for nutrientsdb.com. - id: dmarc conforms: true evidence: DMARC present with policy p=none (monitoring only, not enforcing). - id: mcp conforms: false evidence: No MCP endpoint; POST tools/list to /api/mcp returned 404. - id: a2a conforms: false evidence: >- No agent card. /.well-known/agent-card.json and /.well-known/agent.json both return the SPA HTML shell, not an AgentCard JSON object. - id: llms-txt conforms: false evidence: /llms.txt returns the SPA HTML shell, not an llms.txt document. domain_standards: - id: food-composition-per-100g conforms: true evidence: >- All nutrient values are expressed per 100 g of food, the standard basis used by national food composition databases. - id: normalized-nutrient-units conforms: true evidence: >- Unit is encoded as a field-name suffix (_g, _mg, _ug, _kcal) across all 86 fields, verified 86/86 against the live payload. See vocabulary/nutrientsdb-nutrient-schema.yml. compliance_program: published: false certifications: [] notes: >- No trust center, no named certifications, and no compliance page found. Probed trust./security./compliance surfaces returned nothing.