generated: '2026-07-28' method: derived source: >- Derived from the three harvested service descriptors in capabilities/ and the live probes recorded in review.yml (2026-07-28), plus the Open Government Licence - Canada terms. Transport Canada publishes no conformance or compliance statement of its own for these interfaces. description: >- Which cross-cutting and industry standards Transport Canada's public interfaces actually conform to. The honest headline: one interface is a real open standard (OGC WMS 1.3.0), one is a widely-implemented de facto interface (Esri ArcGIS REST), one is entirely bespoke (the Vehicle Recalls Database API), and the portal layer above them is CKAN. standards: - id: ogc-wms-1.3.0 conforms: true evidence: >- capabilities/transport-canada-airports-wms-capabilities.xml is a WMS_Capabilities version="1.3.0" document declaring xsi:schemaLocation against http://schemas.opengis.net/wms/1.3.0/capabilities_1_3_0.xsd and advertising GetCapabilities, GetMap, GetFeatureInfo, GetLegendGraphic and the ESRI GetStyles extension, with CRS:84, EPSG:4326 and EPSG:3978. - id: ogc-sld conforms: true evidence: >- The esri_wms:GetStyles request advertises application/vnd.ogc.sld+xml in the capabilities document. - id: esri-arcgis-rest-10.81 conforms: true evidence: >- capabilities/transport-canada-airports-arcgis-mapserver.json reports currentVersion 10.81 with capabilities "Map,Data,Query" and supportedQueryFormats "JSON, geoJSON". A de facto industry interface implemented by many servers and consumable by any Esri or GDAL/OGR client — not an open standard. - id: geojson-rfc7946 conforms: partial evidence: >- The MapServer declares geoJSON as a supported query output format and the WMS declares application/geojson for GetFeatureInfo. Esri's geoJSON emitter is broadly RFC 7946-shaped; no formal conformance claim is made by the publisher. - id: ckan-action-api-2.8 conforms: true evidence: >- Transport Canada's 49 datasets are indexed through the CKAN Action API at open.canada.ca/data/en/api/3/action/ (organization_show?id=tc returned 200, package_count 49). Documented against docs.ckan.org/en/2.8/api. Operated by Treasury Board Secretariat for the whole Government of Canada, NOT by Transport Canada. - id: open-government-licence-canada conforms: true evidence: >- Declared in the WMS element and on every open.canada.ca dataset record. A data licence, not an interface standard. - id: dcat conforms: partial evidence: >- open.canada.ca exposes CKAN dataset metadata and publishes DCAT/schema.org serialisations at the portal level. This is a Treasury Board Secretariat capability applied to Transport Canada's records, not something Transport Canada implements. - id: openapi conforms: false evidence: >- No OpenAPI or Swagger document is published on tc.canada.ca, data.tc.gc.ca or github.com/tc-ca. GitHub code search across org:tc-ca for filename:openapi and filename:swagger both returned total_count 0 (2026-07-28). - id: asyncapi conforms: false evidence: No event, streaming or webhook surface exists to describe. - id: graphql conforms: false evidence: No /graphql endpoint on any Transport Canada host. - id: oauth2 conforms: false evidence: No authorization server, no token endpoint, no client registration. Access is anonymous. - id: oidc conforms: false evidence: No /.well-known/openid-configuration on any probed host. - id: rfc9457-problem-details conforms: false evidence: >- The recalls API returns {"Message":"The request is invalid."} as plain application/json on a 400; no application/problem+json anywhere. The WMS uses OGC ServiceExceptionReport instead. - id: rfc9116-security-txt conforms: false evidence: https://tc.canada.ca/.well-known/security.txt returned 404 (review.yml probes). - id: rfc8594-sunset-header conforms: false evidence: No deprecation or sunset signalling on any endpoint; no deprecation policy published. - id: idempotency conforms: not-applicable evidence: >- Read-only estate. Every published operation is a GET, so idempotency keys have nothing to protect. - id: pagination conforms: partial evidence: >- The ArcGIS MapServer paginates via maxRecordCount 1000 plus exceededTransferLimit / resultOffset. The Vehicle Recalls Database API exposes no pagination parameter at all. - id: json-api conforms: false - id: odata conforms: false - id: scim conforms: false - id: fhir-r4 conforms: false - id: fapi conforms: false - id: psd2 conforms: false compliance_program: published: false note: >- Transport Canada publishes no SOC 2, ISO 27001, PCI DSS, FedRAMP-equivalent or Protected-B attestation for these public interfaces, and no trust centre. Government of Canada IT security policy (the Policy on Government Security and ITSG-33) applies departmentally but is not published as an API-level compliance claim, so no Compliance pointer is emitted. Recording the absence rather than asserting an unevidenced certification. regulatory_context: note: >- Transport Canada is itself a regulator. The instruments it administers — the Aeronautics Act and Canadian Aviation Regulations, the Motor Vehicle Safety Act, the Canada Shipping Act — are the source of the data these APIs publish, not conformance obligations on the APIs. Airline economic licensing, all-in fare advertising and the Air Passenger Protection Regulations belong to the separate Canadian Transportation Agency.