generated: '2026-07-27' method: derived source: >- openapi/genability-signal-openapi.json plus the Signal reference documentation (requests, responses, authentication, versioning) and the full 103-page page index at https://docs.arcadia.com/v2022-12-21-Signal/llms.txt, all fetched 2026-07-27 summary: >- Signal conforms to almost nothing beyond OpenAPI 3.1 and HTTP Basic over TLS. The energy-sector data standards were swept for explicitly (Green Button, ESPI, OpenADR, IEEE 2030.5, IEC 61968/CIM, NAESB, Consumer Data Right): zero matches in the documentation and zero in the contract. Genability implements a proprietary tariff data model. No compliance certification (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP) is claimed for Genability or Arcadia themselves — the corporate security page cites only its VENDORS' certifications (AWS, Stripe, Plaid), so no Compliance pointer is wired. standards: - id: openapi-3.1 conforms: true evidence: openapi/genability-signal-openapi.json declares openapi 3.1.0 with 33 paths. - id: http-basic-auth conforms: true evidence: >- components.securitySchemes.sec0 = {type: http, scheme: basic}, applied globally; docs confirm appId as username and appKey as password. - id: tls conforms: true evidence: >- "All API methods should be called over SSL"; api.genability.com negotiates TLSv1.2 (see security/genability-domain-security.yml). - id: iso8601-datetime conforms: true evidence: >- https://docs.arcadia.com/v2022-12-21-Signal/reference/dates-times specifies ISO 8601 date-time strings with explicit timezone offsets. - id: json conforms: true evidence: '"All responses are returned in JSON format."' - id: rfc9457-problem-details conforms: false evidence: >- Errors use a proprietary {status,count,type,results[]} envelope with code/message/objectName/propertyName items; no application/problem+json anywhere in the spec or docs. - id: rfc9116-security-txt conforms: false evidence: No /.well-known/security.txt on any host (well-known/genability-well-known.yml). - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header and no deprecation policy published. - id: oauth2 conforms: false evidence: No oauth2 securityScheme; no token endpoint; no scopes. - id: oidc conforms: false evidence: >- https://api.genability.com/.well-known/openid-configuration returns the Signal 401 envelope, not an OIDC discovery document. (Dashboard SSO for human users is documented separately and is not an API auth mechanism.) - id: json-api conforms: false evidence: Custom envelope, no JSON:API media type or document structure. - id: hal-hypermedia conforms: false evidence: No link relations in responses. - id: idempotency-key conforms: false evidence: No idempotency header or replay window documented (conventions/genability-conventions.yml). - id: rate-limit-headers conforms: partial evidence: >- The spike limiter returns HTTP 429 with a Retry-After header, but no RateLimit-Limit/Remaining/Reset headers (draft-ietf-httpapi-ratelimit) are documented. - id: cursor-pagination conforms: false evidence: Offset pagination via pageStart/pageCount only. - id: green-button-espi conforms: false evidence: >- Zero case-insensitive matches for "Green Button", "GreenButton" or "ESPI" across all 103 Signal documentation pages and the OpenAPI contract. - id: openadr conforms: false evidence: Zero matches in documentation or contract. - id: ieee-2030.5 conforms: false evidence: Zero matches in documentation or contract. - id: iec-61968-cim conforms: false evidence: Zero matches; the tariff model (LSE, Master Tariff, Territory, TOU Group, Property Key) is proprietary. - id: naesb-esaf conforms: false evidence: Zero matches in documentation or contract. - id: consumer-data-right conforms: false evidence: >- Not applicable — Genability is not a designated data holder in any jurisdiction and exposes no individual customer usage data. See review.yml. - id: fhir-r4 conforms: false evidence: Out of domain. - id: scim2 conforms: false evidence: No identity provisioning surface. - id: odata conforms: false evidence: Custom query-parameter filtering, not OData. certifications: provider_certifications: [] vendor_certifications_cited: - vendor: Amazon Web Services certifications: [ISO 27001, SOC 1, SOC 2/SSAE 16/ISAE 3402, PCI Level 1, FISMA Moderate, SOX] context: Infrastructure provider, cited on https://www.arcadia.com/security - vendor: Stripe certifications: [PCI Level 1 Service Provider] context: Payment processing, cited on https://www.arcadia.com/security - vendor: Plaid certifications: [SOC 2 Type II] context: Bank connectivity, cited on https://www.arcadia.com/security note: >- These are the certifications of Arcadia's SUPPLIERS, not of Arcadia or Genability. No first-party audit report, trust centre or certification claim was found; trust.arcadia.com redirects to the marketing homepage.