generated: '2026-08-05' method: derived source: >- grpc/utilidata-protobuf.yml, conventions/utilidata-conventions.yml, data-model/utilidata-data-model.yml, plus live probes of utilidata.com and developer.utilidata.com on 2026-08-05 summary: >- Utilidata's published surface conforms to a small set of infrastructure standards — proto3, the Prometheus text exposition format, ZeroMQ, Helm/Kubernetes — and to none of the API-description or API-security standards. There is no OpenAPI, no AsyncAPI, no GraphQL SDL, no OAuth, and no published compliance program. standards: - id: protobuf-proto3 conforms: true evidence: 'package utilidata.karman.bibimbap.v1, prost-build generated, proto3 optional field presence' - id: zeromq conforms: true evidence: 'PUB/SUB on tcp port 5557, topic "cycle-aligned" (charts/karman-lab/values.yaml)' - id: prometheus-text-exposition-0.0.4 conforms: true evidence: 'data-exporter sets Content-Type "text/plain; version=0.0.4; charset=utf-8" and serves prometheus::TextEncoder output on /metrics:9105' - id: openmetrics conforms: false evidence: 'exporter pins the legacy 0.0.4 text format; no application/openmetrics-text negotiation' - id: helm-3 conforms: true evidence: 'charts/karman-lab, Chart.lock with kube-prometheus-stack dependency' - id: oci-container-images conforms: true evidence: 'three first-party images on public.ecr.aws/k0f5s7n3/karman, registry v2 tags/list returns 200' - id: prometheus-operator-servicemonitor conforms: true evidence: 'charts/karman-lab/templates/data-exporter-servicemonitor.yaml, requires prometheus-operator CRDs' - id: apache-2.0 conforms: true evidence: 'LICENSE + NOTICE at repository root, Copyright (c) 2025 Utilidata' - id: grpc conforms: false evidence: 'the published protobuf package declares messages only — no service definitions' - id: openapi conforms: false evidence: 'no OpenAPI at any probed host; /openapi.json, /openapi.yaml, /swagger.json, /api-docs all 404 on utilidata.com and unreachable on developer.utilidata.com' - id: asyncapi conforms: false evidence: 'a real pub/sub event surface exists (ZeroMQ + protobuf) but no AsyncAPI document is published for it' - id: graphql conforms: false evidence: 'no /graphql surface found on any probed host' - id: json-schema conforms: false evidence: 'no JSON Schema published; the TimescaleDB sink stores frames as untyped JSONB' - id: oauth2 conforms: false evidence: 'no authentication layer in the published contract; /.well-known/oauth-authorization-server 404' - id: openid-connect conforms: false evidence: '/.well-known/openid-configuration returns 404 on utilidata.com' - id: rfc9457-problem-details conforms: false evidence: 'no HTTP error envelope; failures surface as ZeroMQ transport errors handled by a consumer-side retry loop' - id: rfc9116-security-txt conforms: false evidence: '/.well-known/security.txt returns 404 on utilidata.com' - id: rfc8615-well-known conforms: false evidence: 'every probed /.well-known/* path returns 404 on utilidata.com' - id: rfc8594-sunset-header conforms: false evidence: 'no deprecation or sunset policy published' - id: a2a-agent-card conforms: false evidence: '/.well-known/agent-card.json and /.well-known/agent.json both 404 on utilidata.com' - id: mcp conforms: false evidence: 'no MCP server advertised in docs, repositories, or registries' - id: llms-txt conforms: false evidence: '/llms.txt returns 404 on utilidata.com' compliance_program: published: false certifications: [] trust_center: null evidence: >- probe-security-programs.py returned vdp=none trust=none on 2026-08-05; utilidata.com/security, utilidata.com/trust and utilidata.com/blog all return 404. No SOC 2, ISO 27001, NERC CIP or other certification is claimed on the public site. x-note: >- No `Compliance` pointer is wired in apis.yml, because there is no published compliance program to point at. This is an observed absence, not an unchecked field. x-sector-note: >- Utilidata's grid-side product sits inside smart meters and grid-edge devices, a domain governed by NERC CIP, IEEE 1547 / 2030.5, ANSI C12.19/C12.22 and OpenADR. None of those are claimed or discoverable on the public surface, and the open-source module is a data-center reference implementation rather than a grid deployment, so no grid-standard conformance is asserted here either way.