generated: '2026-08-06' method: searched source: >- https://audigent.com/platform-privacy-policy/ ; https://vendor-list.consensu.org/v3/vendor-list.json (vendor 561) ; https://p.ad.gt/static/iab_tcf.json ; https://docs.prebid.org/dev-docs/modules/hadronRtdProvider.html summary: >- Audigent's conformance posture is entirely advertising-industry standards and privacy self-regulation — not API standards. It is a registered IAB Europe TCF vendor with a live, machine-readable device-storage disclosure, it emits and honours TCF / US Privacy / GPP consent strings on its public endpoints, and it speaks OpenRTB and the Prebid.js module contracts. It conforms to no API-design standard: no OpenAPI, no RFC 9457 problem details, no OAuth 2.0, no OpenID Connect, no RFC 8594 deprecation headers, no /.well-known catalog. standards: - id: iab-tcf name: IAB Europe Transparency & Consent Framework v2.2 conforms: true evidence: registry: https://vendor-list.consensu.org/v3/vendor-list.json vendor_id: 561 vendor_name: AuDigent gvl_version: 171 tcf_policy_version: 5 purposes: [1, 2, 3, 4, 5, 9, 10] data_declaration: [1, 3, 6, 8] std_retention_days: 60 cookie_max_age_seconds: 31536000 privacy_url: https://audigent.com/platform-privacy-policy leg_int_claim_url: https://audigent.com/privacy-center/ device_storage_disclosure_url: https://p.ad.gt/static/iab_tcf.json local_copy: conformance/audigent-iab-tcf-gvl-vendor-561.json quote: >- "Audigent participates in the IAB Europe Transparency & Consent Framework and complies with its Specifications and Policies." — https://audigent.com/platform-privacy-policy/ - id: iab-tcf-device-storage-disclosure name: IAB TCF Device Storage Disclosure (machine-readable) conforms: true note: >- This is the one genuinely machine-readable contract Audigent publishes from its own infrastructure. It is a JSON document enumerating every identifier the platform writes to a device, its type, lifetime, domain scope and the TCF purposes it serves. It is not an API spec, but it is a real, fetchable, parseable, first-party artifact and should be counted as such. evidence: url: https://p.ad.gt/static/iab_tcf.json http_status: 200 content_type: application/json last_modified: 'Tue, 14 Jul 2026 11:51:20 GMT' fetched: '2026-08-06' local_copy: conformance/audigent-iab-tcf-device-storage.json disclosures: 5 identifiers: - au_id - au_idmatch - au/sid - _au_1d - _au_last_seen* - id: iab-us-privacy name: IAB US Privacy (USP) string / CCPA opt-out signal conforms: true evidence: parameter: us_privacy source: https://github.com/prebid/Prebid.js/blob/master/modules/hadronIdSystem.js note: >- The hadronIdSystem module reads uspDataHandler.getConsentData() and appends &us_privacy= to every identity call. - id: iab-gpp name: IAB Global Privacy Platform (GPP) conforms: true evidence: parameters: [gpp, gpp_sid] source: https://github.com/prebid/Prebid.js/blob/master/modules/hadronIdSystem.js note: >- gppDataHandler consent string and applicable section IDs are appended to the identity request. - id: openrtb name: OpenRTB 2.x (ortb2) conforms: true evidence: url: https://seg.hadron.ad.gt/api/v1/rtd http_status: 200 observed_body: '{ "rtd": { "ortb2": { } } }' fetched: '2026-08-06' note: >- The RTD endpoint's response contract is an OpenRTB ortb2 fragment merged into the Prebid auction — the interoperability surface is OpenRTB, not a proprietary Audigent schema. - id: prebid-module-contracts name: Prebid.js User ID / RTD / Analytics submodule interfaces conforms: true evidence: userid: https://docs.prebid.org/dev-docs/modules/userid-submodules/hadron.html rtd: https://docs.prebid.org/dev-docs/modules/hadronRtdProvider.html analytics: https://docs.prebid.org/dev-docs/analytics/audigent.html gvlid: 561 note: >- Audigent