generated: '2026-09-04' method: searched source: - https://my-wingtra.eu.auth0.com/.well-known/openid-configuration - https://api.my.wingtra.com/graphql - graphql/wingtra-my-portal.graphql - https://wingtra.com/government/blue-uas-drone/ - https://wingtra.com/government/compliant-ndaa-surveying-drone/ - https://wingtra.com/wingtra-achieves-green-uas-certification/ - https://wingtra.com/wingtraray-achieves-c6-certification-for-expanded-operations-in-europe/ note: >- Two different kinds of claim are recorded here and they are deliberately kept apart. `conformance[]` is what the API surfaces actually conform to, established by probe. `certifications[]` is what Wingtra publishes about its aircraft — real, named, third-party programmes with issuing bodies, and the reason a `Compliance` pointer is emitted — but they certify hardware and firmware supply chain and cyber posture, not the API contract, and none of them is a SOC 2 / ISO 27001 style audit of the WingtraCLOUD service. conformance: - id: oauth2 conforms: true evidence: https://my-wingtra.eu.auth0.com/.well-known/oauth-authorization-server detail: >- RFC 8414 authorization server metadata served, HTTP 200. Advertises authorization_code, refresh_token, client_credentials, device_code, token-exchange and jwt-bearer grants. - id: oidc conforms: true evidence: https://my-wingtra.eu.auth0.com/.well-known/openid-configuration detail: >- OpenID Connect Discovery 1.0 document served, HTTP 200. Issuer, jwks_uri, userinfo, RS256/PS256 id_token signing, 14 scopes, 16 claims. - id: pkce conforms: true evidence: https://my-wingtra.eu.auth0.com/.well-known/openid-configuration detail: >- code_challenge_methods_supported [S256, plain]; portal.wingtra.com's own login redirect was observed carrying code_challenge_method=S256. - id: rfc8414 conforms: true evidence: https://my-wingtra.eu.auth0.com/.well-known/oauth-authorization-server - id: graphql conforms: true evidence: https://api.my.wingtra.com/graphql detail: >- Serves a spec-conformant introspection response over the June 2018 GraphQL schema introspection contract; 84 types resolved anonymously. - id: rfc9457 conforms: false evidence: errors/wingtra-problem-types.yml detail: No application/problem+json anywhere; failures are free-text `error` strings at HTTP 200. - id: rfc9116 conforms: false evidence: well-known/wingtra-well-known.yml detail: No security.txt on any of the 11 hosts probed. - id: idempotency conforms: false evidence: conventions/wingtra-conventions.yml detail: No idempotency key on any of the 33 mutations. - id: pagination conforms: false evidence: graphql/wingtra-my-portal.graphql detail: No Relay connections, no cursor or offset arguments, no pageInfo. Lists are unbounded. - id: rfc8594 conforms: false evidence: lifecycle/wingtra-lifecycle.yml detail: No Sunset or Deprecation headers, and no deprecation policy. - id: openapi conforms: false evidence: well-known/wingtra-well-known.yml detail: >- No OpenAPI or Swagger document is served on any host. /openapi.json, /openapi.yaml, /swagger.json, /api-docs, /docs, /redoc and /v1/openapi.json were probed on api.my.wingtra.com (404 on each), api.sky.wingtra.com (400 on each) and api.updater.wingtra.com (404 on each). domain_standard: market: geospatial / aerial survey declared_in_contract: false detail: >- Nothing in the GraphQL schema declares a domain standard — no OGC conformance class, no SCIM URN, no OData $metadata, no OAI-PMH verb. Probing for an OGC surface was not warranted: no baseURL, docs link or prose names WMS/WFS/WCS/WMTS/CSW or "OGC API" as something Wingtra serves. Where geospatial standards appear at all, Wingtra is the CONSUMER — WingtraPRO imports WMS layers published by others, and the software resolves against 6,500+ published EPSG coordinate system definitions and reads Trimble .T02/.T04 and RINEX. Consuming a standard is not conformance to it, and this is a reward-only dimension, so nothing is claimed. consumed_standards: - {name: EPSG coordinate reference systems, role: consumer, evidence: 'https://wingtra.com/software/plans/'} - {name: OGC WMS, role: consumer (layer import), evidence: 'https://wingtra.com/software/plans/'} - {name: RINEX, role: consumer (GNSS observation exchange), evidence: 'https://wingtra.com/software/'} - {name: 'ASPRS LAS/LAZ', role: producer/consumer (point cloud output), evidence: 'https://wingtra.com/software/'} - {name: OGC KML 2.2, role: consumer (flight plan import), evidence: 'https://wingtra.com/software/plans/'} certifications: - name: Blue UAS Cleared List issuer: US Defense Innovation Unit (DIU) scope: aircraft evidence: https://wingtra.com/government/blue-uas-drone/ - name: NDAA Section 848 compliant hardware issuer: US statute (self-declared compliance) scope: aircraft supply chain evidence: https://wingtra.com/government/compliant-ndaa-surveying-drone/ - name: DIU Authority to Operate (ATO) issuer: US Defense Innovation Unit (DIU) scope: aircraft evidence: https://wingtra.com/government/blue-uas-drone/ - name: Green UAS certification issuer: AUVSI scope: aircraft evidence: https://wingtra.com/wingtra-achieves-green-uas-certification/ - name: FAA Category 3 operations over people issuer: US Federal Aviation Administration scope: aircraft operations evidence: https://wingtra.com/government/blue-uas-drone/ - name: C6 class certification issuer: EU / EASA class marking scope: WingtraRAY, European operations evidence: https://wingtra.com/wingtraray-achieves-c6-certification-for-expanded-operations-in-europe/ information_security_audits: soc2: not published iso27001: not published pci: not applicable hipaa: not applicable fedramp: not published trust_center: none detail: >- probe-security-programs.py found no trust center and no vulnerability disclosure programme: trust.wingtra.com and security.wingtra.com do not resolve, /security and /compliance 404, and no security.txt is served. Wingtra states its Blue sUAS builds are "tested for cyber security with every update" and publishes a Blue cyber security guide in the knowledge base, but names no audit standard and no auditor. No `Security` pointer is emitted, because there is no disclosure programme to point at. x-evidence: fetched: '2026-09-04' probes: - {url: 'https://my-wingtra.eu.auth0.com/.well-known/openid-configuration', http_status: 200} - {url: 'https://api.my.wingtra.com/graphql', http_status: 200} - {url: 'https://wingtra.com/government/blue-uas-drone/', http_status: 200} - {url: 'https://wingtra.com/security/', http_status: 404} - {url: 'https://api.my.wingtra.com/openapi.json', http_status: 404}