generated: '2026-08-06' method: searched source: >- openapi/applike-justtrack-management-openapi.yml, openapi/applike-justtrack-app-events-openapi.yml, https://justtrack.io/security/, https://adjoe.io/, https://justtrack.io/dpa/, https://docs.adjoe.io/rewarded-solutions/reporting-apis/revenue-api, https://docs.justtrack.io/sdk/privacy/ summary: >- AppLike Group's conformance surface is a thin, honest one: OpenAPI 3.1.0 for two of six HTTP surfaces, ISO 27001 claimed by both API-bearing brands, standard data-format standards used inside the schemas, and nothing else. No OAuth 2.0, no OpenID Connect, no RFC 9457 problem details, no RFC 8594 deprecation headers, no industry vertical standard (this is adtech — IAB/OpenRTB would be the relevant family, and neither brand claims conformance to it on its public developer surface). conformance: - id: openapi-3.1 name: OpenAPI Specification 3.1.0 conforms: true scope: partial — 2 of 6 published HTTP surfaces evidence: - openapi/applike-justtrack-management-openapi.yml (openapi 3.1.0, 12 operations, 6 tags) - openapi/applike-justtrack-app-events-openapi.yml (openapi 3.1.0, 1 operation) - https://docs.justtrack.io/management.openapi.yaml - https://docs.justtrack.io/app-events.openapi.yaml gaps: - The Management API document declares no operationId on any of its 12 operations. - >- The Reporting API, Revenue Events API and both adjoe SSP APIs have no OpenAPI contract at all — they are prose documentation only. - id: iso-27001 name: ISO/IEC 27001 Information Security Management conforms: true claimed_by: - brand: justtrack version: 'ISO/IEC 27001:2022' evidence: https://justtrack.io/security/ - brand: adjoe version: not stated evidence: https://adjoe.io/ verification: >- Self-asserted on each brand's marketing site. Neither publishes the certificate, certification body, certificate number or scope statement, so the claim cannot be independently checked from the public surface. - id: gdpr name: EU General Data Protection Regulation conforms: true basis: >- German-incorporated group (justtrack GmbH, adjoe GmbH, Hamburg) publishing a Data Processing Agreement, a privacy notice per brand, and SDK-level consent controls (manual start, stop, anonymize). evidence: - https://justtrack.io/dpa/ - https://justtrack.io/privacy-notice/ - https://docs.justtrack.io/sdk/privacy/ - https://adjoe.io/privacy/ - id: google-play-data-safety name: Google Play Data Safety declarations conforms: true detail: adjoe publishes explicit guidance for publishers filling out the Play Data Safety form for the Playtime SDK. evidence: https://docs.adjoe.io/rewarded-solutions/playtime-sdk-integration/android/google-play-data-safety-guidance - id: apple-att name: Apple App Tracking Transparency conforms: true detail: >- The justtrack SDK does not itself request ATT permission and documents that it can still attribute (with reduced precision) when IDFA is unavailable. evidence: https://docs.justtrack.io/sdk/setup/ - id: semver name: Semantic Versioning 2.0.0 conforms: true scope: SDKs only evidence: changelog/applike-changelog.yml - id: iso-4217 name: ISO 4217 currency codes conforms: true evidence: >- openapi/applike-justtrack-app-events-openapi.yml — AppEvent.currency, minLength/maxLength 3 with an iso4217 binding tag - id: iso-8601 name: ISO 8601 date and time conforms: true evidence: - AppEvent.happenedAt and the justtrack revenue `happenedat` parameter are ISO 8601 - adjoe SSP start_at / stop_at use YYYY-MM-DD - id: rfc-4122-uuid name: RFC 4122 UUID (version 4) conforms: true evidence: >- openapi/applike-justtrack-app-events-openapi.yml — BatchId and AppEvent.id are format uuid, 36 characters, with uuid4 binding tags - id: rfc-6585-429 name: RFC 6585 Too Many Requests + Retry-After conforms: partial detail: >- adjoe SSP returns 429 with Retry-After and X-RateLimit-* headers. justtrack publishes no rate limits and declares no 429 anywhere. evidence: https://docs.adjoe.io/rewarded-solutions/reporting-apis/revenue-api - id: rfc-9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false detail: 'Both brands use a proprietary flat envelope: {"error": ""}. No application/problem+json anywhere.' evidence: errors/applike-problem-types.yml - id: rfc-8594 name: RFC 8594 Sunset header (and the Deprecation header) conforms: false detail: >- No Sunset or Deprecation header is sent, and no OpenAPI operation is flagged deprecated — even though adjoe has published a hard SDK sunset date of 2026-09-01. evidence: lifecycle/applike-lifecycle.yml - id: oauth2 name: OAuth 2.0 conforms: false detail: No OAuth flow on any surface; every API is API-key authenticated. evidence: authentication/applike-authentication.yml - id: oidc name: OpenID Connect conforms: false detail: /.well-known/openid-configuration returns 404 on every host probed. evidence: well-known/applike-well-known.yml - id: rfc-9116 name: RFC 9116 security.txt conforms: false detail: No /.well-known/security.txt on any of the group's hosts. evidence: well-known/applike-well-known.yml - id: rfc-8615-well-known name: RFC 8615 well-known URIs / RFC 9727 api-catalog conforms: false detail: No /.well-known/api-catalog on any host. evidence: well-known/applike-well-known.yml - id: a2a name: A2A Agent Card conforms: false detail: >- No agent card at /.well-known/agent-card.json or /.well-known/agent.json on any host. The 200s returned by docs.adjoe.io for those paths are the Docusaurus catch-all shell, not a card. evidence: well-known/applike-well-known.yml - id: mcp name: Model Context Protocol conforms: false detail: No hosted or documented MCP server for either brand. - id: asyncapi name: AsyncAPI conforms: false detail: >- Real event surfaces exist (revenue postbacks, rewarded payout callbacks) but no AsyncAPI document is published. Captured as a webhook catalog instead. evidence: asyncapi/applike-webhooks.yml - id: openrtb name: IAB OpenRTB / adtech interoperability standards conforms: unknown detail: >- adjoe operates a programmatic ads platform, which in practice implies OpenRTB, but no OpenRTB, ads.txt/app-ads.txt, TCF or SKAdNetwork conformance statement appears on the public developer surface. Recorded as unknown rather than false — this is a documentation gap, not evidence of non-conformance.