implements three distinct upstream Prebid.js submodule interfaces and declares GVLID 561 in each. The modules live in the prebid/Prebid.js repository and are maintained by Audigent (contact prebid@audigent.com). - id: eu-us-dpf name: EU-U.S. Data Privacy Framework (+ UK Extension, Swiss-U.S. DPF) conforms: true self_asserted: true evidence: url: https://audigent.com/platform-privacy-policy/ http_status: 200 quote: >- "Audigent complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework" note: Self-asserted in the platform privacy policy; not independently verified here. - id: daa name: Digital Advertising Alliance Self-Regulatory Principles conforms: true self_asserted: true evidence: url: https://audigent.com/platform-privacy-policy/ quote: >- "Audigent is a member of the Digital Advertising Alliance ("DAA") and adheres to the DAA Self-Regulatory Principles" opt_out: https://youradchoices.com/ - id: nai name: Network Advertising Initiative Code of Conduct conforms: true self_asserted: true evidence: url: https://audigent.com/platform-privacy-policy/ quote: '"Audigent is a member of the NAI and adheres to the NAI''s Framework."' - id: ccpa-cpra name: California Consumer Privacy Act / CPRA conforms: true evidence: opt_out_url: https://audigent.com/?optout=1 opt_out_status: 200 dsr_portal: https://www.requesteasy.com/653b-4813 dsr_portal_status: 200 privacy_center: https://audigent.com/privacy-center/ contacts: - privacy@audigent.com - yourprivacyrights@audigent.com fetched: '2026-08-06' # --- Standards NOT conformed to (probed, negative results are data) --- - id: openapi name: OpenAPI Specification conforms: false evidence: note: >- /openapi.json, /swagger.json and /api-docs returned 404 on id.hadron.ad.gt, analytics.hadron.ad.gt, seg.hadron.ad.gt and api.audigent.com; 403 on cdn.hadronid.net. audigent.com and dev.audigent.com answer 200 for every path (soft-404 to /index.html) and were disqualified by control-path diff. fetched: '2026-08-06' - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: note: >- No application/problem+json observed. a.ad.gt returns a Werkzeug-default JSON error body; hadron.ad.gt hosts return bare status codes. - id: oauth2 name: OAuth 2.0 conforms: false evidence: note: /.well-known/oauth-authorization-server returned 404 on all five API hosts. - id: oidc name: OpenID Connect conforms: false evidence: note: /.well-known/openid-configuration returned 404 on all five API hosts. - id: rfc9116 name: RFC 9116 security.txt conforms: false evidence: note: >- /.well-known/security.txt returned 404 on every API host and soft-404 on audigent.com. No vulnerability disclosure policy published. - id: rfc8594 name: RFC 8594 Sunset / Deprecation headers conforms: false evidence: note: >- Deprecation is communicated in prose on docs.prebid.org (Halo to Hadron), not via Deprecation/Sunset response headers. See lifecycle/. - id: rfc9727 name: RFC 9727 /.well-known/api-catalog conforms: false evidence: note: /.well-known/api-catalog returned 404 on every host probed. - id: a2a name: A2A Agent Card conforms: false evidence: note: >- /.well-known/agent-card.json and /.well-known/agent.json returned 404 on every Audigent and Hadron host. No agent card exists; none was authored. certifications_published: false certifications_note: >- Audigent names no security certification (no SOC 2, ISO 27001, PCI or HIPAA) on any public page, and publishes no trust center. trust.audigent.com does not resolve with a valid certificate. Its published compliance posture is entirely privacy/advertising self-regulation, listed above. Experian, its parent since December 2024, maintains its own separate certifications; those are not asserted here because Audigent does not publish them on its own surface.