generated: '2026-07-27' method: derived source: >- openapi/southern-california-edison-drpep-arcgis-openapi.yml + live probes (2026-07-27) + https://www.sce.com/partners/3rd-party-energy-providers/access-energy-usage-data + https://www.sce.com/sites/default/files/inline-files/Rule26.pdf note: >- Conformance is asserted only where it was observed on the wire or stated by SCE in a first-party document. "claimed" means SCE says it and it could not be verified anonymously. standards: - id: esri-arcgis-rest name: Esri ArcGIS REST API (GeoServices) conforms: true evidence: >- ArcGIS Enterprise 11.1 REST interface; /arcgis_server/rest/info, folder catalogs, FeatureServer and /query all answer the standard contract anonymously (verified 2026-07-27). - id: geojson-rfc7946 name: GeoJSON (RFC 7946) conforms: true evidence: >- ICA_Layer/FeatureServer/0/query?f=geojson returned a GeoJSON FeatureCollection with LineString geometry (verified 2026-07-27). - id: dcat-us-1.1 name: DCAT-US 1.1 (Project Open Data) conforms: true evidence: >- https://drpep-sce2.opendata.arcgis.com/api/feed/dcat-us/1.1.json returns a dcat:Catalog with 47 datasets and conformsTo https://project-open-data.cio.gov/v1.1/schema (saved to arcgis/sce-drpep-hub-dcat-us-1.1.json). - id: dcat-ap-2.1.1 name: DCAT-AP 2.1.1 conforms: true evidence: https://drpep-sce2.opendata.arcgis.com/api/feed/dcat-ap/2.1.1 returns a DCAT-AP JSON-LD catalog (HTTP 200, 152 KB). - id: openapi name: OpenAPI conforms: false evidence: >- SCE publishes no OpenAPI. The document in openapi/ was generated by API Evangelist from live probes and is explicitly marked as such - it is not a provider artifact. - id: ogc-api-features name: OGC API - Features conforms: false evidence: >- .../ICA_Layer/OGCFeatureServer?f=json returns an ArcGIS error (code 500). The OGC interface is not enabled on these hosted services. - id: wms-wfs name: OGC WMS / WFS conforms: false evidence: No WMS or WFS endpoint is exposed on the DRPEP ArcGIS server; only FeatureServer. - id: oauth2 name: OAuth 2.0 (RFC 6749) conforms: claimed evidence: >- SCE states third parties must "complete customer authorization using OAuth 2.0" for Green Button Connect My Data. No authorization endpoint, token endpoint or scope list is published; nothing was observable anonymously. - id: oidc-discovery name: OpenID Connect Discovery 1.0 conforms: true scope: identity infrastructure only evidence: >- https://sce.okta.com/.well-known/openid-configuration returns a complete OIDC discovery document (HTTP 200). This covers SCE's Okta login estate, not an energy-data API. - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: true scope: identity infrastructure only evidence: https://sce.okta.com/.well-known/oauth-authorization-server returns AS metadata (HTTP 200). - id: naesb-espi name: NAESB REQ.21 Energy Services Provider Interface (Green Button) conforms: claimed evidence: >- SCE's third-party page names the NAESB standard for the Green Button Initiative, and Rule 26 states technical eligibility criteria change "consistent with the NAESB ESPI Standard". No ESPI resource, ApplicationInformation document, Atom feed or XSD is published, and no ESPI-shaped path on api.sce.com answers anonymously (all HTTP 500 gateway faults). - id: green-button-alliance-certification name: Green Button Alliance certification conforms: false evidence: >- greenbuttonalliance.org (HTTP 200) does not name SCE in its member/sponsor listing; /certified-products returned 404 so no register could be checked. No certification is claimed. - id: rfc9457 name: Problem Details for HTTP APIs (RFC 9457) conforms: false evidence: Errors use the ArcGIS envelope {"error":{"code","message","details"}} returned with HTTP 200; no application/problem+json anywhere. - id: rfc9116 name: security.txt (RFC 9116) conforms: false evidence: 404 on sce.com, drpep.sce.com, api.sce.com and edison.com. - id: rfc8594 name: Sunset HTTP header (RFC 8594) conforms: false evidence: No Sunset or Deprecation headers; no deprecation policy published. - id: ieee-2030.5 name: IEEE 2030.5 (Smart Energy Profile 2.0) conforms: false evidence: No reference found on any SCE surface probed. - id: iec-cim-61968 name: IEC CIM 61968/61970 conforms: false evidence: No reference found on any SCE surface probed. - id: openadr name: OpenADR conforms: false evidence: >- Not referenced on the public third-party pages. SCE's demand response lane runs under CPUC Rule 24 with a registration gate, not a published OpenADR endpoint. regulatory: - id: cpuc-rule-26 name: CPUC tariff Rule 26 - Release of Customer Data or Energy Usage Related Data to Third Parties applies: true status: in-force evidence: >- Advice 3087-E, filed 2014-07-30, effective 2014-08-29, implementing CPUC Decision 14-05-016. Tariff PDF fetched and read (HTTP 200, 239,298 bytes). - id: cpuc-rule-24 name: CPUC Rule 24 - Direct Participation Demand Response applies: true status: in-force evidence: https://www.sce.com/partners/3rd-party-energy-providers/rule-24-faqs (HTTP 200); support lane Rule24Support@sce.com. - id: cpuc-drp name: CPUC Distribution Resources Plan (ICA / GNA / DDOR / LNBA deliverables) applies: true status: in-force evidence: >- The entire DRPEP data set - Integration Capacity Analysis, Grid Needs Assessment, Distribution Deferral Opportunity Report, Locational Net Benefit Analysis - exists because the CPUC DRP proceeding requires it. certifications_published: found: false note: >- No trust center, SOC 2, ISO 27001, PCI DSS or FedRAMP claim was found on any SCE host (probe-security-programs.py returned trust=none, vdp=none). No Compliance pointer is emitted.