Security
How Space Admins is wired into the platform
The ISO/IEC 27001 partner behind the information security management system the platform is built and operated under.
- What the connection carries
- 3 capabilities, listed in full below
- Who owns what
- Scalara owns the integration and the record it writes. Space Admins owns its own service, under its own terms.
What the integration covers
The capabilities this connection actually carries. Anything Space Admins sells that is not on this list is not part of what you get here.
Information security management system
The policies, controls and review cycle that govern how the platform is built and run.
Control design and review
Security controls are documented, owned and reviewed rather than held in one engineer's head.
Evidence for operator due diligence
What is in place, and what is not, is stated during discovery rather than implied on a web page.
Space Admins is our information security partner. Their work is the ISO/IEC 27001 information security management system that sits behind how this platform is built, deployed and operated.
Inside Scalara
An information security management system is not a feature, and it does not appear on a screen. It is the reason the platform behaves consistently under pressure: documented policies with named owners, controls that are reviewed on a schedule rather than when somebody remembers, access that is granted by role and revoked when a role ends, and a defined path for handling an incident. Space Admins own that framework with us. It is what turns the engineering practice on our security architecture page, including internal services authenticating on every request, into something an auditor can inspect rather than something we simply assert.
The problem it removes
Operator due diligence is where a platform decision usually stalls. A buyer's security questionnaire asks who owns a control, when it was last reviewed, how access is granted and what happens during an incident. Answering that from memory takes weeks and rarely convinces anyone. Having the framework maintained with a specialist partner is what makes those answers available, current and consistent.
What stays with you
Your own regulatory obligations remain yours, including your security posture as a licensed operator, your staff access policy and your incident reporting duties in your markets. On a dedicated deployment, decisions about your infrastructure are yours to take with us.
What we publish, and what we do not
We do not publish a certificate number, an audit scope or a statement of applicability on this page. Ask during discovery and we will tell you precisely what is in place, who holds it and what it covers.
Where it sits on the platform
It stands behind security architecture and the evidence discussed in compliance and audit.
Questions about Space Admins
Yes. The ISO/IEC 27001 information security management system behind how the platform is built and operated is maintained with our partner Space Admins: documented policies with named owners, controls reviewed on a schedule, access granted by role and revoked with it, and a defined incident path.
We do not publish a certificate number or an audit scope on the website, because we would rather show you the real position under due diligence than post a claim you cannot check. Ask, and we will tell you exactly what is in place.
Internally, on a zero trust basis. Every internal system authenticates on every request, every component holds only the permissions its job needs, and nothing inside the platform is implicitly trusted. Each brand has its own separated login and account system.
Every action by a player, a staff member or a system is recorded in a tamper evident audit trail. Staff access is role based, down to individual permissions, and permission changes are themselves audited events. The security framework is maintained with Space Admins.
See it running against your own operation
Commercial terms and jurisdictional availability are assessed with you during discovery.

