generated: '2026-08-09' method: derived source: - openapi/shipfinder-ais-data-api-openapi.yml - https://docs.shipfinder.com/ standards: - id: openapi-3.0 conforms: true evidence: Provider publishes an OpenAPI 3.0.1 fragment on every endpoint documentation page. - id: itu-r-m.1371-ais conforms: true evidence: Payloads carry ITU-R M.1371 AIS field semantics — MMSI, IMO, navistat, ship_type, sog, cog, hdg, rot — and the published navigation-status and vessel-type tables mirror the AIS message vocabulary. - id: un-locode conforms: true evidence: Port identifiers use UN/LOCODE (port_code, destcode, e.g. SGSGP / CNTZO). - id: wgs84 conforms: true evidence: Coordinates are documented as WGS84 decimal degrees on every geospatial field. - id: iala-aton conforms: true evidence: Aids-to-Navigation type codes follow the IALA/AIS AtoN type table published in the appendix. - id: rfc9457-problem-details conforms: false evidence: Errors are returned as a vendor {status,msg,data} envelope with HTTP 200, not application/problem+json. - id: rfc8594-sunset-header conforms: false evidence: No Sunset/Deprecation header documented. - id: oauth2 conforms: false evidence: API-key-only authentication; no OAuth 2.0 surface. - id: oidc conforms: false evidence: No /.well-known/openid-configuration on any host. - id: asyncapi conforms: false evidence: A webhook push surface exists and is documented, but the provider publishes no AsyncAPI document. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns the SPA catch-all HTML on every host (soft 404). - id: json-api conforms: false evidence: Custom envelope, not JSON:API. compliance_program: published: false evidence: No trust centre, SOC 2 / ISO 27001 / PCI / HIPAA / FedRAMP claim, or compliance page was found on shipfinder.com, open.shipfinder.com, docs.shipfinder.com or elaneglobal.com. trust.shipfinder.com does not resolve. x-evidence: fetched: '2026-08-09' derived_from: openapi/shipfinder-ais-data-api-openapi.yml