generated: '2026-08-13' method: searched source: >- https://www.ticketfairy.com/event-ticketing/embedded-ticket-checkout, https://www.ticketfairy.com/event-ticketing/large-event-ticketing-platform (both read as Markdown twins), https://www.ticketfairy.com/privacy-policy; corroborated by live probes of the API and by tf-checkout-react-native@1.0.47 note: >- Compliance claims below are quoted from the company's own marketing pages, which is the only place it states them โ€” there is no trust center, no compliance page, and no certification artifact (no SOC 2 report, no ISO 27001 certificate number, no PCI AoC) published anywhere. Claims found in third-party summaries asserting SOC 2 Type II and ISO 27001 for Ticket Fairy were checked directly against the source pages and are NOT present in them; they are not recorded here. standards: - id: pci-dss conforms: claimed evidence: >- "PCI DSS compliant" (feature bullet, repeated across product pages) and "All payment processing runs through trusted, PCI-compliant payment gateways such as Stripe, Adyen, Razorpay and Xendit. Raw card details never sit on our servers." โ€” https://www.ticketfairy.com/event-ticketing/embedded-ticket-checkout level_published: false attestation_published: false note: >- The claim is scope-limited by its own wording: card data is handled by the gateways, so this is SAQ-A-shaped outsourced compliance rather than a Level 1 service-provider attestation. No AoC or level is published. - id: gdpr conforms: claimed evidence: '"GDPR ready" (feature bullet) and "GDPR and CCPA compliance for data protection"' attestation_published: false - id: ccpa conforms: claimed evidence: '"GDPR and CCPA compliance for data protection"' attestation_published: false - id: soc2 conforms: false evidence: 'No SOC 2 claim appears on any Ticket Fairy page checked.' - id: iso-27001 conforms: false evidence: 'No ISO 27001 claim appears on any Ticket Fairy page checked.' - id: oauth2 conforms: partial evidence: >- A live OAuth 2.0 surface exists โ€” /api/v1/oauth/access_token returns access_token, refresh_token, token_type and scope, and 401 bodies carry error_description per RFC 6749 ยง5.2 (tf-checkout-react-native src/api/ApiClient.ts). But no authorization-server metadata is served: /.well-known/oauth-authorization-server 404s on every host, no scope reference is published, and no grant type is documented. - id: oidc conforms: false evidence: '/.well-known/openid-configuration returns 404 on every Ticket Fairy host.' - id: json:api conforms: partial evidence: >- The checkout API sends and accepts application/vnd.api+json and returns data.attributes / relationships / type document structure (IAccountTicketsData). The anonymous public endpoints do NOT: they return a flat {data, success, error, message, status} envelope with application/json. The two surfaces disagree. - id: rfc9457 conforms: false evidence: >- No application/problem+json. Errors are a custom envelope with a prose `message` and no machine-readable code. See errors/the-ticket-fairy-problem-types.yml. - id: rfc8594 conforms: false evidence: 'No Deprecation or Sunset headers observed; no deprecation policy published.' - id: idempotency conforms: true evidence: >- PROBED. The live API accepts an `idempotency-key` request header on every /api/ route and exposes an `idempotent-replayed` response header to browser clients (CORS preflight on https://www.ticketfairy.com/api/v1/cart/, 2026-08-13). Implemented but entirely undocumented. - id: pagination conforms: partial evidence: >- Page-number pagination (page, limit, total_count, total_pages) exists on the authenticated account surface; the public read endpoints are unpaginated. No Link header, no cursors. - id: rfc9116 conforms: false evidence: '/.well-known/security.txt returns 404 on every Ticket Fairy host.' - id: rfc8615 conforms: false evidence: 'No /.well-known/ document of any kind is served. See well-known/.' compliance_published: true certifications_published: false