HoliSec Agent bronze
holi.r.at
“HoliSec GmbH, Graz (Austria): holistic cyber security for small and medium-sized businesses. Two core offerings — HoliSec Check (one-off assessment with a prioritised roadmap) and HoliSec Care (ongoing implementation support). Typical triggers: NIS2/NISG 2026, DIN SPEC 27076, Cyber Trust Austria, customer and supplier requirements. HoliSec does not operate a SOC. This agent surface is public and read-only: services with prices, approved customer references, blog posts, contact data and every public page as Markdown, via the Model Context Protocol endpoint (get_services, get_references, get_posts, get_contact, get_page_markdown) or the JSON API under /api/v1/. There is no A2A JSON-RPC endpoint and no write operation — appointments and enquiries are handled by humans through the contact page.
a2a https://holi.r.at/.well-known/agent-card.json talk to it https://holi.r.at/.well-known/agent-card.json its cardwe checked this the operator says this
Verified by agenttru.st
Everything here is a check agenttru.st performed itself. Assurance, protocol, hosting and freshness are in the card above and are not repeated.
- Certificate
-
Issued by Let's Encrypt
domain-validated
Valid until 27 Oct 2026. A wildcard certificate: its other hosts are invisible here, because CT logs the wildcard, not them.Control of the hostname was checked; nothing about who operates it.
- DANE / TLSA
- Not verified
- Discovery
-
Well-known document
This host also publishes an ARD catalog (
/.well-known/ai-catalog.json) declaring 9 resources. The catalog's entries are the publisher's claims, not something agenttru.st verified. - First seen
- 11 Sep 2026
View verification details
- Assurance
- bronze Bronze — agent card fetched over HTTPS with a valid certificate
- Protocols
- A2A verified by handshake or card fetch, not merely advertised
- Hosted in
- 🇦🇹 AT · Cloudflare, Inc. (AS13335)
- Last checked
- 10d ago
What this agent says it can do
Declared in the agent's own card. agenttru.st has not tested whether it completes any of these tasks — the operator of holi.r.at controls every word below.
HoliSec Check und HoliSec Care erklären
Explains the two core offerings: HoliSec Check (one-off assessment of technology, organisation and processes, resulting in a risk picture and a prioritised roadmap) and HoliSec Care (ongoing support that implements and maintains that roadmap), including current prices and tiers. Data via MCP (get_services) or GET /api/v1/services and /api/v1/services/{slug}.
- Was kostet ein Security Check für ein KMU in Österreich?
- Was ist der Unterschied zwischen HoliSec Check und HoliSec Care?
- Wie läuft ein HoliSec Check ab?
NIS2 und Compliance-Anlässe einordnen
Answers questions about the triggers HoliSec works on: NIS2 / the Austrian NISG 2026, DIN SPEC 27076, Cyber Trust Austria and security requirements coming from customers or the supply chain. Source material via MCP (get_posts, get_page_markdown) or GET /api/v1/posts. This is orientation, not legal advice.
- Bin ich von NIS 2 betroffen?
- Was verlangt das NISG 2026 von einem mittelständischen Betrieb?
- Wie bereite ich Cyber Trust Austria vor?
Kontaktdaten und Referenzen liefern
Returns contact details (e-mail, phone, address in Graz, booking link) and approved customer references with industry, summary and results. Via MCP (get_contact, get_references) or GET /api/v1/contact and /api/v1/references. Booking and enquiries stay with humans: no endpoint of this agent writes data.
- Cybersecurity-Beratung Graz Kontakt
- Welche Referenzen kann HoliSec vorweisen?
- Wie vereinbare ich ein Erstgespräch mit HoliSec?
What its catalog declares
From the ARD catalog this host publishes at
/.well-known/ai-catalog.json. The operator controls every entry; agenttru.st
verified that the catalog exists and parses, and nothing about what the entries say.
HoliSec MCP Server
Read-only MCP server (streamable-http): core offerings with prices, approved customer references, blog posts, contact data and any public page as Markdown. No authentication.
https://holi.r.at/.well-known/mcp/server-card.jsonHoliSec Agent Guide (Skill)
Agent skill describing what HoliSec offers, how HoliSec Check and HoliSec Care relate, which interface answers which question — and what is explicitly not possible (no bookings, no lead data).
https://holi.r.at/.well-known/agent-skills/holisec-agent-guide/SKILL.mdHoliSec Public API
OpenAPI description of the public read-only JSON API under /api/v1/: health, services, services/{slug}, references, posts, contact.
https://holi.r.at/openapi.jsonHoliSec API-Katalog
RFC 9727 API catalog: linkset of the public API description and its documentation endpoints.
https://holi.r.at/.well-known/api-catalogHoliSec A2A Agent Card
Agent-to-Agent (A2A 0.3.0) card: capabilities, skills and the supported interfaces (MCP endpoint and HTTP+JSON API) of the public HoliSec agent surface.
https://holi.r.at/.well-known/agent-card.jsonHoliSec llms.txt
Compact site index for language models: positioning, all public pages with one-line descriptions and the entry points for structured data.
https://holi.r.at/llms.txtAnd 3 more entries in the catalog, not shown here.
Technical agent card
Copied from the agent's card. The operator controls these values; agenttru.st has not verified them.
- Provider
- HoliSec GmbH — what this agent says about itself; other agents claiming the same provider are not thereby related
- Protocol
- a2a
- Version
- 1.0.0
- Card completeness
- complete all eight fields required by a2a.proto v1.0
View all card details
- Capabilities
- pushNotifications stateTransitionHistory streaming
- Agent card
- https://holi.r.at/.well-known/agent-card.json
Operate this agent and would rather not be listed? Request removal.