generated: '2026-07-26' method: derived source: >- the five OpenAPI documents in openapi/, the Auth0 discovery documents in well-known/ and authentication/, and the public documentation at https://www.landmarkcloudservices.com/ description: >- Which cross-cutting and industry standards the Landmark Cloud Services APIs actually conform to, asserted from the machine-readable contracts and the published documentation. Landmark makes no explicit conformance or certification claim anywhere in its public API surface, so every entry here is derived evidence rather than a vendor claim. standards: - id: openapi-3 conforms: true evidence: >- Five public OpenAPI documents, versions 3.0.1, 3.0.3 and 3.0.4, published as the rendered reference on landmarkcloudservices.com. - id: oauth2 conforms: true evidence: >- securitySchemes declare oauth2 with the clientCredentials flow against https://lmkmaster.eu.auth0.com/oauth/token; four further specs declare the resulting JWT as an http bearer scheme. - id: oauth2-client-credentials conforms: true evidence: RFC 6749 section 4.4 grant, with an audience parameter per environment. - id: oidc-discovery conforms: true evidence: >- The authorization server publishes /.well-known/openid-configuration and /.well-known/oauth-authorization-server (Auth0 tenant lmkmaster.eu.auth0.com); captured in well-known/ and authentication/. - id: rfc8414-authorization-server-metadata conforms: true evidence: /.well-known/oauth-authorization-server returns 200 on the Auth0 tenant. - id: jwt conforms: true evidence: bearerFormat JWT on every http bearer scheme; jwks_uri published by the tenant. - id: rfc9457-problem-details conforms: partial evidence: >- Every error response is served as application/problem+json, but the body uses Landmark members (status, code, title, messages[]) instead of the RFC's type/title/status/detail/instance, and no dereferenceable problem type URI is published. - id: w3c-trace-context conforms: true evidence: >- A traceparent request header is accepted and validated (a malformed value returns 400 with error code 40002); every response carries a traceresponse header. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header support and no deprecation policy is published. - id: idempotency-key conforms: false evidence: No idempotency key header or parameter appears in any spec or in the documentation. - id: odata-v4 conforms: false evidence: >- The Conveyancing Experience API borrows $filter, $orderby, $top and $skip query syntax but publishes no $metadata document and no OData service root; it is OData-flavoured, not OData. - id: json-api conforms: false - id: hal conforms: false - id: asyncapi conforms: false evidence: >- A real event surface exists (OpenAPI callbacks objects on the Milestone Notification Service and Compliance/Order APIs) but no AsyncAPI document is published. See asyncapi/landmark-information-webhooks.yml. - id: webhooks conforms: true evidence: >- Nine typed valuation milestone notifications plus an order status callback, with three supported outbound authentication mechanisms. - id: openapi-webhooks-object conforms: false evidence: Events are modelled with the operation-level callbacks object, not the OpenAPI 3.1 webhooks object. - id: ogc-wmts conforms: true evidence: >- Landmark markets its Geodata tile service explicitly against the OGC Web Map Tile Service standard, but publishes no endpoint and no GetCapabilities document, so conformance cannot be verified against a live service. - id: reso-web-api conforms: false evidence: >- RESO is a North American MLS construct with no UK equivalent; nothing in Landmark's surface references RESO, the RESO Data Dictionary or a Universal Property Identifier. - id: fhir-r4 conforms: false - id: scim2 conforms: false - id: fapi conforms: false uk_domain_identifiers: - id: uprn present: true evidence: >- UPRN (Unique Property Reference Number) is one of the 19 documented attributes of the Planning API, consistent with Landmark's Ordnance Survey AddressBase supply. - id: hm-land-registry-title-number present: true evidence: Scottish Title Check and Landmark Ownership Check products in the Compliance/Order API. certifications_published: false certifications: [] certifications_note: >- No trust centre, certification page or compliance statement could be verified. The corporate site www.landmark.co.uk sits behind an edge WAF that returns 403 to automated clients, so an absence of evidence here is not evidence that Landmark holds no certifications - it means none could be confirmed from a machine-readable or fetchable source. No Compliance pointer is emitted for that reason.