generated: '2026-08-28' method: searched source: >- openapi/sojo-industries-victoria-agent-openapi.json, live probes of api.sojoshield.com and victoria-agent.sojoshield.com, sojoindustries.com, and the provider's own press announcements note: >- Two things are kept strictly apart below. `conforms: true` is only set where the CONTRACT or a live response demonstrates it. Everything Sojo claims in marketing and press but does not declare in a machine-readable contract is recorded under claimed_not_declared with the URL of the claim. standards: - id: mcp name: Model Context Protocol conforms: true version: '2025-06-18' evidence: >- Live initialize against https://victoria-agent.sojoshield.com/mcp returned protocolVersion 2025-06-18 with tools/prompts/resources/logging capabilities, and tools/list returned 6 tools with valid inputSchema. Streamable-HTTP transport; correctly 406s a client that omits Accept: text/event-stream. method: probed - id: openapi name: OpenAPI Specification conforms: true version: 3.0.3 evidence: 'https://victoria-agent.sojoshield.com/openapi.json returns HTTP 200 and parses as OpenAPI 3.0.3 with 8 paths / 10 operations.' method: probed - id: json-schema name: JSON Schema conforms: true evidence: 'All six MCP tool inputSchemas are JSON Schema objects with typed properties and required[].' method: probed - id: sse name: Server-Sent Events conforms: true evidence: 'POST /api/chat responds text/event-stream using the AI SDK UI Message Stream Protocol; the MCP endpoint also uses SSE framing.' method: derived - id: oauth2 name: OAuth 2.0 conforms: false evidence: >- No OAuth flow is declared. The only securityScheme is http/bearer carrying a Stytch session JWT, and /.well-known/oauth-authorization-server + /.well-known/oauth-protected-resource return 404 on victoria-agent.sojoshield.com and 401 on api.sojoshield.com. method: probed - id: oidc name: OpenID Connect conforms: false evidence: '/.well-known/openid-configuration returns 404 on www.sojoindustries.com and an SPA HTML shell (not a document) on sojoshield.com.' method: probed - id: rfc9457 name: 'RFC 9457 Problem Details for HTTP APIs' conforms: false evidence: 'No application/problem+json anywhere. The live error envelope is a custom {data,error{code,details}} shape.' method: probed - id: rfc8594 name: 'RFC 8594 Sunset HTTP Header' conforms: false evidence: 'No Sunset or Deprecation header observed and no deprecation policy published.' method: probed - id: rfc9116 name: 'RFC 9116 security.txt' conforms: false evidence: 'No security.txt on any host — 404 on www.sojoindustries.com, SPA shell on sojoshield.com, 401 on api.sojoshield.com.' method: probed - id: pagination name: Pagination conforms: true evidence: 'GET /api/chat/conversations declares page and limit query parameters with a documented 422 on invalid values.' method: derived - id: idempotency name: Idempotency keys conforms: false evidence: 'No idempotency header, key or retention window declared or documented on any write operation.' method: derived domain_standards: - id: fsma-204 name: 'FDA FSMA Section 204 Food Traceability Rule (21 CFR 1 Subpart S)' conforms: false declared_in_contract: false evidence: >- This is the standard Sojo Shield is built for and it is the single most important standard in its market — but it is NOT declared in any contract we can retrieve. The Victoria OpenAPI never mentions it; the Shield API spec that would carry Critical Tracking Event / Key Data Element shapes is the one returning HTTP 503 at https://api.sojoshield.com/swagger.json. The claim is made only in prose. claim_sources: - https://www.businesswire.com/news/home/20250205330831/en/Sojo-Shield-Achieves-Built-for-NetSuite-Status - https://www.bevnet.com/news/supplier-news/2024/sojo-industries-launches-track-and-trace-platform-for-food-and-beverage/ remedy: >- Publishing the Shield OpenAPI with CTE/KDE-shaped schemas — or a GS1 EPCIS 2.0 event surface — would turn the strongest sales claim Sojo makes into something a buyer's integration team can verify without a call. Today an integrator who already speaks FSMA 204 has no way to tell whether Shield speaks it too. - id: gs1-epcis name: 'GS1 EPCIS 2.0 / CBV (supply-chain event standard)' conforms: false declared_in_contract: false evidence: >- No EPCIS event vocabulary, no GS1 identifier scheme (GTIN/SSCC/GLN) and no CBV business step appears in any retrievable contract or in the six MCP tool schemas. Sojo Shield describes QR-code scans and geolocated critical tracking events in prose, which is EPCIS-shaped territory, but the standard is never named. compliance: certifications: [] trust_center: null note: >- No SOC 2, ISO 27001, PCI, HIPAA or FedRAMP claim was found on sojoindustries.com or sojoshield.com, and no trust center exists. probe-security-programs.py returned vdp=none trust=none. partner_certifications: - name: 'Built for NetSuite' issuer: 'Oracle NetSuite' subject: 'Sojo Shield SuiteApp' date: '2025-02-05' evidence: https://www.businesswire.com/news/home/20250205330831/en/Sojo-Shield-Achieves-Built-for-NetSuite-Status note: >- A platform-integration certification, not a security or privacy attestation. It is recorded here because it is the only third-party validation of a Sojo software artifact we could verify, and because it means the real integration surface for Shield is partly published inside the Oracle NetSuite SuiteApp marketplace rather than on Sojo's own developer site.