Standards
What every partner app is assessed against. The application sets out all 65 commitments.
Draft: the commitments are awaiting final sign-off and may change. Applications are rolling: we reply within 10 working days of a complete application.
Scale and resilience
SCL-01 to 05- A game you bring must support at least 100,000 concurrent players, with load test evidence before launch.
- A customer build is sized to the customer's own peak plus headroom, from the infrastructure survey.
- Plan for broadcast and push-notification spikes. Add at least 20% random jitter to polling, retry with backoff and fail gracefully.
Security and access
SEC-01 to 07- Decide points, scores, ranks and prizes on the server. Keep secrets out of the client. Use HTTPS and secure WebSockets.
- Use SSO via SAML first. Otherwise named accounts, two-factor authentication and least privilege.
- Run SAST, secret detection and dependency checks on every build. Report incidents within 24 hours, with a written report within 72.
Data and consent
DAT-01 to 09- Partners do not store personal data. Use the Monterosa Forms service; personal data stays on or with Monterosa.
- Without consent: no cookies, no tracking and no use of personal data. Honour the Interaction SDK consent signal.
- Show the customer's privacy notice and terms, not your own. Declare every cookie and local storage item.
App experience
APP-01 to 13- Meet WCAG 2.2 AA. Test on mobile web, iOS and Android native apps, desktop browsers and slow connections.
- Make styling and copy configurable in Studio. Support localisation, right-to-left languages and non-Latin scripts.
- Create new runs as Events without code changes. Handle open, closed, revealed and stopped states. Use SDK server time.
Analytics and integrations
ANL-01 to 04- Include Interaction SDK analytics in every app, including a game you bring.
- Carry the customer's ad serving, analytics, SSO and consent management. Consent governs what runs.
- Declare captured behaviour and deliver backend data to the S3 bucket we nominate, in the agreed format and cadence.
Monetisation and prizes
MON-01 to 03- Declare advertising, sponsorship, payments and all other monetisation before approval.
- For prizes, predictions, sweepstakes, virtual currency or betting-like features, you handle licences, official rules, age and territory restrictions, and promotions and gambling law.
- Plan certification before launch. Adding monetisation later needs written approval.
Hosting and environments
HST-01 to 04- Use approved static hosting and declared URLs, with branded customer-facing endpoints.
- Build only on a development instance or Playground (Monterosa's sandbox instance). Keep Projects, App Spec (the JSON that defines your app) versions, hosting, credentials and configuration separate.
- Keep real fan data out of development. Configure instance details; never hardcode them.
AI and business conduct
AI-01 to 03, CMP-01- Declare AI used for code, artwork, audio and copy. A person reviews AI-generated code before release.
- A model inside the app needs approval: model, version, provider, hosting and guardrails. Never send personal data to AI services.
- Comply with the Modern Slavery Act and address the risk in your business and supply chain.
Declare exceptions early
For each commitment, choose Will comply, Will comply with exceptions, Will not comply, or Not applicable. Explain exceptions and refusals. We discuss them at assessment; they do not rule you out on their own.
Performance targets
Confirmed for each partner in the Partner Agreement.
| Measure | Target | Conditions |
|---|---|---|
| First content visible | Under 2 seconds | 4G, mid-range Android, cold cache |
| Interactive | Under 3 seconds | 4G, mid-range Android, cold cache |
| Interactive on a slow connection | Under 6 seconds | Throttled 3G |
| Initial transfer | Under 1.5 MB | Everything needed for first interaction |
| JavaScript bundle | Under 400 KB compressed | Excludes the Interaction SDK |

