generated: '2026-08-13' method: derived source: live probes 2026-08-13 + https://sitefire.ai/data-privacy notes: >- Standards posture derived from the artifacts in this repo and from live probes. Sitefire's conformance is concentrated entirely on the agent axis - MCP, OAuth 2.1 discovery, llms.txt, Agent Skills, Content-Signal - and is absent on the classic API-hygiene axis: no RFC 9457 errors, no RFC 9116 security.txt, no RFC 8594 sunset headers, no A2A card, no AsyncAPI. On compliance, Sitefire is a German GmbH (pulse Energy GmbH, Munich, HRB 299092) with a US parent, and publishes a GDPR compliance statement, a DPA incorporated by reference including EU Standard Contractual Clauses, and named technical/organizational measures. It publishes NO third-party certification - no SOC 2, no ISO 27001, no PCI DSS, no HIPAA, no FedRAMP - and no trust center. The Compliance pointer in apis.yml points at that published GDPR/DPA posture and nothing more. standards: - id: mcp name: Model Context Protocol conforms: true evidence: >- Hosted remote server at https://app.sitefire.ai/api/mcp. A JSON-RPC 2.0 tools/list POST returns a well-formed JSON-RPC error object with HTTP 401, which is correct MCP behaviour for an unauthenticated call. - id: oauth2 name: OAuth 2.0 / 2.1 conforms: true evidence: >- authorization_code + refresh_token grants, PKCE S256, bearer token in header. See authentication/sitefire-authentication.yml. - id: rfc9728 name: OAuth 2.0 Protected Resource Metadata conforms: partial evidence: >- The document exists and the 401 carries a conformant WWW-Authenticate Bearer challenge with a resource_metadata parameter. It is served from /api/mcp/oauth-metadata, not the canonical /.well-known/oauth-protected-resource, so discovery by well-known probe fails. - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata conforms: true evidence: >- Published by the delegated authorization server (qhfesxmsojjleewjufcn.supabase.co/auth/v1), which Sitefire's own protected-resource document names. Third-party-operated, not Sitefire-hosted. - id: oidc name: OpenID Connect conforms: true evidence: >- The authorization server advertises the openid scope, a userinfo endpoint, a jwks_uri and id_token signing algorithms (RS256/HS256/ES256). - id: rfc7591 name: OAuth 2.0 Dynamic Client Registration conforms: true evidence: registration_endpoint published at /auth/v1/oauth/clients/register. - id: openapi name: OpenAPI conforms: true evidence: >- OpenAPI 3.1.0 for the Book Demo API. Note the described endpoints did not resolve when probed - see lifecycle/sitefire-lifecycle.yml. - id: agent-skills name: Agent Skills (Anthropic) conforms: true evidence: >- Four SKILL.md skills plus a plugin manifest published at github.com/sitefire-ai/skills; installable via npx skills add. - id: llms-txt name: llms.txt conforms: true evidence: >- Served at https://sitefire.ai/llms.txt with a markdown twin (.md) for every linked documentation and blog page. - id: content-signal name: Content Signals (robots.txt) conforms: true evidence: 'robots.txt declares "Content-Signal: search=yes, ai-input=yes, ai-train=yes".' - id: gdpr name: GDPR conforms: true evidence: >- Data-privacy page names Sitefire as data controller, states GDPR compliance, cites Article 6(1) legal bases, and lists technical/organizational measures (encryption in transit and at rest, access controls, backups). Terms ยง 7 incorporates a standard DPA with EU Standard Contractual Clauses for US transfers. - id: rfc9457 name: Problem Details for HTTP APIs conforms: false evidence: No application/problem+json; nested {"error":{"code","message"}} envelope instead. - id: rfc9116 name: security.txt conforms: false evidence: /.well-known/security.txt returns 404 on sitefire.ai. - id: rfc8594 name: Sunset HTTP Header conforms: false evidence: No Sunset or Deprecation header; no deprecation policy published. - id: rfc8615-well-known name: Well-Known URIs conforms: false evidence: >- No /.well-known/ path on either host returns a document. app.sitefire.ai answers 200 with an SPA shell for every path, which is worse than a 404 because it defeats automated discovery. - id: a2a name: A2A Agent Card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json probed on both hosts - 404 on sitefire.ai, SPA HTML shell on app.sitefire.ai. No card. - id: asyncapi name: AsyncAPI conforms: false evidence: >- Not applicable - Sitefire documents no webhooks, no event stream and no callback surface. Recorded as absent, not as a failure. - id: soc2 name: SOC 2 conforms: false evidence: No SOC 2 report or attestation is published or referenced. - id: iso27001 name: ISO/IEC 27001 conforms: false evidence: No ISO 27001 certification is published or referenced. compliance: published: true program: GDPR + DPA with EU Standard Contractual Clauses url: https://sitefire.ai/data-privacy certifications: [] certifications_note: >- No third-party certification of any kind is published. The compliance posture is a self-declared GDPR/DPA statement, appropriate to an EU controller, and should not be read as an audited control environment. legal_entities: - name: pulse Energy GmbH address: Kellerstr. 30, 81667 Munich, DE registry: Munich HRB 299092 vat_id: DE452862576 officers: [Jochen Madler (Managing Director), Vincent Jeltsch (Managing Director)] - name: pulse Holding Inc. address: 1111B S Governors Ave STE 80203, Dover, DE 19904, USA officers: [Jochen Madler (President & CEO)] source: https://sitefire.ai/imprint