generated: '2026-07-27' method: searched source: >- SEARCHED the Consumer Data Standards v1.36.0 (Security Profile, High Level Standards, Non-functional Requirements) and the CDR Register, and DERIVED from the harvested OpenAPI in ../openapi/. Several entries are marked behaviourally_verified where a live call against Red Energy's own surfaces on 2026-07-27 proved conformance rather than asserting it. provider: Red Energy providerId: red-energy docs: https://consumerdatastandardsaustralia.github.io/standards/ context: >- Red Energy makes no conformance claim of its own — its website is unreachable to programmatic clients. Conformance here is (a) a statutory obligation under Part IVD of the Competition and Consumer Act 2010, evidenced by its listing on the CDR Register, and (b) where possible, demonstrated by observed behaviour. standards: - id: cds-au-1.36.0 name: CDR Consumer Data Standards (Australia), version 1.36.0 conforms: true behaviourally_verified: true evidence: >- Listed on the CDR Register as an energy data holder brand (dataHolderBrandId 39230258-a56c-ee11-a81c-002248e31327, HTTP 200 on 2026-07-27). Its registered public base URI serves the CDS Common API discovery endpoints, and CDS version negotiation behaves exactly to standard — HTTP 200 with x-v 1, HTTP 400 with no x-v header, HTTP 406 with an unsupported x-v. url: https://consumerdatastandardsaustralia.github.io/standards/ - id: cdr-energy-designation name: Consumer Data Right — energy sector designation conforms: true evidence: >- Red Energy Pty Ltd (ABN 60 107 479 372) is a designated CDR energy data holder. Confirmed in the CDR Register energy data holder brands summary. url: https://api.cdr.gov.au/cdr-register/v1/energy/data-holders/brands/summary - id: openapi-3.0.3 name: OpenAPI Specification 3.0.3 conforms: true evidence: >- The contract Red Energy implements is published as OpenAPI 3.0.3 by the Data Standards Body — cds_energy 1.36.0 (23 operations) and cds_common 1.36.0 (4 operations), harvested verbatim into ../openapi/. - id: oauth2 name: OAuth 2.0 (RFC 6749) conforms: true behaviourally_verified: false evidence: >- Required by the CDS Security Profile for the consumer-authorised half. Authorization Code flow with PKCE S256. Not observable anonymously. scope: consumer-authorised operations only - id: oidc name: OpenID Connect Core 1.0 conforms: true behaviourally_verified: false evidence: >- Required by the CDS Security Profile. Pairwise pseudonymous subject identifiers, ID Tokens signed with ES256 or PS256, an OpenID Provider Configuration document published to accredited participants. probe: url: https://public.cdr.redenergy.com.au/.well-known/openid-configuration status: 404 note: No anonymous OIDC discovery document; the infosec base URI is register-authenticated only. - id: fapi-1.0-advanced name: FAPI 1.0 Advanced (Financial-grade API Security Profile) conforms: true behaviourally_verified: false evidence: >- The CDS Security Profile is built on FAPI 1.0 Advanced — pushed authorisation requests, signed request objects, private_key_jwt client authentication, and mutual-TLS sender-constrained access tokens. scope: consumer-authorised operations only - id: rfc8705-mtls name: OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access Tokens (RFC 8705) conforms: true behaviourally_verified: false evidence: >- tls_client_certificate_bound_access_tokens is true across the CDR ecosystem; resource requests must be validated so the client certificate matches the access token. Certificates must be issued by the CDR CA. - id: rfc9126-par name: OAuth 2.0 Pushed Authorization Requests (RFC 9126) conforms: true behaviourally_verified: false evidence: require_pushed_authorization_requests is true in the CDS OpenID Provider Configuration profile. - id: rfc7636-pkce name: Proof Key for Code Exchange (RFC 7636) conforms: true behaviourally_verified: false evidence: code_challenge_methods_supported S256 in the CDS Security Profile. - id: rfc4122-uuid name: UUID (RFC 4122) conforms: true behaviourally_verified: true evidence: >- x-fapi-interaction-id is an RFC 4122 UUID correlation id, played back on every response. Observed on the AER Product Reference Data host on 2026-07-27. - id: cds-version-negotiation name: CDS endpoint version negotiation (x-v / x-min-v) conforms: true behaviourally_verified: true evidence: >- Verified live on