generated: '2026-08-05' method: derived source: openapi/star-therapeutics-content-openapi.yml + live probes of https://star-therapeutics.com on 2026-08-05 note: >- Cross-cutting standards conformance for the only public API surface Star Therapeutics exposes. Star Therapeutics makes no published compliance claims of any kind — no trust center, no SOC 2 / ISO 27001 / HIPAA statement, no certifications page — so no `Compliance` pointer is emitted in apis.yml. Every entry below is derived from the deployed contract, not from a provider assertion. standards: - id: openapi-3.1 conforms: true evidence: >- openapi/star-therapeutics-content-openapi.yml is an API Evangelist derivation, not a provider publication. Star Therapeutics itself publishes no OpenAPI. published_by_provider: false - id: wordpress-rest-api-v2 conforms: true evidence: >- The /wp-json/ index declares the wp/v2 namespace and every modelled route matches the upstream WordPress REST contract documented at https://developer.wordpress.org/rest-api/. - id: oembed-1.0 conforms: true evidence: >- /oembed/1.0/embed returns a valid oEmbed 1.0 rich response with version, provider_name, provider_url, title, html and thumbnail fields. - id: rfc8288-web-linking conforms: true evidence: >- Collection responses carry a Link header with rel="next"/rel="prev"; objects carry HAL-style _links relations to self, author, replies and terms. - id: rfc9457-problem-details conforms: false evidence: >- Errors use the WordPress envelope {code, message, data:{status}} served as application/json. No type URI, no application/problem+json. See errors/star-therapeutics-problem-types.yml. - id: oauth2 conforms: false evidence: No oauth2 security scheme; the /wp-json/ index reports an empty authentication array. - id: oidc conforms: false evidence: /.well-known/openid-configuration returned 404. - id: rfc8414-oauth-authorization-server-metadata conforms: false evidence: /.well-known/oauth-authorization-server returned 404. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returned 404 (nginx, not the WordPress 404 handler). - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog returned 404. - id: a2a-agent-card conforms: false evidence: >- Both /.well-known/agent-card.json (A2A 1.0.0 canonical) and /.well-known/agent.json (pre-0.3 legacy) returned 404. No a2a/ artifact is written. - id: llms-txt conforms: false evidence: >- /llms.txt returned 404. The llms/star-therapeutics-llms.txt in this repo is an API Evangelist generation, not a provider publication. - id: model-context-protocol conforms: false gated: true evidence: >- The site DOES register a JetEngine MCP server at /wp-json/jet-engine/v1/mcp with a companion /wp-json/jet-engine/v1/mcp-tools route, and separately registers the WordPress Abilities API at /wp-json/wp-abilities/v1/. A JSON-RPC {"jsonrpc":"2.0","id":1,"method":"tools/list"} POST to the MCP endpoint returned 401 rest_forbidden ("You cannot access this resource"), and every wp-abilities/v1 route returned 401. Both are therefore plugin-default administrative surfaces bound to an authenticated WordPress user, not an agent endpoint Star Therapeutics publishes for consumers. No MCPServer pointer is emitted and no tool list is derived — the live schema is auth-gated and inventing one would fabricate an agent posture this provider does not have. - id: rate-limit-headers conforms: false evidence: No RateLimit-* or X-RateLimit-* headers on any /wp-json response. - id: idempotency conforms: false evidence: No idempotency key, no request deduplication contract, no anonymous write surface. - id: cors conforms: true evidence: >- Access-Control-Allow-Headers advertises Authorization, X-WP-Nonce, Content-Disposition, Content-MD5 and Content-Type; Access-Control-Expose-Headers advertises X-WP-Total, X-WP-TotalPages, Link, Jet-Query-Total and Jet-Query-Pages. - id: tls-1.3 conforms: true evidence: TLSv1.3 negotiated on star-therapeutics.com; see security/star-therapeutics-domain-security.yml. - id: hsts conforms: false evidence: No Strict-Transport-Security header on the site root. HTTPS is enforced by 301 redirect only. - id: dnssec conforms: false evidence: No DNSSEC on star-therapeutics.com. - id: caa conforms: false evidence: No CAA records on star-therapeutics.com. - id: dmarc conforms: partial evidence: >- A DMARC record is published but with p=none and a typo'd rua address (admin@star-therapeutisc.com) pointing at a domain that does not resolve — no enforcement and no working aggregate reporting. See security/star-therapeutics-domain-security.yml. regulatory_context: note: >- Star Therapeutics is a clinical-stage biopharmaceutical company. It is subject to FDA regulation of its investigational products — VGA039 carries Orphan Drug, Fast Track, Rare Pediatric Disease and Breakthrough Therapy designations — but that is drug-development regulation, not API or data-processing regulation, and it confers nothing on the public content API catalogued here. The site publishes a Privacy Policy, Terms of Use and a Consumer Health US notice; none of them describe an API, a data-processing agreement or a compliance certification. No HIPAA, GDPR, SOC 2 or ISO 27001 claim is published anywhere on the public surface, and none is asserted on the company's behalf.