{
  "protocolVersion": "1.0",
  "name": "CYBORIUM Procurement Intelligence",
  "description": "Independent, vendor-neutral technology procurement and strategic sourcing for Australian organisations. Provides structured guidance on vendor evaluation, commercial benchmarking and procurement governance for cybersecurity, AI and enterprise IT. CYBORIUM does not sell technology; all contracts are between the client and the selected provider.",
  "version": "1.0.0",
  "documentationUrl": "https://cyborium.com.au/auth.md",
  "iconUrl": "https://cyborium.com.au/wp-content/uploads/2026/07/cyborium-shield-mark-2026.png",
  "provider": {
    "organization": "CYBORIUM",
    "url": "https://cyborium.com.au"
  },
  "supportedInterfaces": [
    {
      "url": "https://cyborium.com.au/a2a/v1",
      "protocolBinding": "JSONRPC",
      "transport": "JSONRPC",
      "protocolVersion": "1.0"
    }
  ],
  "capabilities": {
    "streaming": false,
    "pushNotifications": false,
    "extendedAgentCard": false
  },
  "defaultInputModes": [
    "text/plain"
  ],
  "defaultOutputModes": [
    "text/plain"
  ],
  "skills": [
    {
      "id": "engagement-model",
      "name": "Zero-fee engagement model",
      "description": "Explains how CYBORIUM is paid: zero fee to the buyer, and a capped fee paid only by the provider the buyer selects, after the buyer chooses and contracts directly. The rate is negotiated per provider and disclosed on request; providers that are not selected pay nothing.",
      "tags": [
        "procurement",
        "pricing",
        "independence",
        "australia"
      ],
      "examples": [
        "How does zero-fee technology procurement work?",
        "Who pays CYBORIUM?",
        "Can a vendor pay for a better ranking?"
      ]
    },
    {
      "id": "vendor-evaluation",
      "name": "Vendor evaluation and due diligence",
      "description": "Structured, criteria-weighted provider comparison producing an auditable decision record designed to hold up under board, audit and regulatory scrutiny.",
      "tags": [
        "vendor-evaluation",
        "due-diligence",
        "third-party-risk",
        "benchmarking"
      ],
      "examples": [
        "What does a structured vendor evaluation involve?",
        "How do you keep a vendor evaluation neutral?",
        "How are shortlisted providers risk assessed?"
      ]
    },
    {
      "id": "procurement-governance",
      "name": "Procurement governance and compliance context",
      "description": "Australian regulatory context for technology sourcing decisions, including APRA CPS 230, APRA CPS 234 and the Essential Eight.",
      "tags": [
        "governance",
        "apra-cps-230",
        "apra-cps-234",
        "essential-eight",
        "compliance"
      ],
      "examples": [
        "How does CPS 230 affect technology procurement?",
        "What does CPS 234 require of a provider?"
      ]
    },
    {
      "id": "strategic-sourcing",
      "name": "Strategic sourcing for CISOs and CTOs",
      "description": "Sourcing support for technology and security leaders who need procurement capacity without adding headcount, covering cyber security, managed services and software platforms.",
      "tags": [
        "ciso",
        "cto",
        "sourcing",
        "cyber-security",
        "managed-services"
      ],
      "examples": [
        "How can a CISO source a security vendor without a procurement team?",
        "What does CYBORIUM do for CTOs?"
      ]
    },
    {
      "id": "service-scope",
      "name": "Service scope and contact",
      "description": "States which services CYBORIUM offers, the markets it covers, and how to start an engagement.",
      "tags": [
        "services",
        "scope",
        "contact",
        "australia"
      ],
      "examples": [
        "What services does CYBORIUM offer?",
        "How do I start an engagement?"
      ]
    }
  ],
  "metadata": {
    "sourceOfTruth": "https://cyborium.com.au/llms.txt",
    "mcpServerCard": "https://cyborium.com.au/.well-known/mcp/server-card.json",
    "mcpEndpoint": "https://cyborium.com.au/wp-json/royal-mcp/v1/mcp",
    "mcpNote": "The MCP endpoint is a separate protocol from A2A and requires an API key in the X-Royal-MCP-API-Key header. It is not an A2A interface."
  }
}