Security
Controls in the code.Assurance through evidence.
Security claims are cheap. Here is what the platform does today, and what independent assurance still has to establish.
What’s built
Technical controls.
Implemented in the platform, with tests behind them. Production operation needs its own evidence on top.
Access
Sign-in supports a second factor (TOTP). Staff identity and capability checks apply to every admin action, and tenant ownership is enforced by the API.
Included
Tenant boundaries
Tenant resolution and scoped queries, with tests for cross-tenant ownership and isolation. Sports odds and some trading exposure are deliberately shared.
Included
Audit & accountability
Write actions carry a named actor. There is no public API route to edit or delete the audit trail.
Included
Transaction integrity
Ledger tests, a reconciliation command, financial limit enforcement and settlement checks.
Included
Data protection
Player data export and anonymisation, with documented retention and refusal conditions.
Included
Change & vulnerability management
Automated back-end and front-end checks, static analysis, and smoke, abuse and adversarial probe tooling.
Included
Availability & recovery
A health service, alerting and documented deployment procedures, with recovery workflows for interrupted games.
Configuration dependent
Internal verification on 1 October 2026: 2,385 back-end tests and 183,604 assertions passed. Internal tests are not certification.
Standards
What we don’t claim.
We’d rather be precise than impressive.
Not certified
ISO/IEC 27001:2022
Technical controls support readiness. Certification needs a scoped information security management system and independent assessment.
No report claimed
SOC 2
Controls relate to the Trust Services Criteria. A scoped examination has to establish the report, and a Type II needs an operating period.
External gate
Games & RNG testing
Internal maths and integrity checks prepare the evidence. An approved test house decides the outcome.
Before launch
The work still to do.
- 01
Independent penetration test
Commissioned against the defined service before launch.
- 02
Proven backups and restoration
Off-site backups, tested restores and agreed recovery objectives.
- 03
Information security programme
Owners, scope, risk treatment, policies, training, supplier reviews and internal audit, towards ISO/IEC 27001.
- 04
Independent examination
A scoped SOC 2 engagement. We will publish only the actual scope and outcome of any report.
Want the technical session?
Tenant isolation, access control and audit are best judged hands-on. We’ll walk your team through them.