Included
Security & observability
Two-factor sign-in, staff capability checks, tenant isolation and an audit trail with no edit route. Certification is not claimed.
The problem
Security claims are cheap. Evidence isn’t.
What the platform does
Technical controls in the code: two-factor sign-in (TOTP), staff capability checks on every admin action, tenant isolation with tests, named write-audit coverage and player data export and anonymisation.
How it works
Follow it through.
- Sign-in
- Second factor
- Capability check
- Audit
- 01
Sign-in supports a second factor (TOTP).
- 02
Every admin action checks the staff member’s capabilities.
- 03
Queries are scoped to the tenant; isolation is tested.
- 04
Writes are audited with a named actor.
Controls
- TOTP two-factor sign-in
- Capability checks
- Tenant isolation tests
- Audit trail with no public edit or delete route
- Player data export and anonymisation
Operator experience
Staff access is per role, and the audit log is visible to the operator.
Integration points
- Independent penetration testing (planned workstream)
- Log retention and independent storage (readiness work)
Audit & reporting
Application-level append-only audit. Immutable infrastructure is separate readiness work.
Related capabilities
Let’s talk about what you’re building.
Tell us what you’re building. We’ll tell you plainly what the platform does today and what it would take.