both Red Energy public surfaces on 2026-07-27 — 200 at the supported version, 400 Header/Missing with no x-v, 406 Header/UnsupportedVersion above the maximum, and the maximum version reported in the error detail. - id: cds-error-envelope name: CDS errors[] error envelope (code/title/detail, urn:au-cds URNs) conforms: true behaviourally_verified: true partial: true evidence: >- Observed on 400, 404 and 406 responses. One deviation recorded — the 404 Resource/NotFound response from the AER Product Reference Data host omits the detail field, which the standard says MUST be present. detail: errors/red-energy-problem-types.yml - id: rfc9457-problem-details name: Problem Details for HTTP APIs (RFC 9457) conforms: false evidence: >- The CDS define their own errors[] envelope served as application/json. No application/problem+json is used anywhere in the harvested specs or in the observed responses. - id: cds-pagination name: CDS offset pagination (page / page-size, links, meta.totalRecords) conforms: true behaviourally_verified: true evidence: >- GET /energy/plans?page=1&page-size=1 returned meta.totalRecords 1705, meta.totalPages 1705 and links.self / links.next / links.last on 2026-07-27. - id: idempotency name: Idempotency keys conforms: false evidence: >- Not applicable. The CDR data holder surface is read-only; no Idempotency-Key header exists in the standard or the specs. - id: rfc8594-sunset name: Sunset HTTP Header (RFC 8594) conforms: false evidence: >- The CDS retire endpoint versions on a published Endpoint Version Schedule rather than through Sunset or Deprecation response headers. - id: rfc9116-security-txt name: security.txt (RFC 9116) conforms: false evidence: >- /.well-known/security.txt returned 404 on public.cdr.redenergy.com.au and on cdr.energymadeeasy.gov.au, and 403 (Cloudflare) on www.redenergy.com.au, on 2026-07-27. See well-known/red-energy-well-known.yml. - id: rfc8414-oauth-metadata name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: unknown evidence: >- /.well-known/oauth-authorization-server returned 404 on the public base URI. The data holder's authorisation server metadata is published only to accredited participants, so this could not be assessed anonymously. - id: green-button-espi name: Green Button / NAESB ESPI conforms: false evidence: No reference found. Australia's energy data sharing standard is the CDS, not ESPI. - id: ocpp-ocpi name: OCPP / OCPI conforms: false evidence: Not applicable — Red Energy is a retailer, not an EV charging network operator. - id: openadr name: OpenADR conforms: false evidence: No demand-response API surface found. - id: ieee-2030.5 name: IEEE 2030.5 (Smart Energy Profile) conforms: false evidence: No reference found on any Red Energy surface. - id: iec-cim name: IEC Common Information Model (61968/61970) conforms: false evidence: No reference found. The CDS energy schemas are bespoke, not CIM-derived. compliance_program: regime: Consumer Data Right (Part IVD, Competition and Consumer Act 2010) regulator: Australian Competition and Consumer Commission (ACCC) standards_body: Treasury Data Standards Body privacy_regulator: Office of the Australian Information Commissioner (OAIC) privacy_safeguards: >- CDR Privacy Safeguards apply, including Privacy Safeguard 11 (data quality) and the requirement to correct CDR data. published_policy: name: Red Energy Consumer Data Right Policy url: https://www.redenergy.com.au/docs/Red-Energy-Consumer-Data-Right-Policy.pdf required_by: CDR Rules — every data holder must publish a CDR policy. fetch_status: 403 fetch_note: >- Returns HTTP 403 with a Cloudflare bot challenge to every programmatic client, including a browser user-agent. The document is indexed by search engines and its existence and title are verified that way, but its contents were NOT fetched and are not treated as fetched evidence here. conformance_testing: >- The ACCC operates a Conformance Test Suite that a participant must pass before activation on the CDR Register. Red Energy's active register entry implies it passed; no per-participant test report is public. certifications: [] certifications_note: >- No SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP certification was found for Red Energy, and no trust centre exists. Probes of trust./security./compliance surfaces returned nothing — see security/red-energy-domain-security.yml.