generated: '2026-09-02' method: probed source: https://vertoeducation.org/.well-known/oauth-authorization-server name: Verto Education Conformance description: >- Cross-cutting and domain standards asserted against what Verto Education actually serves. Every `conforms: true` below is backed by a document fetched from the company's own host; every `conforms: false` is an observed absence, not an assumption. Verto publishes no compliance or certification claims of any kind, so no Compliance pointer is emitted. standards: - id: oauth2 name: OAuth 2.0 (RFC 6749) conforms: true evidence: >- Live authorization_code + refresh_token authorization server on the company's own origin. /oauth/authorize returns 400 to a parameterless GET and /oauth/token returns 405 to GET (POST-only), i.e. both routes exist and behave as OAuth endpoints. source: https://vertoeducation.org/.well-known/oauth-authorization-server - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: true evidence: >- /.well-known/oauth-authorization-server returns 200 application/json carrying issuer, authorization_endpoint, token_endpoint, revocation_endpoint, response_types_supported, grant_types_supported, code_challenge_methods_supported and scopes_supported. source: https://vertoeducation.org/.well-known/oauth-authorization-server - id: rfc9728 name: OAuth 2.0 Protected Resource Metadata (RFC 9728) conforms: true evidence: >- /.well-known/oauth-protected-resource returns 200 with resource, authorization_servers, bearer_methods_supported and scopes_supported. This is the document that makes the MCP endpoint discoverable at all. source: https://vertoeducation.org/.well-known/oauth-protected-resource - id: rfc7636 name: PKCE (RFC 7636) conforms: true evidence: code_challenge_methods_supported ["S256"] - plain is not offered. source: https://vertoeducation.org/.well-known/oauth-authorization-server - id: mcp name: Model Context Protocol conforms: partial evidence: >- A remote MCP endpoint exists and is advertised through RFC 9728, which is the protocol's own discovery mechanism. Protocol conformance beyond discovery could not be verified: initialize and tools/list both return HTTP 401. source: https://vertoeducation.org/wp-json/mcp/mcp-oauth-server - id: rfc8615 name: Well-Known URIs (RFC 8615) conforms: true evidence: Two documents served under /.well-known/ (see well-known/verto-education-well-known.yml). - id: llmstxt name: llms.txt conforms: true evidence: >- /llms.txt returns 200 text/plain, 3,881 bytes, in llms.txt format with H1, blockquote summary and sectioned link lists. Generated by Yoast SEO v28.2. source: https://vertoeducation.org/llms.txt - id: oidc name: OpenID Connect Discovery conforms: false evidence: /.well-known/openid-configuration returns the WordPress 404 template. - id: rfc9457 name: Problem Details for HTTP APIs (RFC 9457) conforms: false evidence: >- Observed error bodies use the WordPress REST envelope {"code","message","data":{"status"}} with content-type application/json, not application/problem+json. - id: rfc9116 name: security.txt conforms: false evidence: /.well-known/security.txt returns 404. - id: a2a name: A2A Agent Card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json both return the WordPress 404 HTML template. - id: openapi name: OpenAPI conforms: false evidence: >- No OpenAPI or Swagger document served. /openapi.json, /openapi.yaml, /swagger.json and /api-docs all return the WordPress 404 template; there is no api., docs. or developer. subdomain (NXDOMAIN). - id: soap-wsdl name: WSDL / SOAP conforms: false evidence: >- ?wsdl returns the WordPress homepage (the query parameter is ignored), which is a miss, not a contract. domain_standards: market: Education / study abroad and college-transfer pathways assessment: >- None declared, and none found. Verto's market has real interoperability standards - IMS/1EdTech LTI, OneRoster, Caliper Analytics and QTI, plus PESC XML and the Common App/Coalition transfer schemas that a college-pathway operator would plausibly speak with its 60+ partner colleges. No trace of any of them appears in anything Verto serves publicly: no LTI launch endpoint, no OneRoster /ims/oneroster path, no PESC schema reference, no urn:ietf:params:scim URN, no $metadata surface. Verto's partner integrations, if they exist, are private. Reward-only dimension - recorded as absent, not penalised, and deliberately not invented. probed: - urn:ietf:params:scim:schemas - /ims/oneroster - LTI launch / .well-known - OData $metadata standards_found: [] compliance_claims: [] compliance_note: >- No trust center, no SOC 2 / ISO 27001 / PCI / FERPA / GDPR certification page, and no security page found on the site. The company does publish a California privacy notice and a notice-at-collection page (CCPA/CPRA posture), which are legal notices rather than a compliance certification programme, so no Compliance pointer is emitted. checked: '2026-09-02'