{"data":[{"id":"ocpi-221-routes-repo","kind":"repo-review","level":1,"title":"OCPI 2.2.1 route table","detail":"The OCPI adapter mounts controllers for credentials, locations, sessions, cdrs, tariffs, tokens, commands, chargingprofiles and hubclientinfo under the 2.2.1 version endpoint, with auth, idempotency, rate-limit and audit middleware.","source":"ChargeBridge hub source repository (private), reviewed on the date given","url":null,"supports":"That the nine 2.2.1 modules are implemented and routed in the hub.","not_supported":"Interoperability with a specific partner’s implementation; that is established per partner in the sandbox and the acceptance checklist.","modules":["credentials","locations","sessions","cdrs","tariffs","tokens","commands","chargingprofiles","hubclientinfo"],"claims":["ocpi-221"],"verified_at":"2026-10-04","review_due":"2027-02-01","stale":false},{"id":"ocpi-230-routes-repo","kind":"repo-review","level":1,"title":"OCPI 2.3.0 route table","detail":"A separate 2.3.0 version endpoint routes bookings, parking bays, payment sessions and token groups, with a translation layer between 2.2.1 and 2.3.0 partners.","source":"ChargeBridge hub source repository (private), reviewed on the date given","url":null,"supports":"That OCPI 2.3.0 objects are accepted and relayed and that mixed-version partners can be connected.","not_supported":"Production use of 2.3.0 with a named partner; payment-session objects do not make the hub a payment institution.","modules":["bookings","parking-bays","payment-sessions","token-groups"],"claims":["ocpi-230"],"verified_at":"2026-10-04","review_due":"2027-02-01","stale":false},{"id":"tr-cdr-additionals-repo","kind":"repo-review","level":1,"title":"Türkiye CDR extension (tr-cdr-additionals)","detail":"A dedicated controller and integration profile carry the utility rate in TRY/kWh, VAT breakdown and reporting identifiers next to each CDR. The underlying OCPI-TR custom module specification (v1.0.0, January 2026) was authored by ZES; E-Gridium implements it as published and credits ZES for the work.","source":"OCPI-TR Custom Modules specification v1.0.0 (ZES, 19 January 2026) and the hub source repository (private)","url":null,"supports":"That the Türkiye profile exists as an OCPI extension on both sender and receiver side.","not_supported":"Regulatory acceptance by any authority; the fields are what the parties need for their own reporting.","modules":["tr-cdr-additionals"],"claims":["turkiye"],"verified_at":"2026-10-04","review_due":"2027-02-01","stale":false},{"id":"settlement-window-repo","kind":"repo-review","level":1,"title":"Settlement window state machine","detail":"The clearing platform moves each settlement window through OPEN, GRACE_PERIOD, RECONCILING and CLOSED; late CDRs enter during the grace period and disputes surface before close.","source":"ChargeBridge hub source repository (private), reviewed on the date given","url":null,"supports":"That settlement periods, netting statements and payment obligations are produced by the platform.","not_supported":"That money has moved between partners through the hub: settlement runs in dry-run until the financial go-live gate closes, and invoicing is fenced until then.","modules":["cdrs"],"claims":["settlement"],"verified_at":"2026-10-04","review_due":"2027-02-01","stale":false},{"id":"ledger-hash-chain-repo","kind":"repo-review","level":1,"title":"Hash-chained settlement ledger","detail":"Ledger entries are chained by hash so a statement can be re-verified against its inputs; hub fees are booked as separate lines for each party and never netted against roaming amounts.","source":"ChargeBridge hub source repository (private), reviewed on the date given","url":null,"supports":"Tamper-evidence of the ledger and the “hub fee outside netting” rule.","not_supported":"Fee rates or splits; those are in the participation agreement, not on this site.","modules":["cdrs"],"claims":["settlement","fees"],"verified_at":"2026-10-04","review_due":"2027-02-01","stale":false},{"id":"edge-fail-closed-repo","kind":"repo-review","level":1,"title":"Fail-closed partner relationships","detail":"No location, tariff, session, CDR or token flows unless an explicitly accepted, active partner relationship exists between the two parties; publish scope defaults to deny and changes are written to an audit