generated: '2026-08-02' method: searched source: https://documentation.replicahq.com/ description: >- Standards and reference data conformance for Replica. Replica is a data provider, not an API provider - it publishes no OpenAPI, no OAuth/OIDC surface and no REST error contract, so the usual API-protocol conformance rows are recorded as not-applicable. What Replica does conform to are the geospatial, transportation and statistical reference standards its datasets are built on and keyed to; every row below is evidenced by a specific documentation page. standards: - id: openstreetmap name: OpenStreetMap road network conforms: true evidence: 'Network link functional classifications (freeway, trunk, primary, secondary, tertiary) are derived from OpenStreetMap; every link carries an osm_id (OSM Way ID) with a stated OSM extract version, and street_name matches the OSM-assigned name.' source: https://documentation.replicahq.com/docs/network-links - id: gtfs name: GTFS (General Transit Feed Specification) conforms: true evidence: Transit routes and schedules in the transit trip tables are sourced from agency GTFS feeds; release notes track the number of transit agencies and GTFS feeds added per season. source: https://documentation.replicahq.com/docs/transit - id: census-fips name: US Census FIPS geographic identifiers conforms: true evidence: 'geoid fields carry the FIPS code when the geographic feature is a Census geography; trip origins and destinations are keyed to Census block groups (bgrp).' source: https://documentation.replicahq.com/docs/daily-vmt - id: census-acs-pums name: US Census ACS / PUMS / CTPP / LEHD inputs conforms: true evidence: The synthetic population and demographics/employment tables are built from American Community Survey, PUMS, CTPP and LEHD inputs. source: https://documentation.replicahq.com/docs/seasonal-mobility-model-methodology-extended-places - id: naics name: NAICS industry classification conforms: true evidence: Consumer spending transactions were categorized by the merchant's NAICS code (dataset family discontinued 2024-12-28). source: https://documentation.replicahq.com/docs/weekly-spend-by-merchant-location - id: hpms name: FHWA HPMS (Highway Performance Monitoring System) conforms: true evidence: 'Ground-truth AADT values are derived from HPMS data conflated to Replica''s roadway network representation; documentation states the most up-to-date HPMS data available is used.' source: https://documentation.replicahq.com/docs/annual-average-daily-traffic-aadt - id: nhtsa-fars name: NHTSA FARS crash data conforms: true evidence: Crash datasets incorporate NHTSA FARS fatality records. source: https://documentation.replicahq.com/docs/crash-data - id: wgs84 name: WGS 84 (EPSG:4326) coordinate reference system conforms: true evidence: Latitude/longitude fields across the trip and geography tables are documented as WGS 84. source: https://documentation.replicahq.com/docs/disaggregate-trip-tables - id: h3 name: Uber H3 hierarchical hexagonal grid conforms: true evidence: Daily origin-destination pairs and several application datasets are aggregated to H3 cells of resolution 8. source: https://documentation.replicahq.com/docs/daily-o-d-data - id: wkt-geojson name: WKT / GeoJSON geometry encodings conforms: true evidence: 'Network-link and intersection geometry fields are published as WKT; several datasets are additionally offered as GeoJSON and shapefile exports.' source: https://documentation.replicahq.com/docs/free-flow-speed-per-network-link - id: privacy-by-design name: Published privacy-preserving data principles conforms: true evidence: 'Replica publishes an "Approach to Privacy" document committing to: procuring only de-identified data and never receiving/using/outputting PII; never sharing raw locational data; never joining sources on sensitive keys; statistical noise injection defending against membership -inclusion and location-inference attacks; and physical/logical separation of sensitive data storage. These principles are codified in a Data Protection Addendum in customer agreements.' source: https://documentation.replicahq.com/docs/approach-to-privacy - id: openapi name: OpenAPI conforms: false evidence: 'No OpenAPI/Swagger document found. Probed replicahq.com, documentation.replicahq.com, studio.replicahq.com and api.studio.replicahq.com for /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs and /redoc - all 404 or SPA HTML shells.' - id: graphql name: GraphQL conforms: false evidence: '/graphql returns 404 on api.studio.replicahq.com; no GraphQL surface advertised.' - id: asyncapi name: AsyncAPI / webhooks conforms: false evidence: No event, streaming or webhook surface is documented. Not applicable - Replica delivers batch data products. - id: oauth2 name: OAuth 2.0 conforms: false evidence: 'No OAuth surface. /.well-known/oauth-authorization-server returns 404 on every host. The Replica Studio backend authenticates with an Express session cookie (replica.sid).' - id: oidc name: OpenID Connect conforms: false evidence: /.well-known/openid-configuration returns 404 on every probed host. - id: rfc9457-problem-details name: RFC 9457 Problem Details conforms: false evidence: 'The private Studio backend returns a bespoke JSON envelope {status, message, requestId} with content-type application/json, not application/problem+json. Not a published contract.' - id: rfc9116-security-txt name: RFC 9116 security.txt conforms: false evidence: /.well-known/security.txt returns the SPA HTML shell on replicahq.com and 404 on the documentation, studio and API hosts. - id: a2a-agent-card name: A2A Agent Card conforms: false evidence: '/.well-known/agent-card.json and /.well-known/agent.json return HTML SPA catch-alls on replicahq.com and 404 on documentation.replicahq.com, studio.replicahq.com and api.studio.replicahq.com. No agent card published.' - id: llms-txt name: llms.txt conforms: true evidence: 'https://documentation.replicahq.com/llms.txt returns a real llms.txt (HTTP 200, text/plain) indexing 31 documentation pages. Saved verbatim to llms/replica-llms.txt.' certifications: [] compliance_program_published: false compliance_note: >- No trust center, certification page or named certification (SOC 2, ISO 27001, HIPAA, FedRAMP, StateRAMP, CJIS) was found for replicahq.com. Probes of trust.replicahq.com and security.replicahq.com do not resolve. NOTE: web results claiming "Replica achieved SOC 2 Type II" belong to Replica Cyber (replicacyber.com), a different company with the same brand name - do not attribute them here. x-evidence: fetched: '2026-08-02' hosts_probed: [replicahq.com, www.replicahq.com, documentation.replicahq.com, help.replicahq.com, studio.replicahq.com, api.studio.replicahq.com]