generated: '2026-08-26' method: searched source: 'https://trust.prizeout.com/ ; https://www.prizeout.com/privacy/ ; https://www.prizeout.com/terms/ ; SDK integration wikis ; /.well-known probes' name: Prizeout Conformance description: >- Standards and cross-cutting conformance assertions for Prizeout. Every entry is evidenced or recorded as not-conformant / unknown. Nothing is asserted from marketing copy. Prizeout publishes no machine-readable contract, so no conformance could be read out of a spec. entries: - id: openapi conforms: false evidence: 'No OpenAPI or Swagger document served on any Prizeout host. /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs and /redoc all probed 2026-08-26: 404 on the widget and www hosts, 403 on the backend API hosts.' - id: graphql conforms: false evidence: 'POST to /graphql on www, widget, widget-v2 and py-merchant-portal-api returned 404/400/403. No GraphQL surface.' - id: asyncapi conforms: false evidence: 'No AsyncAPI document. Event surface is partner-implemented callbacks; see asyncapi/prizeout-partner-callbacks.yml.' - id: mcp conforms: false evidence: 'tools/list POST returned 404/400/403 on every host. No MCP server.' - id: a2a conforms: false evidence: '/.well-known/agent-card.json and /.well-known/agent.json returned 404 on all four hosts.' - id: oauth2 conforms: false evidence: 'No authorization server. /.well-known/oauth-authorization-server 404 on all hosts. Auth is API key + shared secret.' - id: oidc conforms: false evidence: '/.well-known/openid-configuration 404 on all hosts.' - id: rfc9457 conforms: false evidence: 'No problem+json usage documented; no error envelope published at all.' - id: rfc9116 conforms: false evidence: '/.well-known/security.txt 404 on all four hosts probed 2026-08-26.' - id: rfc8594 conforms: false evidence: 'No Sunset or Deprecation headers documented.' - id: rfc8615 conforms: false evidence: 'No /.well-known/api-catalog. 404 on all four hosts.' - id: pagination conforms: false evidence: 'No public list endpoints to paginate.' - id: idempotency conforms: false evidence: 'No idempotency key or retry-safety statement published for the cash-out callbacks.' - id: llmstxt conforms: true evidence: 'https://www.prizeout.com/llms.txt served HTTP 200, content-type text/plain, 49408 bytes, generated by All in One SEO v5.0.0.1. Saved verbatim to llms/prizeout-llms.txt. It indexes marketing posts and pages, not an API surface.' - id: pci-dss conforms: unknown evidence: >- Prizeout handles gift-card purchase funded from partner-held balances and loads Stripe.js on both the widget and the partner dashboard, so a card-data scope plausibly exists - but no PCI attestation is published on any reachable page. Recorded as unknown, not asserted. - id: gdpr conforms: unknown evidence: 'A cookie policy (https://www.prizeout.com/cookie/) and OneTrust/CookiePro consent management are deployed, and a privacy policy is served at https://www.prizeout.com/privacy/ (HTTP 200). No explicit GDPR/CCPA conformance statement was machine-readable.' domain_standards: market: 'Gift cards / rewards / merchant-funded incentives, delivered into banking and gaming platforms' candidates_probed: - standard: 'GCVA (Gift Card and Voucher Association) membership' result: 'Prizeout Corp. is listed as a GCVA member (https://www.gcva.co.uk/members/prizeout-corp). This is a trade-association membership, not a technical interchange standard, and is recorded for context only - it earns no domain_standard_conformance credit.' - standard: 'FDX (Financial Data Exchange)' result: 'No FDX endpoint, schema or claim found. Prizeout does not aggregate financial data; it consumes a partner-supplied balance.' - standard: 'ISO 20022' result: 'No ISO 20022 message types. Prizeout does not move funds over payment rails in its published surface.' - standard: 'OpenRTB' result: >- Prizeout describes a real-time auction in which brands bid to place a gift-card offer, which is the OpenRTB shape - but no bid endpoint, no OpenRTB object names and no IAB claim appear on any public surface. Recorded as probed-and-missed, not asserted. - standard: 'Jack Henry Vendor Integration Program' result: >- Prizeout announced an expanded integration with the Jack Henry Vendor Integration Program (GlobeNewswire, 2023-04-13, linked from the published llms.txt). This is a certified banking-core integration program, not a published open standard, and the certification artifact is not public. conforms: false note: >- REWARD-ONLY dimension. Prizeout's market has candidate standards (OpenRTB for the auction side, core-banking vendor programs for the CU side) but Prizeout declares none of them in a contract, because it publishes no contract. No conformance was invented to fill the slot. compliance_certifications: published_named_certs: false note: >- A Vanta-hosted trust center exists at https://trust.prizeout.com/ (HTTP 200, canonical https://trust.prizeout.com, title "Prizeout Trust Center"), but its contents are rendered entirely client-side by a React bundle - the served HTML carries only the title and description. No certification name (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP) could be read from any machine-readable surface, and a targeted search returned no Prizeout-specific attestation. Because no certification is legible, NO Compliance pointer is wired into apis.yml. See security/prizeout-trust-center.yml.