Standards

What every partner app is assessed against. The application sets out all 65 commitments.

Draft: the commitments are awaiting final sign-off and may change. Applications are rolling: we reply within 10 working days of a complete application.

Scale and resilience

SCL-01 to 05
  • A game you bring must support at least 100,000 concurrent players, with load test evidence before launch.
  • A customer build is sized to the customer's own peak plus headroom, from the infrastructure survey.
  • Plan for broadcast and push-notification spikes. Add at least 20% random jitter to polling, retry with backoff and fail gracefully.

Security and access

SEC-01 to 07
  • Decide points, scores, ranks and prizes on the server. Keep secrets out of the client. Use HTTPS and secure WebSockets.
  • Use SSO via SAML first. Otherwise named accounts, two-factor authentication and least privilege.
  • Run SAST, secret detection and dependency checks on every build. Report incidents within 24 hours, with a written report within 72.

Data and consent

DAT-01 to 09
  • Partners do not store personal data. Use the Monterosa Forms service; personal data stays on or with Monterosa.
  • Without consent: no cookies, no tracking and no use of personal data. Honour the Interaction SDK consent signal.
  • Show the customer's privacy notice and terms, not your own. Declare every cookie and local storage item.

App experience

APP-01 to 13
  • Meet WCAG 2.2 AA. Test on mobile web, iOS and Android native apps, desktop browsers and slow connections.
  • Make styling and copy configurable in Studio. Support localisation, right-to-left languages and non-Latin scripts.
  • Create new runs as Events without code changes. Handle open, closed, revealed and stopped states. Use SDK server time.

Analytics and integrations

ANL-01 to 04
  • Include Interaction SDK analytics in every app, including a game you bring.
  • Carry the customer's ad serving, analytics, SSO and consent management. Consent governs what runs.
  • Declare captured behaviour and deliver backend data to the S3 bucket we nominate, in the agreed format and cadence.

Monetisation and prizes

MON-01 to 03
  • Declare advertising, sponsorship, payments and all other monetisation before approval.
  • For prizes, predictions, sweepstakes, virtual currency or betting-like features, you handle licences, official rules, age and territory restrictions, and promotions and gambling law.
  • Plan certification before launch. Adding monetisation later needs written approval.

Hosting and environments

HST-01 to 04
  • Use approved static hosting and declared URLs, with branded customer-facing endpoints.
  • Build only on a development instance or Playground (Monterosa's sandbox instance). Keep Projects, App Spec (the JSON that defines your app) versions, hosting, credentials and configuration separate.
  • Keep real fan data out of development. Configure instance details; never hardcode them.

AI and business conduct

AI-01 to 03, CMP-01
  • Declare AI used for code, artwork, audio and copy. A person reviews AI-generated code before release.
  • A model inside the app needs approval: model, version, provider, hosting and guardrails. Never send personal data to AI services.
  • Comply with the Modern Slavery Act and address the risk in your business and supply chain.

Declare exceptions early

For each commitment, choose Will comply, Will comply with exceptions, Will not comply, or Not applicable. Explain exceptions and refusals. We discuss them at assessment; they do not rule you out on their own.

Performance targets

Confirmed for each partner in the Partner Agreement.

MeasureTargetConditions
First content visibleUnder 2 seconds4G, mid-range Android, cold cache
InteractiveUnder 3 seconds4G, mid-range Android, cold cache
Interactive on a slow connectionUnder 6 secondsThrottled 3G
Initial transferUnder 1.5 MBEverything needed for first interaction
JavaScript bundleUnder 400 KB compressedExcludes the Interaction SDK
Building →