generated: '2026-08-04' method: derived source: >- Derived from openapi/orderco-content-openapi.yml, openapi/orderco-status-openapi.yml, conventions/orderco-conventions.yml, errors/orderco-problem-types.yml and live header captures on 2026-08-04; cross-checked against every page reachable from https://www.order.co/sitemap.xml (998 URLs) and https://www.order.co/llms.txt. summary: >- Order.co makes no standards or compliance claim anywhere on its public site. There is no trust centre, no security page, no SOC 2 / ISO 27001 / PCI / HIPAA statement, no security.txt and no vulnerability-disclosure policy. That is notable for a company that moves purchase orders, invoices, virtual cards and payments for mid-market and enterprise buyers - the compliance posture almost certainly exists behind the sales motion, it is simply not published. Nothing below is asserted as conformant unless it was observed in a live response. standards: - id: openapi conforms: false evidence: >- Order.co publishes no OpenAPI. The two specs in this repo are generated by API Evangelist from the provider's own discovery document and endpoint reference; the provider itself publishes none. Probed 404: api.order.co/openapi.json, api.order.co/swagger.json, api.order.co/api-docs, developer.order.co/openapi.json, docs.order.co/openapi.json, app.order.co/openapi.json. - id: asyncapi conforms: false evidence: No AsyncAPI document and no published event catalog on any Order.co host. - id: graphql conforms: false evidence: POST https://app.order.co/graphql returned HTTP 404 (Rails default 404 page). - id: json-schema conforms: partial evidence: >- Not published by Order.co, but the WordPress REST discovery document at https://www.order.co/wp-json/ carries JSON-Schema-shaped `args` for all 226 routes, including types, enums, defaults, minimum/maximum and format. That is the machine-readable contract this profile's content OpenAPI was generated from. - id: rfc9457 conforms: false evidence: >- Errors are the WordPress `code`/`message`/`data.status` object served as application/json. No application/problem+json anywhere. See errors/orderco-problem-types.yml. - id: rfc8288 conforms: true evidence: >- Link header pagination observed on the content API: '; rel="next"'. - id: rfc8594 conforms: false evidence: No Sunset or Deprecation header on any probed response from either host. - id: rfc9116 conforms: false evidence: >- /.well-known/security.txt returned HTTP 404 on www.order.co, app.order.co and api.order.co. - id: pagination conforms: true evidence: >- page/per_page with per_page bounded 1-100 server-side, plus X-WP-Total and X-WP-TotalPages, on the content API. The status API returns whole collections and needs none. - id: idempotency conforms: false evidence: >- No Idempotency-Key support on either surface. Both are read-only, so this is a statement about the undocumented write surface, not a defect in what is published. - id: rate-limit-headers conforms: false evidence: No RateLimit-*, X-RateLimit-* or Retry-After header on any probed response. - id: oauth2 conforms: false evidence: >- /.well-known/oauth-authorization-server and /.well-known/oauth-protected-resource returned HTTP 404 on every Order.co host probed. - id: oidc conforms: false evidence: >- /.well-known/openid-configuration returned HTTP 404 on www.order.co, app.order.co and api.order.co. Order.co does document SSO *into* the product with Okta and Ping Identity at https://www.order.co/sso-integrations/, but publishes no issuer or discovery document, so there is nothing an OIDC client can discover. - id: mcp conforms: false evidence: >- No MCP endpoint found. No /.well-known/ai-plugin.json, and llms.txt names no tool surface. - id: a2a conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json returned HTTP 404 on www.order.co, app.order.co and api.order.co. - id: llmstxt conforms: true evidence: >- https://www.order.co/llms.txt returns HTTP 200, text/plain, 5,253 bytes, and is a well-formed llms.txt - H1, blockquote summary, then linked sections for Products, Solutions, Industries, Integrations, Resources, Company and Policies. Saved verbatim to llms/orderco-llms.txt. Order.co also serves a companion human page for models at https://www.order.co/ai-info/. - id: cors conforms: true evidence: >- Both surfaces are browser-callable. Status API returns access-control-allow-origin: *; the content API exposes X-WP-Total, X-WP-TotalPages and Link via access-control-expose-headers. - id: sitemap conforms: true evidence: https://www.order.co/sitemap.xml returns HTTP 200 with 998 URLs and an XSL stylesheet. compliance_claims: published: false certifications: [] trust_center: null security_page: null evidence: - url: https://www.order.co/security/ status: 404 - url: https://www.order.co/trust/ status: 404 - url: https://www.order.co/compliance/ status: 404 - url: https://www.order.co/soc-2/ status: 404 - url: https://www.order.co/.well-known/security.txt status: 404 note: >- Searched the full 998-URL sitemap and llms.txt; the only legal/assurance pages Order.co publishes are the privacy policy, the terms and conditions and a privacy-notice-for-covered-consumers page. No certification is named anywhere. sector_note: >- Order.co issues virtual cards and moves payments, and states publicly that it uses Lithic's card-issuing API. Card data therefore sits with a PCI-compliant issuer processor rather than with Order.co, but Order.co publishes no statement of its own scope or posture either way. provider_gaps: - Publish a trust centre naming the certifications the company actually holds. - Publish /.well-known/security.txt (RFC 9116) with a disclosure contact and policy URL. - Publish a vulnerability disclosure policy. - Publish an OpenAPI for the customer API so integrators can evaluate it without a sales call.