ledger.","source":"ChargeBridge hub source repository (private), reviewed on the date given","url":null,"supports":"That a completed credentials handshake does not open data flow and that scope is an explicit, auditable decision.","not_supported":"Contractual data-sharing permissions; those come from the signed agreement and DPA.","modules":["credentials","locations","tariffs","sessions","cdrs","tokens"],"claims":["scope","security"],"verified_at":"2026-10-04","review_due":"2027-02-01","stale":false},{"id":"kvkk-retention-repo","kind":"repo-review","level":1,"title":"Retention sweep for token material","detail":"Hashed token data and encrypted credentials are deleted as soon as their retention time expires; the sweep runs on a schedule and is the most conservative setting available.","source":"ChargeBridge hub source repository (private), reviewed on the date given","url":null,"supports":"The delete-on-expiry rule stated on the trust page.","not_supported":"A data-controller’s own retention obligations; those are set in each DPA.","modules":["tokens"],"claims":["security"],"verified_at":"2026-10-04","review_due":"2027-02-01","stale":false},{"id":"test-suite-count","kind":"test-suite","level":3,"title":"Automated test suite","detail":"About 1,500 test files across the OCPI adapter, clearing platform, identity service, roaming mesh and hub portal: unit, contract, end-to-end, property-based and mutation tests.","source":"Hub source repository, test directories (count of 4 October 2026)","url":null,"supports":"That protocol flows and settlement logic are covered by automated tests.","not_supported":"On which release and date the suite last passed; a dated run report will be published when available.","modules":[],"claims":["quality"],"verified_at":"2026-10-04","review_due":"2027-02-01","stale":false},{"id":"openapi-specs","kind":"document","level":2,"title":"OpenAPI specifications","detail":"Machine-readable API descriptions for the OCPI adapter, the clearing platform and the identity service, published on the developers page.","source":"OpenAPI documents generated from the hub services","url":"https://egridium.com/api-specs/ocpi-adapter.openapi.json","supports":"The endpoint surface a partner integrates against.","not_supported":"Access: endpoints require partner credentials issued during onboarding.","modules":[],"claims":["developers"],"verified_at":"2026-10-04","review_due":"2026-12-03","stale":false},{"id":"compliance-status-json","kind":"document","level":2,"title":"Compliance programme status","detail":"ISO/IEC 27001:2022 in progress (gap assessment, target end of 2026), SOC 2 in planning, PCI DSS SAQ-A scoped as a self-assessment; the matrix tracks each control’s status and owner.","source":"Hub repository, docs/compliance/compliance-status.json and COMPLIANCE-MATRIX.md","url":null,"supports":"That the programmes exist and their stated status on the trust page.","not_supported":"Any certification or attestation: none has been issued for E-Gridium.","modules":[],"claims":["compliance"],"verified_at":"2026-10-04","review_due":"2027-01-02","stale":false},{"id":"oicp-frozen","kind":"repo-review","level":1,"title":"OICP bridge not installed","detail":"The OICP-to-OCPI bridge service is marked installed:false in every environment and has no outbound HTTP client; the launch decision record keeps it out of scope.","source":"ChargeBridge hub source repository (private), reviewed on the date given","url":null,"supports":"The negative claim on the modules page: OICP translation is not offered.","not_supported":"Any future availability.","modules":["oicp"],"claims":["not-offered"],"verified_at":"2026-10-04","review_due":"2027-02-01","stale":false},{"id":"webhooks-501","kind":"repo-review","level":1,"title":"Webhook endpoints return 501","detail":"The seven webhook endpoints answer 501 Not Implemented and were removed from the public path list and the portal navigation by the launch decision record; the delivery chain is not wired.","source":"ChargeBridge hub source repository (private), reviewed on the date given","url":null,"supports":"The negative claim on the modules page: webhooks are not offered.","not_supported":"Any future availability.","modules":["webhooks"],"claims":["not-offered"],"verified_at":"2026-10-04","review_due":"2027-02-01","stale":false},{"id":"engineering-footprint","kind":"repo-review","level":1,"title":"Engineering