generated: '2026-07-27' method: derived source: authentication/good-energy-openid-configuration.json, well-known/good-energy-security.txt, security/good-energy-domain-security.yml, review.yml note: >- Conformance is asserted only where a fetched artifact evidences it. Good Energy publishes no OpenAPI, no AsyncAPI, no GraphQL SDL and no energy-data standard implementation, so every API-design and energy-sector standard below is recorded as not conforming with the reason stated. The standards it DOES conform to are identity and web-security standards carried by its customer login provider and its marketing host — not energy standards. standards: - id: openid-connect-discovery-1.0 conforms: true evidence: >- https://login.goodenergy.co.uk/.well-known/openid-configuration returns HTTP 200 application/json with issuer, jwks_uri, authorization_endpoint, token_endpoint and userinfo_endpoint (saved verbatim to authentication/good-energy-openid-configuration.json). - id: oauth2-rfc6749 conforms: true evidence: authorization_code, client_credentials, refresh_token, implicit and password grants advertised in grant_types_supported. - id: oauth2-pkce-rfc7636 conforms: true evidence: code_challenge_methods_supported includes S256 (and plain). - id: oauth2-par-rfc9126 conforms: true evidence: pushed_authorization_request_endpoint advertised (require_pushed_authorization_requests false). - id: oauth2-device-authorization-rfc8628 conforms: true evidence: device_authorization_endpoint and urn:ietf:params:oauth:grant-type:device_code advertised. - id: oidc-ciba conforms: true evidence: backchannel_authentication_endpoint plus backchannel_token_delivery_modes_supported [poll]. - id: oauth2-token-introspection-rfc7662 conforms: true evidence: introspection_endpoint advertised. - id: oauth2-token-revocation-rfc7009 conforms: true evidence: revocation_endpoint advertised. - id: oauth2-dpop-rfc9449 conforms: partial evidence: dpop_signing_alg_values_supported advertised (RS/PS/ES families); DPoP is offered, not required. - id: jwks-rfc7517 conforms: true evidence: https://login.goodenergy.co.uk/.well-known/openid-configuration/jwks returns HTTP 200 application/json (saved verbatim to authentication/good-energy-openid-jwks.json). - id: oauth2-authorization-server-metadata-rfc8414 conforms: false evidence: /.well-known/oauth-authorization-server on login.goodenergy.co.uk returns the HTML login page from a catch-all route, not RFC 8414 metadata. - id: oauth2-dynamic-client-registration-rfc7591 conforms: false evidence: no registration_endpoint in the discovery document. - id: security-txt-rfc9116 conforms: partial evidence: >- https://www.goodenergy.co.uk/.well-known/security.txt returns HTTP 200 with Contact, Canonical, Preferred-Languages and Hiring fields, but the required Expires field is malformed ("2026-12-310T23:59:59.000Z" is not a valid ISO 8601 timestamp), so the file is not strictly valid. - id: hsts-rfc6797 conforms: true evidence: 'strict-transport-security max-age=31536000 observed on www., account. and login. goodenergy.co.uk (security/good-energy-domain-security.yml).' - id: dmarc-rfc7489 conforms: true evidence: DMARC record present for goodenergy.co.uk with policy reject. - id: spf-rfc7208 conforms: true evidence: SPF record present for goodenergy.co.uk. - id: dnssec conforms: false evidence: no DNSSEC observed for goodenergy.co.uk. - id: caa-rfc8659 conforms: false evidence: no CAA records observed for goodenergy.co.uk. - id: openapi conforms: false evidence: no OpenAPI/Swagger document retrievable from any host; api.goodenergy.co.uk returns 404 for /openapi.json and /api-docs and 403 (WAF) for any path containing "swagger". - id: asyncapi conforms: false evidence: no event, streaming or webhook surface published. - id: graphql conforms: false evidence: https://api.goodenergy.co.uk/graphql returns HTTP 404. - id: rfc9457-problem-details conforms: false evidence: no public API surface to carry problem+json. - id: green-button-espi conforms: false evidence: no Green Button / ESPI Download My Data or Connect My Data implementation, and no Green Button Alliance certification, anywhere on the public site. - id: cdr-energy-consumer-data-standards conforms: false evidence: not applicable — the Australian Consumer Data Right does not bind a GB supplier and no UK equivalent designating Good Energy is in force. - id: ocpi conforms: false evidence: no OCPI/OCPP surface published despite the EV-charger installation business line. - id: openadr conforms: false evidence: no OpenADR reference published. - id: iec-cim-61968 conforms: false evidence: no IEC CIM reference published. industry_codes: note: >- These are GB industry-code obligations Good Energy carries as a licensed supplier. They are party-to-party code compliance, not public API conformance, and produce no callable surface. codes: - id: smart-energy-code party: true evidence: SMETS2 smart meters carried by the Smart DCC; documented in review.yml. - id: balancing-and-settlement-code party: true evidence: Elexon BSC modification P459 raised by Good Energy; Ofgem regulatory-sandbox decision naming Good Energy Ltd requesting BSC Section J derogations. - id: retail-energy-code party: true evidence: same Ofgem regulatory-sandbox decision requesting REC Schedule 14 derogations. compliance_program: published: false note: >- No trust center, no SOC 2 / ISO 27001 / PCI DSS / HIPAA / FedRAMP certification page was found (probe-security-programs.py returned trust=none on 2026-07-27). B Corp certification (2024) is a social/environmental certification, not an information-security compliance program, so no Compliance pointer is emitted.