Security

Controls in the code.Assurance through evidence.

Security claims are cheap. Here is what the platform does today, and what independent assurance still has to establish.

What’s built

Technical controls.

Implemented in the platform, with tests behind them. Production operation needs its own evidence on top.

  • Access

    Sign-in supports a second factor (TOTP). Staff identity and capability checks apply to every admin action, and tenant ownership is enforced by the API.

    Included

  • Tenant boundaries

    Tenant resolution and scoped queries, with tests for cross-tenant ownership and isolation. Sports odds and some trading exposure are deliberately shared.

    Included

  • Audit & accountability

    Write actions carry a named actor. There is no public API route to edit or delete the audit trail.

    Included

  • Transaction integrity

    Ledger tests, a reconciliation command, financial limit enforcement and settlement checks.

    Included

  • Data protection

    Player data export and anonymisation, with documented retention and refusal conditions.

    Included

  • Change & vulnerability management

    Automated back-end and front-end checks, static analysis, and smoke, abuse and adversarial probe tooling.

    Included

  • Availability & recovery

    A health service, alerting and documented deployment procedures, with recovery workflows for interrupted games.

    Configuration dependent

Internal verification on 1 October 2026: 2,385 back-end tests and 183,604 assertions passed. Internal tests are not certification.

Standards

What we don’t claim.

We’d rather be precise than impressive.

  • Not certified

    ISO/IEC 27001:2022

    Technical controls support readiness. Certification needs a scoped information security management system and independent assessment.

  • No report claimed

    SOC 2

    Controls relate to the Trust Services Criteria. A scoped examination has to establish the report, and a Type II needs an operating period.

  • External gate

    Games & RNG testing

    Internal maths and integrity checks prepare the evidence. An approved test house decides the outcome.

Before launch

The work still to do.

  1. 01

    Independent penetration test

    Commissioned against the defined service before launch.

  2. 02

    Proven backups and restoration

    Off-site backups, tested restores and agreed recovery objectives.

  3. 03

    Information security programme

    Owners, scope, risk treatment, policies, training, supplier reviews and internal audit, towards ISO/IEC 27001.

  4. 04

    Independent examination

    A scoped SOC 2 engagement. We will publish only the actual scope and outcome of any report.

Want the technical session?

Tenant isolation, access control and audit are best judged hands-on. We’ll walk your team through them.