generated: '2026-08-02' method: searched source: Cowboy Space public materials, FCC/space-industry trade press and company announcements (2026-08-02 web search) scope: >- Cowboy Space Corporation publishes no API, so there are no API or cross-cutting technical standards to assert. What the company is actually measured against is launch and spectrum licensing for its satellites and rockets, plus US export control for space hardware. Those regimes are recorded here as applicable with their status stated honestly as not-yet-evidenced rather than achieved, and the API/protocol block is recorded as not-applicable rather than false, so this file is never mistaken for a compliance posture the company does not claim. regulatory_regime: - id: fcc-part-25-satellite-licensing name: FCC Part 25 satellite and earth-station licensing (US spectrum authority) conforms: false applicable: true status: unknown evidence: >- Any US-licensed LEO constellation transmitting to ground stations requires FCC authorization, and the company plans a power-beaming demonstrator in 2026 and a Galactic Brain orbital data-center node in early 2027. Cowboy Space publishes no licensing statement on its own site; recorded as applicable-but-unevidenced. - id: faa-part-450-launch-licensing name: FAA Part 450 commercial launch vehicle operator licensing conforms: false applicable: true status: anticipated evidence: >- The company announced in May 2026 that it is developing its own orbital launch vehicle, sized between Falcon 9 and Starship at roughly 20,000-25,000 kg payload, with a first flight targeted for the end of 2028. A US commercial launch requires an FAA Part 450 license. No license or application has been published. - id: itar-ear-export-control name: ITAR / EAR US export control for spacecraft and launch vehicles conforms: false applicable: true status: unknown evidence: >- Satellites and launch vehicles are export-controlled; the company's job listings are US-based (San Carlos, CA and Seattle, WA). No public compliance statement. - id: dod-contracting name: US Department of Defense program participation conforms: false applicable: true status: partial evidence: >- As Aetherflux, the company was reported to have DoD funding approved for a space-based power proof-of-concept demonstration, and SAIC participated in the May 2026 Series B. This is a customer/investor relationship, not a published compliance certification. api_standards: - id: openapi conforms: false applicable: false evidence: no public API contract published (see well-known/aetherflux-well-known.yml) - id: oauth2 conforms: false applicable: false - id: openid-connect conforms: false applicable: false - id: rfc9457-problem-details conforms: false applicable: false - id: asyncapi conforms: false applicable: false - id: graphql conforms: false applicable: false evidence: /graphql returns 404 on every Cowboy Space host - id: mcp conforms: false applicable: false - id: a2a conforms: false applicable: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json both 404 on www.cowboyspace.com, cowboyspace.com and cowboy.space - id: rfc9116-security-txt conforms: false applicable: true evidence: /.well-known/security.txt returns 404 on every Cowboy Space host information_security_compliance: found: false note: >- No trust center, SOC 2, ISO 27001, CMMC, FedRAMP or equivalent information-security certification page was found by probe-security-programs.py (vdp=none trust=none) or by search; trust.cowboyspace.com and security.cowboyspace.com do not resolve. No `Compliance` and no `TrustCenter` pointer is wired in apis.yml. The launch and spectrum regimes above are airworthiness/spectrum regimes, not published infosec compliance programs, so they do not earn one either. observed_vendors: note: >- Domain TXT records show the company uses Google Workspace, KnowBe4 security awareness training, EdgePilot email security, Atlassian and Smartsheet. This is observed internal tooling, not a published compliance attestation, and is recorded as context only. domain_security_observed: source: security/aetherflux-domain-security.yml summary: >- www.cowboyspace.com serves TLS 1.3 with a certificate valid to 2026-10-07 and DOES publish HSTS with a one-year max-age. The cowboyspace.com domain has NO DNSSEC and NO CAA record. SPF is present (Google Workspace plus EdgePilot and KnowBe4 senders) and DMARC is enforced at p=quarantine.