generated: '2026-09-05' method: searched source: https://solsten.io/data-privacy name: Solsten conformance and compliance summary: >- Solsten publishes a privacy and data-security posture but no third-party certification. The strongest claim is alignment with ISO 27001 ("follows the ISO 27001 norm") — an alignment statement, not a certificate, and no audit report or attestation is offered. Data-protection regimes (EU/UK GDPR, EU Standard Contractual Clauses, US state privacy rights, PRC transfer disclosure) are addressed in the privacy policy. There is no SOC 2, no ISO certificate number, no trust center, and no domain standard declared by the API contract — psychographic audience intelligence has no market-wide interchange standard, so that is a genuine absence, not a miss. legal_entity: Tessera Data, LLC (doing business as "Solsten") entity_evidence: https://solsten.io/privacy-policy certifications: [] conformance: - id: iso-27001 conforms: false status: claimed-alignment detail: >- "Solsten's security setup follows the ISO 27001 norm. This includes providing necessary and appropriate resources, the implementation of regular internal audits, appropriate document control, management assessment, and the application of the continuous improvement model (PDCA)." No certificate, registration number, certification body or audit date is published, so this is recorded as alignment claimed by the provider, not certification. evidence: https://solsten.io/data-privacy - id: gdpr conforms: true detail: >- The privacy policy carries a "SUPPLEMENTAL NOTICE FOR EU/UK GDPR" section covering lawful basis, data-subject rights and the right to lodge a complaint with a supervisory authority. evidence: https://solsten.io/privacy-policy - id: eu-standard-contractual-clauses conforms: true detail: >- "one of the safeguards we may use to support such transfer is the EU Standard Contractual Clauses" — the stated transfer mechanism for personal information leaving the EEA/UK. evidence: https://solsten.io/privacy-policy - id: us-state-privacy-rights conforms: true detail: >- The privacy policy publishes a "YOUR PRIVACY RIGHTS" section with access, deletion and choice rights, and the API exposes DELETE /v1/userData specifically so a customer can honour a subject's deletion request programmatically. evidence: https://docs.api.solsten.io/#delete-user - id: data-minimisation-pii-exclusion conforms: true detail: >- "Solsten does not allow its customers to send any personally identifying information (PII) and only accepts fully anonymized player IDs as well as in-game behavioral data, both of which do not enable Solsten to know the identity of an individual user." This is a contractual constraint on the ingestion surface and is reflected in the data model: every payload keys on a caller-supplied opaque user_id. evidence: https://solsten.io/data-privacy - id: rest-http conforms: true detail: >- "The Solsten API is a REST API, which accepts and returns JSON-encoded data, and uses standard HTTP response codes, authentication, and verbs." evidence: https://docs.api.solsten.io/#introduction - id: rfc9457 conforms: false detail: >- Errors are a bespoke {code, message, errors} JSON envelope served as application/json, not application/problem+json. evidence: errors/12traits-error-codes.yml - id: openapi conforms: false detail: >- No OpenAPI, Swagger, GraphQL SDL, AsyncAPI or Postman collection is published on any Solsten host. Probed /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs, /redoc and /rapidoc against api.solsten.io, docs.api.solsten.io, solsten.io, elaris.new and navigator.solsten.io — all miss. evidence: https://api.solsten.io/openapi.json - id: oauth2 conforms: false detail: Authentication is a bearer API key. No OAuth 2.0 or OpenID Connect surface exists. evidence: authentication/12traits-authentication.yml domain_standard: applicable: false detail: >- Psychographic / audience-intelligence measurement has no cross-vendor interchange standard for a contract to declare (no SCIM/OData/OpenRTB/HL7-equivalent for this market). The nearest analogues are psychometric research conventions, which are methodological rather than machine-readable. Recorded as not applicable rather than as a failure. standard: null evidence: https://solsten.io/data evidence: - url: https://solsten.io/data-privacy status: 200 - url: https://solsten.io/privacy-policy status: 200 - url: https://solsten.io/terms-of-service status: 200 - url: https://solsten.io/acceptable-use-policy status: 200 - url: https://docs.api.solsten.io/ status: 200 gaps: - No SOC 2 Type II, no ISO 27001 certificate, no penetration-test summary published. - No trust center — trust.solsten.io does not resolve. - No subprocessor list published.