footprint of the hub","detail":"Twelve services in one monorepo (OCPI adapter, clearing platform, identity, roaming mesh, PKI, map data, sandbox, ops MCP, mocks and migrations), 593 database migrations, 87 architecture decision records, about 1,500 test files, and three OpenAPI documents with 83 paths in total.","source":"Hub source repository, counted on 4 October 2026","url":null,"supports":"That the hub is an engineered, documented system rather than a prototype.","not_supported":"Production scale, partner counts or service levels; counts describe the codebase, not the traffic.","modules":[],"claims":["engineering"],"verified_at":"2026-10-04","review_due":"2027-02-01","stale":false},{"id":"settlement-architecture-doc","kind":"document","level":2,"title":"Settlement architecture: agreements, windows, statements, obligations","detail":"Bilateral, versioned agreements define cycle, grace period, dispute window, fee allocation, payment automation and FX policy; windows move OPEN → GRACE_PERIOD → RECONCILING → CLOSED; statements move GENERATED → PUBLISHED → ACKNOWLEDGED and are hub-signed; obligations carry debtor, creditor, amount and due date.","source":"Hub repository, docs/architecture/settlement (domain model, state machines, cycle computation)","url":null,"supports":"The structure described on the settlement page.","not_supported":"Any rate, amount or that real money has moved; payment automation beyond manual mode is configured per partner after the financial go-live gate.","modules":["cdrs"],"claims":["settlement"],"verified_at":"2026-10-04","review_due":"2027-04-02","stale":false},{"id":"tr-profile-doc","kind":"document","level":2,"title":"Türkiye profile: binding interpretation of tr-cdradditionals","detail":"Eight rules the hub applies where the specification leaves room: unit price semantics and precision, VAT handling, versioned corrections, idempotency responses, discovery via version details, eventual matching with a 24-hour compliance-gap report, serial-number reading, transport security. Open points are confirmed with the specification’s author before integration.","source":"OCPI-TR Custom Modules specification v1.0.0 (ZES, 19 January 2026) and the hub implementation profile docs/integration/TR_CDRADDITIONALS_PROFILE.md","url":null,"supports":"The rule table on the Türkiye page.","not_supported":"Regulatory acceptance; the profile is a technical agreement between integrating parties.","modules":["tr-cdr-additionals"],"claims":["turkiye"],"verified_at":"2026-10-04","review_due":"2027-04-02","stale":false},{"id":"portal-routes-repo","kind":"repo-review","level":1,"title":"Hub portal views per role","detail":"The portal route table defines hub-operator views (directory, map, settlement windows, approvals, partners, contract queue, aggregators, operations, stuck work) and partner views (my statements, my records, my contract, roaming, data quality) with CPO-only sharing sets and tariffs and eMSP-only tokens, sessions, reservations and commands.","source":"ChargeBridge hub source repository (private), reviewed on the date given","url":null,"supports":"The portal views listed on the role pages.","not_supported":"What a given partner sees in production; access is scoped per party. Real screens will be added as separate product-flow records.","modules":[],"claims":["portal"],"verified_at":"2026-10-04","review_due":"2027-02-01","stale":false},{"id":"sandbox-repo","kind":"repo-review","level":1,"title":"Partner sandbox","detail":"Sandbox routes in the OCPI adapter and a mock partner and charger simulator let a partner complete the handshake and exercise each module against test data before onboarding.","source":"ChargeBridge hub source repository (private), reviewed on the date given","url":null,"supports":"That a test environment is part of onboarding.","not_supported":"Self-service sign-up; sandbox credentials are issued after the application is reviewed.","modules":["credentials"],"claims":["onboarding"],"verified_at":"2026-10-04","review_due":"2027-02-01","stale":false}],"meta":{"version":"2026-10-04","coverage":{"modules":{"total":16,"covered":16},"stale":0},"rule":"No record without a public, inspectable artefact or a dated internal review; every record states what it supports and what it does not show."}}