SSL / TLS
Valid HTTPS · 391ms
x402 discovery
No x402 discovery found
Agent discovery
No agent.json found
llms.txt
HTTP 404 · 384ms
security.txt
Not found · 380ms
CORS headers
No CORS header (OK if server-to-server only) · 622ms
Security headers
1/5 — missing critical: x-content-type-options, content-security-policy · 654ms
Response time
661ms avg · 661ms
MCP server
/mcp responds · 907ms
API endpoints
2 endpoints found
Error handling
404 returned · 432ms
x402 compliance
No x402 payment gates found · 745ms
Rate limiting
No rate-limit headers (may still be rate-limited server-side) · 620ms
Documentation
No documentation endpoint
robots.txt AI crawlers
robots.txt exists but no AI crawler rules · 591ms
AI plugin manifest
No ai-plugin.json (optional for ChatGPT/LLM integration)
OpenAPI spec
/openapi.json — 3.1.0, 14 paths, servers defined, auth documented · 1200ms
Privacy / GDPR
/privacy found (107229 chars) · 987ms
Status / Health
No status or health endpoint
EU AI Act disclosure
No AI model card or disclosure endpoint
Travel Rule (FATF)
No Travel Rule endpoint or VASP disclosure
A2A Protocol (Google)
No agent.json for A2A discovery
DNSSEC
DNSSEC check failed
CAA Records
CAA check failed
DMARC / SPF
No DMARC or SPF records found
Auth maturity
No authentication detected — open API or check failed
API versioning
No versioned paths or version headers found
Human oversight
No human oversight / kill switch endpoint (EU AI Act Art. 14)
Terms of Service
No Terms of Service endpoint found
Content-Type
No application/json responses (1 paths tested)
OASF Classification
No OASF or agent service classification found
MCP Transport Security
/mcp active · HSTS · 1190ms
Voice AI Disclosure
No voice agent disclosure endpoint found
Synthetic Voice Labeling
No synthetic voice labeling declaration found (EU AI Act Article 50)
Synthetic Content Labeling
No machine-readable synthetic content label (EU AI Act Article 50 requires marking AI-generated audio)
Emotion Recognition Declaration
No emotion recognition declaration (EU AI Act requires explicit opt-in/out)
Call Recording Consent
No call recording disclosure or consent mechanism found (required in two-party consent states & GDPR)
FCC/TCPA Compliance
No FCC/TCPA compliance declaration (required for US voice AI calls)
Operator Identity & KYB
No operator identity or KYB status declared
Opt-out & Human Escalation
No opt-out mechanism or human escalation path found (required by FCC + EU AI Act)
Voice Call Policy
No voice call policy (calling hours, frequency limits, recording disclosure)
Caller Identity Declaration
No caller identity declaration (who is calling, is it AI, callback number)
Wallet trust
No wallet address found in x402 or agent.json
ERC-8004 on-chain
No EVM wallet found to verify on-chain registration
Critical — 11x402 discovery failedNo x402 discovery found
Agent discovery failedNo agent.json found
Voice AI Disclosure failedNo voice agent disclosure endpoint found
Synthetic Voice Labeling failedNo synthetic voice labeling declaration found (EU AI Act Article 50)
Call Recording Consent failedNo call recording disclosure or consent mechanism found (required in two-party consent states & GDPR)
FCC/TCPA Compliance failedNo FCC/TCPA compliance declaration (required for US voice AI calls)
Operator Identity & KYB failedNo operator identity or KYB status declared
Opt-out & Human Escalation failedNo opt-out mechanism or human escalation path found (required by FCC + EU AI Act)
Voice Call Policy failedNo voice call policy (calling hours, frequency limits, recording disclosure)
Caller Identity Declaration failedNo caller identity declaration (who is calling, is it AI, callback number)
Warning — 26security.txt needs attentionNot found
CORS headers needs attentionNo CORS header (OK if server-to-server only)
Security headers needs attention1/5 — missing critical: x-content-type-options, content-security-policy
Response time needs attention661ms avg
x402 compliance needs attentionNo x402 payment gates found
Rate limiting needs attentionNo rate-limit headers (may still be rate-limited server-side)
Documentation needs attentionNo documentation endpoint
robots.txt AI crawlers needs attentionrobots.txt exists but no AI crawler rules
AI plugin manifest needs attentionNo ai-plugin.json (optional for ChatGPT/LLM integration)
Status / Health needs attentionNo status or health endpoint
EU AI Act disclosure needs attentionNo AI model card or disclosure endpoint
Travel Rule (FATF) needs attentionNo Travel Rule endpoint or VASP disclosure
A2A Protocol (Google) needs attentionNo agent.json for A2A discovery
DNSSEC needs attentionDNSSEC check failed
CAA Records needs attentionCAA check failed
DMARC / SPF needs attentionNo DMARC or SPF records found
Auth maturity needs attentionNo authentication detected — open API or check failed
API versioning needs attentionNo versioned paths or version headers found
Human oversight needs attentionNo human oversight / kill switch endpoint (EU AI Act Art. 14)
Terms of Service needs attentionNo Terms of Service endpoint found
Content-Type needs attentionNo application/json responses (1 paths tested)
OASF Classification needs attentionNo OASF or agent service classification found
Synthetic Content Labeling needs attentionNo machine-readable synthetic content label (EU AI Act Article 50 requires marking AI-generated audio)
Emotion Recognition Declaration needs attentionNo emotion recognition declaration (EU AI Act requires explicit opt-in/out)
Wallet trust needs attentionNo wallet address found in x402 or agent.json
ERC-8004 on-chain needs attentionNo EVM wallet found to verify on-chain registration