generated: '2026-08-05' method: derived source: >- openapi/twinstrand-biosciences-content-openapi.yml, live response headers, well-known/twinstrand-biosciences-well-known.yml and security/twinstrand-biosciences-domain-security.yml note: >- TwinStrand Biosciences makes no public conformance or compliance claim for any API — there is no developer surface on which to make one. Products carry a "For Research Use Only. Not For Use in Diagnostic Procedures." label, so no clinical-diagnostic regime (CLIA, IVDR, FDA 510(k)) is asserted by the company and none is asserted here. No trust center, SOC 2, ISO 27001 or HIPAA attestation was found. No Compliance pointer is wired — there is nothing published to point at. standards: - id: openapi-3.1 conforms: true provider_published: false evidence: >- openapi/twinstrand-biosciences-content-openapi.yml — DERIVED by API Evangelist from the live route-discovery document, not published by TwinStrand. - id: json-schema conforms: true evidence: >- WordPress REST route args in /wp-json/ are JSON Schema fragments (type / enum / default / minimum / maximum / items) and were carried verbatim into the derived OpenAPI parameters. - id: rfc7617-http-basic conforms: true evidence: >- securitySchemes.applicationPassword — http/basic. The discovery document advertises authentication.application-passwords.endpoints.authorization = https://twinstrandbio.com/wp-admin/authorize-application.php. - id: rfc8288-web-linking conforms: true evidence: 'Link: ; rel="next" observed on GET /wp/v2/news' - id: oembed conforms: true evidence: oembed/1.0 namespace registered; GET /wp-json/oembed/1.0/embed returns 200 application/json - id: rfc9457-problem-details conforms: false evidence: >- Errors use the WordPress {code, message, data.status} envelope with content-type application/json, not application/problem+json. Observed 400 and 401 bodies recorded in errors/twinstrand-biosciences-problem-types.yml. - id: llms-txt conforms: false provider_published: false evidence: https://twinstrandbio.com/llms.txt returns 404. The file in llms/ is generated by API Evangelist. - id: oauth2 conforms: false evidence: no oauth2 securityScheme; /.well-known/oauth-authorization-server 404 - id: openid-connect conforms: false evidence: /.well-known/openid-configuration 404 - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt and /security.txt both 404 on the apex and the www alias - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog 404 - id: a2a conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json both 404 on twinstrandbio.com and www.twinstrandbio.com. No agent card exists, and none was authored. - id: model-context-protocol conforms: false evidence: >- No mcp namespace in the 18 registered WordPress REST namespaces and no /.well-known/mcp.json. The wp-abilities/v1 registry is installed but returns 401 rest_forbidden anonymously, so no tool surface is publicly enumerable. - id: asyncapi conforms: false evidence: no event, streaming or webhook surface published anywhere on twinstrandbio.com - id: graphql conforms: false evidence: /graphql 404; no graphql namespace in the WordPress route index - id: rfc8594-sunset-header conforms: false evidence: no Sunset or Deprecation header on any probed response; no deprecation policy published - id: hsts conforms: true evidence: 'strict-transport-security: max-age=31536000 observed on twinstrandbio.com' - id: tls-1.3 conforms: true evidence: security/twinstrand-biosciences-domain-security.yml — TLSv1.3 negotiated - id: dnssec conforms: false evidence: no DNSKEY on twinstrandbio.com - id: caa conforms: false evidence: no CAA record on twinstrandbio.com - id: spf conforms: true evidence: SPF record present on twinstrandbio.com - id: dmarc conforms: partial evidence: DMARC record present but policy is p=none (monitor only, neither quarantine nor reject)