generated: '2026-07-27' method: derived source: >- Derived from live probes of https://api.zap-map.com/v5/, the first-party client bundles, and a search of zapmap.com (Spark product pages, data licensing page, for-business pages) for standards and compliance claims. 2026-07-27. note: >- Zapmap makes NO conformance or certification claim anywhere on its public surface. Every entry below with conforms:false records a verified absence of evidence, not a tested failure. standards: - id: ocpi name: Open Charge Point Interface conforms: false evidence: >- No OCPI reference on any Zapmap page or in the client bundles. Notable, since OCPI is the dominant roaming/data-exchange standard in this exact market and Zap-Pay is a cross-network charging payment surface. - id: ocpp name: Open Charge Point Protocol conforms: false evidence: No OCPP reference found. Zapmap operates no charge points. - id: iso-15118 name: ISO 15118 (Plug and Charge) conforms: false evidence: No reference found. - id: openadr conforms: false evidence: No reference found; Zapmap has no demand-response surface. - id: green-button-espi conforms: false evidence: No Green Button / ESPI reference; Zapmap holds no meter data. - id: oauth2 conforms: false evidence: >- Observed auth is a static X-Api-Key application header plus an opaque bearer access token from POST /v5/authentication/login. No OAuth 2 authorization server, no scopes, no /.well-known/oauth-authorization-server (404). - id: openid-connect conforms: false evidence: >- /.well-known/openid-configuration returns 404 on both www.zapmap.com and api.zap-map.com. - id: rfc9457-problem-details conforms: false evidence: >- Errors use a proprietary {success, resources, notices[]} JSON envelope served as application/json, not application/problem+json. See errors/zapmap-error-codes.yml. - id: rfc9116-security-txt conforms: false evidence: >- /.well-known/security.txt returns 403 (nginx denial) on www.zapmap.com and 404 on api.zap-map.com. See well-known/zapmap-well-known.yml. - id: rfc8594-sunset-header conforms: false evidence: No deprecation or sunset policy published; no header evidence. - id: openapi conforms: false evidence: >- No OpenAPI or Swagger document is served on any Zapmap host; every candidate path was probed (see review.yml probes and conventions/zapmap-conventions.yml). - id: graphql conforms: false evidence: /graphql returns 404 on api.zap-map.com; the client is REST/JSON only. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface is published or observed. - id: http-api-keys name: API key authentication (header) conforms: true evidence: >- X-Api-Key request header enforced on every /v5 path; unauthenticated requests return 401 with subtype "Missing API Key". - id: http-bearer-tokens conforms: true evidence: >- Authorization: Bearer sent by the first-party client on user-scoped operations, issued by POST /v5/authentication/login. - id: hsts name: HTTP Strict Transport Security conforms: true evidence: >- www.zapmap.com serves strict-transport-security max-age=31536000 over TLS 1.3; map.zapmap.com serves max-age=31536000; includeSubDomains; preload. See security/zapmap-domain-security.yml. regulatory: regime: The Public Charge Point Regulations 2023 (UK) binds_this_organization: false detail: >- The open-data, contactless-payment and reliability duties bind public charge point OPERATORS. Zapmap owns no charge points; it is the downstream aggregator and the largest single consumer of the data the regime compels others to publish. Zapmap separately holds a Department for Transport contract (announced 16 September 2025) to act as its electric vehicle chargepoint open data provider — a private supply contract to a government department, not a public open-data API. Full treatment in review.yml. certifications: published: [] note: >- No SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP or CSA STAR claim appears on any Zapmap page, and no trust centre exists (trust./security. subdomains do not resolve; /security and /responsible-disclosure return 404). No Compliance pointer is emitted for this provider.