Skip to main content

Nothing inside the platform is implicitly trusted

Every internal system proves its identity on every request. Every brand runs its own separated login and account system. Security is on by default rather than configured on later.

A portrait crop of the audit trail showing the time, event and participants columns for branding, compliance and authentication events.

The old assumption is that anything already inside the network is safe

  • One compromised component becomes a platform incident

    If internal services trust each other by default, reaching any one of them reaches all of them. The blast radius of a single failure is the whole estate rather than one service.

  • A shared account layer spreads the damage

    When brands share a login system, a credential leak on the smallest brand is an incident on the largest, and a regulator in one market starts asking about players in another.

  • Nobody can reconstruct what happened

    Without one record of who did what, from where and with which permissions, an incident review becomes an argument between systems that each saw part of the picture.

Work of this kind is unglamorous and almost entirely invisible.

The payoff is plain. The blast radius of any one failure stays small, which is the property that matters when the data is player money and player identity.

How the platform is put together

  • Every internal call authenticates

    Services prove their identity on every request. Nothing is trusted because of where it sits on the network.

  • Least privilege, service by service

    Each component holds only the permissions its job requires, so a component behaving unlike itself has nothing implicit to fall back on.

  • Identity isolation per brand

    Every brand runs its own login and account system, so credentials never cross between brands inside a group.

  • One tamper-evident record

    Player, staff and system actions land in a single stream with the actor, the role, the location and the device attached.

Isolation is a property of the architecture, not a setting

On a dedicated deployment there is nothing shared for another customer to reach: your infrastructure, your data, your player accounts. On shared deployments, brands remain separated at the identity and account level.

  • A dedicated deployment is your own environment

    Where it sits is decided with you, because residency is usually driven by your licence and your target markets.

  • Brands never share an account system

    A player on one brand is not a player on another unless they choose to be.

  • Hosting runs through our infrastructure partner

    CloudWalker operates the infrastructure the deployments run on.

Four tenant brand cards fanned out, each with its own brand mark and a row of readiness dots, shown as separate environments rather than one merged console.

How the platform is built and operated

Engineering practice

  • Security on by default in every new service

    A new component starts with no implicit access and is granted only what it needs.

  • Access granted by role and revoked with it

  • Every permission change recorded as an audited event

  • Viewing an identity document is itself an event

    Opening a player's document is recorded in the audit trail with the staff member named.

Operations and assurance

  • Infrastructure operated with CloudWalker

  • Identity verification and screening through Sumsub

  • An ISO/IEC 27001 management system maintained with Space Admins

    Documented policies with named owners, controls reviewed on a schedule, and a defined incident path. The certificate belongs to Space Admins, our information security partner, not to us.

  • GLI-19 certification in progress with Gaming Labs International

    The standard is named, not badged. It is in progress and it is not held today, so nothing on this site is certified to it yet, and we will say where the work stands if you ask.

  • The detailed position shared under due diligence

    We would rather show your team what is in place than publish a claim you cannot check.

Request the security overview

A shared deployment against a dedicated one

Shared deployment

Brands separated at the identity layer

Login and account systemWhether an account on one brand is an account on another.
Separate per brand
Player records and history
Separated per brand
Infrastructure
Operated for several tenants
Where the deployment sitsResidency is usually driven by the licence and the target markets.
Decided by us
Back-office portal
One per brand
Platform code and updates
The same codebase

Dedicated deployment

A private copy of the platform

Login and account systemWhether an account on one brand is an account on another.
Separate per brand
Player records and history
Yours alone
Infrastructure
Your own environment
Where the deployment sitsResidency is usually driven by the licence and the target markets.
Decided with you
Back-office portal
One per brand
Platform code and updates
The same codebase

If data residency or isolation carries a specific meaning for your licence, raise it in discovery, because it shapes where your deployment sits.

Questions security reviewers ask

In the deployment your brand runs on, hosted through our infrastructure partner CloudWalker. On a dedicated deployment that is your own environment, and where it sits is a decision we take with you rather than a default we apply, because residency is often driven by your licence and your target markets.

On shared deployments, brands remain separated at the identity and account level. If residency is a hard requirement, bring it to discovery early, because it shapes the deployment plan.

Yes. The ISO/IEC 27001 information security management system behind how the platform is built and operated is maintained with our partner Space Admins: documented policies with named owners, controls reviewed on a schedule, access granted by role and revoked with it, and a defined incident path.

We do not publish a certificate number or an audit scope on the website, because we would rather show you the real position under due diligence than post a claim you cannot check. Ask, and we will tell you exactly what is in place.

What this page covers in the feature matrix

Each capability below is a row in the platform index, where its tier sits beside the method and the date behind it. Read the full feature matrix.

Zero-trust internal security

Every internal system proves its identity on every request. Nothing inside the platform is implicitly trusted, and security is on by default.

Identity isolation per brand

Every brand runs its own separated login and account system. Player credentials are walled off between brands, even inside a single operator group.

Full-platform audit trail

Every action by every player, staff member and system lands in one central, tamper evident stream, enriched with location data and fully searchable.

Request the security overview before your review starts

We will walk your team through the architecture, the controls and the evidence we can produce, under due diligence rather than on a public page.

We reply within one working day.