generated: '2026-07-27' method: derived source: openapi/utilita-status-openapi.yml + live probes 2026-07-27 scope: >- Standards conformance for the Utilita Status API, the provider's only public API surface, plus the sector standards that do and do not apply to Utilita as a GB licensed energy supplier. standards: - id: rest-json conforms: true evidence: Eight resource-oriented GET endpoints returning application/json over HTTPS. - id: openapi conforms: false evidence: Utilita publishes no OpenAPI document. openapi/utilita-status-openapi.yml was generated by API Evangelist from live observation. - id: rfc9457-problem-details conforms: false evidence: 'Errors are returned as {"errors":["..."]} with content-type application/json, not application/problem+json.' - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on utilita.co.uk and my.utilita.co.uk. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header support; no deprecation policy published. - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog returns 404. - id: oauth2 conforms: false evidence: No OAuth 2.0 authorization server, no /.well-known/oauth-authorization-server (404). - id: openid-connect conforms: false evidence: No OIDC discovery document on any probed host (404/403). - id: cors conforms: true evidence: 'Access-Control-Allow-Origin: * with Access-Control-Expose-Headers: ETag on every status API response.' - id: http-conditional-requests conforms: true evidence: Weak ETag returned with a public Cache-Control max-age=10 / stale-while-revalidate policy. - id: rss-2.0 conforms: true evidence: https://status.utilita.co.uk/history.rss returns RSS 2.0 (HTTP 200). - id: atom-1.0 conforms: true evidence: https://status.utilita.co.uk/history.atom returns an Atom feed (HTTP 200). - id: asyncapi conforms: false evidence: No AsyncAPI document; webhook payload schemas are not published (see asyncapi/utilita-status-webhooks.yml). - id: green-button-espi conforms: false evidence: No Green Button / ESPI energy usage export. Not adopted and not mandated in Great Britain. - id: cdr-energy conforms: false evidence: The Australian Consumer Data Right does not apply; Great Britain has no equivalent energy data-portability right. - id: smart-energy-code conforms: true evidence: >- Utilita holds an Ofgem supply licence and is obliged by licence condition to accede to the Smart Energy Code and operate as a DCC User. This is a device/communications and governance obligation over the private DCC User Interface — it is not an API standard and produces no public API. note: Infrastructure mandate, not a data-sharing mandate. See review.yml. - id: iec-cim-61968 conforms: false evidence: No CIM-based data exchange published. - id: ocpp-ocpi conforms: false evidence: No EV charging interfaces published. compliance_program: published: false certifications: [] detail: >- No trust centre, no SOC 2 / ISO 27001 / PCI DSS attestation page, and no security or compliance documentation was found on any Utilita host (probed 2026-07-27). No `Compliance` pointer is wired. Utilita's obligations are regulatory (Ofgem supply licence, Smart Energy Code, UK GDPR) rather than a published certification programme.