The Road511 API uses an allowlist of its own origins (not a wildcard), so cross-origin requests from arbitrary sites receive no Access-Control-Allow-Origin header. Updates the CORS column from Yes to No to reflect actual behavior.