generated: '2026-08-02' method: searched source: >- https://www.vumedi.com/public/pages/privacy/ , https://www.vumedi.com/public/pages/tos/ , https://www.vumedi.com/robots.txt , live probes of the VuMedi hosts note: >- VuMedi publishes no machine-readable API contract, so every API-technical standard below is asserted false on the basis of an observed absence rather than a negative claim by the provider. No certification program (SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP) is published anywhere on the public site, so no Compliance pointer is wired. standards: - id: openapi conforms: false evidence: >- No OpenAPI/Swagger document found. /openapi.json, /openapi.yaml, /swagger.json, /api/schema returned 404; /api-docs returned the site HTML catch-all (200 HTML, matches control path). - id: graphql conforms: false evidence: >- POST /graphql on www.vumedi.com returns the marketing HTML shell; introspection returns no GraphQL response. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface documented. - id: mcp conforms: false evidence: No hosted MCP server published or discoverable. - id: a2a conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json returned 404 on both www.vumedi.com and vumedi.com. - id: oauth2 conforms: false evidence: >- No OAuth2 authorization server; /.well-known/oauth-authorization-server 404. Sign-in is a first-party username/password form at /accounts/login/. - id: oidc conforms: false evidence: /.well-known/openid-configuration returned 404. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returned 404. - id: rfc8615-well-known conforms: false evidence: No /.well-known/ document returned 200 on any VuMedi host. - id: rfc9457-problem-details conforms: false evidence: No API surface to evaluate. - id: fhir conforms: false evidence: >- VuMedi is a medical education/content platform, not a clinical data system; no FHIR resources, endpoints or claims are published. - id: hipaa conforms: false evidence: >- No HIPAA claim, BAA offer or covered-entity/business-associate language found in the privacy policy or terms of use. The platform serves clinician education content, not patient PHI. - id: gdpr conforms: true evidence: >- Privacy policy (last updated 2026-06-17) contains explicit EU/UK data protection handling ("If the processing of personal information about you is subject to European Union or United Kingdom data protection law"). - id: ccpa conforms: true evidence: >- Privacy policy references the California Consumer Privacy Act; a "Your Privacy Choices" page is published at /public/pages/privacy-choices/. - id: sitemaps-org conforms: true evidence: >- https://www.vumedi.com/sitemap.xml is a valid sitemaps.org 0.9 sitemap index (videos, webinars, channels, PDFs, events, flatpages). - id: robots-exclusion conforms: true evidence: >- https://www.vumedi.com/robots.txt is published and explicitly Disallows all major AI/agent user agents site-wide.