Included

Security & observability

Two-factor sign-in, staff capability checks, tenant isolation and an audit trail with no edit route. Certification is not claimed.

The problem

Security claims are cheap. Evidence isn’t.

What the platform does

Technical controls in the code: two-factor sign-in (TOTP), staff capability checks on every admin action, tenant isolation with tests, named write-audit coverage and player data export and anonymisation.

How it works

Follow it through.

  1. Sign-in
  2. Second factor
  3. Capability check
  4. Audit
  1. 01

    Sign-in supports a second factor (TOTP).

  2. 02

    Every admin action checks the staff member’s capabilities.

  3. 03

    Queries are scoped to the tenant; isolation is tested.

  4. 04

    Writes are audited with a named actor.

Controls

  • TOTP two-factor sign-in
  • Capability checks
  • Tenant isolation tests
  • Audit trail with no public edit or delete route
  • Player data export and anonymisation

Operator experience

Staff access is per role, and the audit log is visible to the operator.

Integration points

  • Independent penetration testing (planned workstream)
  • Log retention and independent storage (readiness work)

Audit & reporting

Application-level append-only audit. Immutable infrastructure is separate readiness work.

Let’s talk about what you’re building.

Tell us what you’re building. We’ll tell you plainly what the platform does today and what it would take.