generated: '2026-09-04' method: probed source: 'Live probes of https://api.worldia.com plus json-ld/ context documents, 2026-09-04' name: Worldia Standards Conformance description: >- Cross-cutting and domain standards the Worldia API demonstrably implements, asserted against evidence fetched from the running API rather than against marketing claims — Worldia publishes no compliance page, no trust center and no developer documentation in which to claim anything. Each entry records what was checked and where. conformance: - id: json-ld-1.1 name: JSON-LD conforms: true evidence: >- GET https://api.worldia.com/channels with Accept: application/ld+json returns HTTP 200 content-type application/ld+json with @context, @id and @type members. Sixteen dereferenceable context documents are served at /contexts/{Type} and saved verbatim in json-ld/. strength: strong - id: hydra-core name: 'W3C Hydra Core Vocabulary' conforms: partial evidence: >- Responses use hydra:Collection, hydra:totalItems, hydra:member, hydra:PartialCollectionView (hydra:first/last/next) and, on /locations, a hydra:IriTemplate under hydra:search with per-variable hydra:mapping. Every response carries the Link header '; rel="http://www.w3.org/ns/hydra/core#apiDocumentation"'. gap: >- The advertised apiDocumentation document returns HTTP 404 under every Accept header tried (application/ld+json, application/vnd.openapi+json, application/json, text/html) and under the vendor X-Standard header. Hydra's central affordance is that a client bootstraps from the apiDocumentation entry point; here the pointer is emitted on every response and the target is not served, so the hypermedia contract advertises itself and then dead-ends. This is the single highest-value fix available to Worldia: the document is generated by API Platform and would expose the operation set the company currently publishes nowhere. strength: partial - id: rfc7807 name: 'RFC 7807 Problem Details for HTTP APIs' conforms: partial evidence: >- Errors are returned as application/problem+json with type, title, detail and (sometimes) status members — observed on 400, 403, 404 and 406 responses. gap: >- The `type` member is the constant https://tools.ietf.org/html/rfc2616#section-10 on every error regardless of cause, so it cannot be used as the machine-readable discriminator the specification intends; `title` is likewise the constant "An error occurred". `status` is present on some responses and absent on others. Authentication failures bypass problem+json entirely and return {"code":401,"message":"..."}. strength: partial - id: rfc9457 name: 'RFC 9457 Problem Details (obsoletes 7807)' conforms: false evidence: >- Same responses as above. The media type is correct but the type-URI discipline that RFC 9457 rests on is not implemented; no problem type registry is published. strength: none - id: rfc9110-conditional-requests name: 'HTTP conditional requests (ETag)' conforms: partial evidence: 'GET /channels returns etag: "269176eba0851c4a" with cache-control: no-cache, private.' gap: 'If-None-Match handling was not verified by this probe; only ETag emission was observed.' strength: partial - id: w3c-trace-context name: 'W3C Trace Context' conforms: true evidence: >- `traceparent` appears in access-control-allow-headers on every response, and responses carry x-trace-id and x-span-id. Worldia open-sources the Symfony OpenTelemetry bundle that produces this (worldia/instrumentation-bundle 3.0.1, 78,735 installs). strength: strong - id: rfc6797-hsts name: 'RFC 6797 HTTP Strict Transport Security' conforms: true evidence: >- api.worldia.com returns strict-transport-security: max-age=2592000; includeSubDomains; preload. corp.worldia.com returns max-age=31536000 without those directives. strength: strong - id: schema-org name: 'schema.org vocabulary' conforms: partial evidence: >- Location resources are typed "@type": "https://schema.org/Place" in the JSON-LD representation, and embedded coordinate objects are typed the same way. gap: >- Adoption is limited to the geographic core. The travel-commerce types where schema.org has direct equivalents — Trip, LodgingBusiness, Reservation, Offer — use Worldia's own vocabulary namespace instead, so a consumer gets schema.org semantics for places and bespoke semantics for everything that is actually being sold. strength: partial - id: iata-airport-codes name: 'IATA / ICAO location identifiers' conforms: true evidence: >- json-ld/worldia-context-airport.jsonld declares iataCode, icaoCode and cityIataCode as first-class properties of the Airport type. strength: moderate note: >- Identifier-scheme adoption only. It means an integrator can join Worldia's airport reference data to any other system keyed on IATA codes without a mapping table, which is real value — but it is not conformance to an airline-distribution message standard. - id: iso-4217 name: 'ISO 4217 currency codes' conforms: true evidence: >- Channel declares defaultCurrencyCode and currencies; the live channel B2B-LTUR-DE returns defaultCurrencyCode "EUR". strength: moderate - id: iso-639-3166-locales name: 'ISO 639 / ISO 3166 language and country codes' conforms: true evidence: >- Channel declares defaultLocaleCode, fallbackLocaleCode, defaultRegionalLocaleCode, countryCode and billingCountry; Location IRIs are built on ISO 3166 country codes (/locations/io/re for Reunion). strength: moderate - id: rfc9727-api-catalog name: 'RFC 9727 api-catalog well-known URI' conforms: false evidence: >- No Worldia host serves /.well-known/api-catalog. careers.worldia.com does return one (HTTP 200, application/linkset+json), but that host is a hosted Teamtailor careers site and the document is a Teamtailor platform feature describing its job feed — its own service-doc link points at docs.teamtailor.com. It is not Worldia's publication and is not counted. See well-known/worldia-well-known.yml. strength: none domain_standard: applicable: true sector: 'Travel distribution / tourism' declared: false finding: >- Worldia's contract declares no travel-industry message standard. The candidates for this market — OpenTravel Alliance (OTA) XML/JSON schemas, IATA NDC, HTNG for hospitality, and the GDS message formats — appear nowhere in any context document or response. The model is entirely Worldia's own vocabulary namespaced under https://api.worldia.com/docs.jsonld#, with the exceptions noted above (schema.org for places, IATA/ICAO for airports, ISO codes for currency and locale). consequence: >- An integrator who already speaks OTA or NDC gains nothing from that fluency here and needs a bespoke connector. This is a reward-only dimension and Worldia is not penalised for it; it is recorded because it is the honest answer to "can I reuse my existing travel-standard integration", and the answer is no. probed_for: [opentravel, ota, iata-ndc, htng, hedna, gds-message-formats] probe_method: >- Case-insensitive search across all sixteen context documents and every live response body captured, plus inspection of the type list at /contexts/{Type}. regulatory_signals: - regime: 'EU Package Travel Directive (2015/2302)' signal: >- Channel declares euPackageRights and financialProtection as per-tenant document references, and the consumer-facing terms of sale, insurance conditions and legal notice are published as per-market PDFs on static.worldia.com. conforms: unassessed note: >- This is a signal that the platform is built for regulated package-travel distribution across partner brands, read from the data model. It is NOT an assertion that Worldia complies with the directive — that is a legal determination this pipeline does not make and has no evidence for. compliance_certifications: published: false note: >- No SOC 2, ISO 27001, PCI DSS or other certification is published on any Worldia surface. corp.worldia.com has no /security, /trust, /compliance or /legal page (all 404), no trust center exists at trust.worldia.com (404), and probe-security-programs.py returned vdp=none trust=none. No Compliance pointer is wired in apis.yml, because there is no published compliance program to point at. not_applicable: - id: oauth2 reason: 'Bearer JWT only; no OAuth2 authorization server (both well-known documents 404 on every host).' - id: openid-connect reason: 'No /.well-known/openid-configuration on any host.' - id: fhir reason: 'Not a healthcare provider.' - id: psd2 reason: 'Not a payment service provider; Worldia records payments against trips but does not offer a payments API.' - id: scim reason: 'No identity-provisioning surface.' - id: odata reason: 'No $metadata surface; the API is API Platform REST with JSON-LD/Hydra.' - id: ogc reason: >- Geographic data is present (Location, Place, coordinates) but there is no OGC surface — no /conformance document, no WMS/WFS/WCS/WMTS GetCapabilities endpoint, and no prose naming an OGC service. Not probed with blind path patterns, per pipeline policy.