generated: '2026-08-05' method: derived source: openapi/wugen-allotera-content-openapi.yml + live probes of both provider hosts summary: >- Cross-cutting standards conformance for the only machine-readable surface Wugen/Allotera exposes, the WordPress REST wp/v2 content API. This is a derived assessment of observed behaviour. Allotera publishes no compliance program, no certifications and no conformance claims of its own, so no Compliance pointer is emitted for this provider. standards: - id: openapi-3.1 conforms: true evidence: >- openapi/wugen-allotera-content-openapi.yml and openapi/wugen-legacy-content-openapi.yml are valid OpenAPI 3.1.0, derived by API Evangelist. The provider itself publishes no OpenAPI, and both documents carry x-provider-published: false. - id: rest conforms: true evidence: Resource-oriented URIs, GET semantics, JSON representations, HTTP status codes. - id: rfc8288-web-linking conforms: true evidence: >- Pagination is advertised via a Link header carrying rel="next" / rel="prev", observed on /wp/v2/posts. - id: hal-style-hypermedia conforms: partial evidence: >- Every resource carries a _links object with self/collection/about/author/wp:term relations and an _embedded expansion via _embed. It is WordPress's own link format, not HAL, JSON:API or Siren. - id: rfc9457-problem-details conforms: false evidence: >- Errors use the WordPress envelope {code, message, data.status} served as application/json. No type URI, no title/detail members, no application/problem+json media type. - id: json-api conforms: false evidence: No data/attributes/relationships document structure and no application/vnd.api+json. - id: odata conforms: false - id: oauth2 conforms: false evidence: >- No oauth2 security scheme anywhere on the surface. /.well-known/oauth-authorization-server returns 404 on alloteratx.com and a soft 404 on wugen.com. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on alloteratx.com. - id: rfc9116-security-txt conforms: false evidence: No /.well-known/security.txt on either host. See well-known/wugen-well-known.yml. - id: rfc9727-api-catalog conforms: false evidence: No /.well-known/api-catalog on either host. - id: rfc8594-sunset-header conforms: false evidence: >- No Sunset or Deprecation headers were observed, including on the retired wugen.com host whose human-facing site has in fact been decommissioned — the API surface there carries no machine-readable deprecation signal at all. - id: a2a-agent-card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json probed on both hosts; 404 on alloteratx.com, soft 404 on wugen.com. No card exists, so none was written. - id: mcp conforms: false evidence: >- No mcp namespace on either host. alloteratx.com registers wp-abilities/v1, the WordPress Abilities API that an MCP adapter would build on, but its registry returns HTTP 401 rest_forbidden anonymously, so nothing could be enumerated. - id: llms-txt conforms: false evidence: >- /llms.txt returns 404 on alloteratx.com and a soft 404 on wugen.com. The llms.txt in this repo was generated by API Evangelist, not published by the provider. - id: cors conforms: true evidence: >- Access-Control-Expose-Headers advertises X-WP-Total, X-WP-TotalPages and Link; Access-Control-Allow-Headers advertises Authorization and X-WP-Nonce. - id: tls-1.3 conforms: true evidence: TLSv1.3 negotiated on both alloteratx.com and wugen.com. See security/wugen-domain-security.yml. - id: hsts conforms: false evidence: No Strict-Transport-Security header on either host. - id: dnssec conforms: false evidence: No DNSKEY on either registrable domain. - id: caa conforms: false evidence: No CAA records on either registrable domain. - id: spf conforms: true evidence: SPF present on alloteratx.com and wugen.com. - id: dmarc conforms: partial evidence: >- DMARC present on both, but alloteratx.com publishes p=none (monitor only) while the retired wugen.com publishes the stronger p=quarantine — the live brand is the weaker of the two. compliance_program: published: false certifications: [] detail: >- No trust center, no SOC 2 / ISO 27001 / HIPAA / GDPR statement and no compliance page were found on either host by probe-security-programs.py. As a clinical-stage biotech Allotera is subject to FDA and HIPAA regimes in its operations, but it publishes nothing about them in a form this pipeline can cite, so nothing is asserted here.