generated: '2026-08-04' method: derived source: well-known/oncoc4-openid-configuration.json, security/oncoc4-domain-security.yml name: OncoC4 standards conformance description: >- Cross-cutting standards assertions for the OncoC4 public surface. OncoC4 is a clinical-stage biopharmaceutical company with no developer program, so most API-layer standards are simply not applicable. The two that do hold are carried by the Umbraco CMS behind oncoc4.com, which serves a conformant OAuth 2.0 / OpenID Connect discovery document. Each entry records what was actually observed; `conforms: false` here means "not published", not "implemented badly". standards: - id: oidc name: OpenID Connect Discovery 1.0 conforms: true evidence: >- https://oncoc4.com/.well-known/openid-configuration returned HTTP 200 with a valid discovery document carrying issuer, authorization_endpoint, token_endpoint, userinfo_endpoint, jwks_uri, response_types_supported, subject_types_supported and id_token_signing_alg_values_supported (RS256). scope: Umbraco CMS member authentication only — not an API product. - id: oauth2 name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: true evidence: >- https://oncoc4.com/.well-known/oauth-authorization-server returned HTTP 200 with issuer, authorization_endpoint, token_endpoint, revocation_endpoint, grant_types_supported (authorization_code, refresh_token), token_endpoint_auth_methods_supported and authorization_response_iss_parameter_supported (RFC 9207). scope: Umbraco CMS member authentication only — not an API product. - id: pkce name: PKCE (RFC 7636) conforms: true evidence: >- code_challenge_methods_supported advertises S256 (and plain, which RFC 7636 discourages for public clients). - id: rfc9116 name: security.txt (RFC 9116) conforms: false evidence: https://oncoc4.com/.well-known/security.txt returned HTTP 404. - id: rfc8615 name: Well-Known URIs (RFC 8615) conforms: partial evidence: >- /.well-known/openid-configuration, /.well-known/oauth-authorization-server and /.well-known/jwks return 200; /.well-known/security.txt, /.well-known/api-catalog, /.well-known/ai-plugin.json, /.well-known/agent-card.json and /.well-known/agent.json all return 404. - id: hsts name: HTTP Strict Transport Security (RFC 6797) conforms: true evidence: >- oncoc4.com responds with Strict-Transport-Security, max-age 2592000 (30 days), over TLS 1.3. - id: dmarc name: DMARC (RFC 7489) conforms: true evidence: DMARC record present on oncoc4.com with policy `quarantine`; SPF present. - id: dnssec name: DNSSEC (RFC 4033) conforms: false evidence: No DNSKEY records observed for oncoc4.com. - id: caa name: CAA (RFC 8659) conforms: false evidence: No CAA records observed for oncoc4.com. - id: openapi name: OpenAPI Specification conforms: false evidence: >- /openapi.json, /openapi.yaml, /swagger.json, /api-docs and /docs on oncoc4.com all returned 404 (or the site's HTML error page); api.oncoc4.com, developer.oncoc4.com and docs.oncoc4.com do not resolve. - id: graphql name: GraphQL conforms: false evidence: https://oncoc4.com/graphql returned HTTP 404. - id: asyncapi name: AsyncAPI conforms: false evidence: No event, streaming or webhook surface is documented publicly. - id: rfc9457 name: Problem Details for HTTP APIs (RFC 9457) conforms: false evidence: No public API contract exists to assert an error format against. not_applicable: - id: fhir reason: >- OncoC4 is a drug developer, not a healthcare data platform; it exchanges no clinical data over a public interface. - id: fapi reason: Not a financial institution. - id: psd2 reason: Not a financial institution. - id: scim reason: No identity provisioning surface is published. - id: odata reason: No data query API is published. - id: json-api reason: No public REST API is published. x-evidence: checked: '2026-08-04' hosts: - oncoc4.com - www.oncoc4.com