generated: '2026-09-06' method: searched source: >- https://www.forcelink.net/privacy-policy, https://www.mysmart.city/privacypolicy, https://www.mysmart.city/termsandconditions note: >- Nothing technical could be asserted from a contract, because Acumen Software publishes no OpenAPI, AsyncAPI, GraphQL SDL, WSDL or .proto for any of its APIs. The entries below are the compliance claims the company actually makes in its own published legal pages — data-protection regimes, not certifications. No SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP claim appears anywhere on any of the three sites, and no trust centre exists. conformance: - id: popia name: Protection of Personal Information Act 4 of 2013 (South Africa) conforms: true evidence: https://www.mysmart.city/termsandconditions quote: >- "Acumen Software takes all necessary precautions to protect personal information and adheres to the Protection of Personal Information Act 4 of 2013." kind: regulatory-claim - id: gdpr name: EU General Data Protection Regulation conforms: true evidence: https://www.forcelink.net/privacy-policy quote: >- "The Company will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with the UK/EU GDPR and POPI act" kind: regulatory-claim - id: uk-gdpr name: UK GDPR / Data Protection Act 2018 conforms: true evidence: https://www.mysmart.city/termsandconditions quote: >- "in accordance with the Protection of Personal Information Act 4 of 2013, the United Kingdom's Data Protection Act, 2018, and the EU's General Data Protection Regulation" kind: regulatory-claim - id: oauth2 conforms: false evidence: https://za2.forcelink.net/forcelink/rest note: >- No OAuth 2.0 or OpenID Connect surface. /.well-known/oauth-authorization-server and /.well-known/openid-configuration miss on every host; the REST tree answers a bare {"error":"No authentication method supplied"} rather than an RFC 6750 WWW-Authenticate challenge. - id: rfc9457 conforms: false evidence: https://za2.forcelink.net/forcelink/rest note: >- Error bodies are a bare {"error": "..."} JSON object served as text/plain, not application/problem+json. domain_standard: present: false candidates_considered: - id: ogc-api probed: false note: >- My Smart City is map-based and the Forcelink surface is geospatial in places, but nothing in the company's own material names WMS, WFS, WMTS, CSW or "OGC API", and no baseURL or docs link points at a geospatial service root. Per the contract, no blind OGC path probing was done. - id: ogc-ows probed: false note: Same — no evidence pointed at a GetCapabilities endpoint, so none was invented. note: >- Reward-only dimension. The field-service / municipal-works market Acumen Software sells into has no widely adopted machine-readable interchange standard that the company could be measured against, and no standard is declared in any surface we could read. Recorded as absent, not as a failure. certifications: [] trust_center: present: false note: No trust.* host and no trust or compliance page on any of the three sites.