generated: '2026-08-09' method: derived source: >- derived from well-known/civil-maps-well-known.yml (probe record) and security/civil-maps-domain-security.yml, plus public reporting on the Luminar acquisition, 2026-08-09 scope: >- Civil Maps publishes no API, so there is no API or cross-cutting technical standard it can be asserted against. Every API/protocol standard below is recorded as applicable:false rather than as a failure, so this file is never mistaken for a posture the company was measured on and fell short of. The company was absorbed into Luminar Technologies in mid-2022; any live conformance obligation now belongs to Luminar, not to this entity. api_standards: - id: openapi conforms: false applicable: false evidence: >- no public API contract published; /openapi.json, /swagger.json and /api-docs all soft-404 to the homepage shell, and api.civilmaps.com does not resolve - id: asyncapi conforms: false applicable: false evidence: no event, streaming or webhook surface is documented anywhere on the site - id: graphql conforms: false applicable: false evidence: /graphql returns the homepage shell, not a GraphQL endpoint - id: mcp conforms: false applicable: false evidence: no hosted MCP server and no mcp. subdomain - id: a2a conforms: false applicable: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json both return HTTP 200 with the homepage HTML on civilmaps.com - a soft-404, not a card - id: oauth2 conforms: false applicable: false - id: openid-connect conforms: false applicable: false evidence: /.well-known/openid-configuration soft-404s to the homepage shell - id: rfc9457-problem-details conforms: false applicable: false - id: rfc9727-api-catalog conforms: false applicable: false evidence: /.well-known/api-catalog soft-404s to the homepage shell - id: rfc9116-security-txt conforms: false applicable: true evidence: >- /.well-known/security.txt soft-404s to the homepage shell on civilmaps.com; no RFC 9116 file is published - id: llms-txt conforms: false applicable: true evidence: >- /llms.txt soft-404s to the homepage shell; the llms.txt in this repo is API Evangelist generated, not provider published domain_standards: - id: robots-txt conforms: true applicable: true evidence: >- /robots.txt is a real document that allows general crawlers, blocks seven SEO scrapers, and declares a sitemap - id: sitemap-xml conforms: true applicable: true evidence: /sitemap.xml is a real document listing 91 marketing and blog URLs information_security_compliance: found: false note: >- No trust center, no SOC 2 / ISO 27001 / PCI / HIPAA / FedRAMP claim, and no vulnerability disclosure or bug bounty program was found on civilmaps.com. No `Compliance` and no `TrustCenter` pointer is wired in apis.yml. corporate_status: independent: false acquirer: Luminar Technologies acquired: '2022-06' announced: '2023-01-04' note: >- Acquisition closed in Q2 2022 and was announced by Luminar at CES on 2023-01-04; the HD mapping and localization technology was folded into Luminar's Sentinel platform. civilmaps.com remains online as a marketing archive stamped "Copyright 2019". domain_security_observed: source: security/civil-maps-domain-security.yml summary: >- civilmaps.com is served by Cloudflare over TLS with x-content-type-options and a referrer-policy set, but no Strict-Transport-Security header, no CAA record, no DNSSEC DS record and no DMARC record. SPF is present (v=spf1 include:_spf.mx.cloudflare.net ~all).