Zero-trust internal security
Every internal system proves its identity on every request. Nothing inside the platform is implicitly trusted, and security is on by default.
Every internal system proves its identity on every request. Every brand runs its own separated login and account system. Security is on by default rather than configured on later.

If internal services trust each other by default, reaching any one of them reaches all of them. The blast radius of a single failure is the whole estate rather than one service.
When brands share a login system, a credential leak on the smallest brand is an incident on the largest, and a regulator in one market starts asking about players in another.
Without one record of who did what, from where and with which permissions, an incident review becomes an argument between systems that each saw part of the picture.
Work of this kind is unglamorous and almost entirely invisible.
The payoff is plain. The blast radius of any one failure stays small, which is the property that matters when the data is player money and player identity.
Services prove their identity on every request. Nothing is trusted because of where it sits on the network.
Each component holds only the permissions its job requires, so a component behaving unlike itself has nothing implicit to fall back on.
Every brand runs its own login and account system, so credentials never cross between brands inside a group.
Player, staff and system actions land in a single stream with the actor, the role, the location and the device attached.
On a dedicated deployment there is nothing shared for another customer to reach: your infrastructure, your data, your player accounts. On shared deployments, brands remain separated at the identity and account level.
A dedicated deployment is your own environment
Where it sits is decided with you, because residency is usually driven by your licence and your target markets.
Brands never share an account system
A player on one brand is not a player on another unless they choose to be.
Hosting runs through our infrastructure partner
CloudWalker operates the infrastructure the deployments run on.

Security on by default in every new service
A new component starts with no implicit access and is granted only what it needs.
Access granted by role and revoked with it
Every permission change recorded as an audited event
Viewing an identity document is itself an event
Opening a player's document is recorded in the audit trail with the staff member named.
Infrastructure operated with CloudWalker
Identity verification and screening through Sumsub
An ISO/IEC 27001 management system maintained with Space Admins
Documented policies with named owners, controls reviewed on a schedule, and a defined incident path. The certificate belongs to Space Admins, our information security partner, not to us.
GLI-19 certification in progress with Gaming Labs International
The standard is named, not badged. It is in progress and it is not held today, so nothing on this site is certified to it yet, and we will say where the work stands if you ask.
The detailed position shared under due diligence
We would rather show your team what is in place than publish a claim you cannot check.
Brands separated at the identity layer
A private copy of the platform
If data residency or isolation carries a specific meaning for your licence, raise it in discovery, because it shapes where your deployment sits.
In the deployment your brand runs on, hosted through our infrastructure partner CloudWalker. On a dedicated deployment that is your own environment, and where it sits is a decision we take with you rather than a default we apply, because residency is often driven by your licence and your target markets.
On shared deployments, brands remain separated at the identity and account level. If residency is a hard requirement, bring it to discovery early, because it shapes the deployment plan.
Yes. The ISO/IEC 27001 information security management system behind how the platform is built and operated is maintained with our partner Space Admins: documented policies with named owners, controls reviewed on a schedule, access granted by role and revoked with it, and a defined incident path.
We do not publish a certificate number or an audit scope on the website, because we would rather show you the real position under due diligence than post a claim you cannot check. Ask, and we will tell you exactly what is in place.
Each capability below is a row in the platform index, where its tier sits beside the method and the date behind it. Read the full feature matrix.
Every internal system proves its identity on every request. Nothing inside the platform is implicitly trusted, and security is on by default.
Every brand runs its own separated login and account system. Player credentials are walled off between brands, even inside a single operator group.
Every action by every player, staff member and system lands in one central, tamper evident stream, enriched with location data and fully searchable.
We will walk your team through the architecture, the controls and the evidence we can produce, under due diligence rather than on a public page.
We reply within one working day.