Licensed, certified and auditable by design

Every module, including the AI ones, is built to be inspected: certified RNG, signed replayable round logs, and a live audit stream regulators can query directly.

2

gaming licences held

6

regulated markets live or in certification

8

active certifications & standards

15min

P1 regulator/operator response SLA

Where we hold gaming licences and supplier registrations

Our critical gaming supply licence sits in Malta; every other market listed here is either a supplier registration or an active certification submission run in parallel.

AuthorityJurisdictionLicence / registration typeStatus
Malta Gaming Authority (MGA)Malta / EUB2B critical gaming supply licenceActive
Curaçao Gaming Control BoardCuraçaoB2B gaming services authorisationActive
Ontario AGCO / iGOOntario, CanadaRegistered gaming-related supplierIn certification
New Jersey DGENew Jersey, USVendor registration, casino service industryIn certification

Eight active certifications across the platform

MGA
Curaçao GCB
Ontario AGCO
GLI-19 / 33
ISO 27001
PCI DSS L1
SOC 2 Type II
GDPR

Live, in certification, and on the roadmap

A market moves from roadmap to in-certification once a commercial commitment is in place, and to live once the local regulator signs off, typically 8–14 weeks depending on the authority.

Europe

  • MaltaLive
  • SpainIn certification
  • RomaniaIn certification
  • IrelandRoadmap
  • SwedenRoadmap
  • DenmarkRoadmap

North America

  • OntarioIn certification
  • New JerseyIn certification
  • MichiganRoadmap

LatAm

  • BrazilIn certification
  • PeruRoadmap
  • ColombiaRoadmap

Rest of world

  • CuraçaoLive
  • Isle of ManRoadmap

Defence in depth, audited on a recurring cycle

Independent verification on every layer (infrastructure, application, cryptography, and process) on a recurring cycle.

ISO/IEC 27001

Certified information security management system covering platform infrastructure, application code, HR security, and vendor management, audited annually by an accredited body.

PCI DSS Level 1

Highest merchant tier for card data handling, required for any provider processing more than 6 million card transactions per year. Assessed annually by a Qualified Security Assessor.

Penetration testing & bug bounty

Independent penetration testing quarterly plus a continuous private bug-bounty programme with tiered payouts; every finding tracked to remediation with regulator-visible evidence.

Encryption & key management

AES-256 at rest, TLS 1.3 in transit, and a hardware security module (HSM) backed key hierarchy with quarterly rotation and split custodial access for the most sensitive material.

SOC 2 Type II

Independently audited across security, availability, and confidentiality trust principles over a 12-month observation window, with the report available under NDA to operators.

Infrastructure hardening

Segmented production networks, least-privilege IAM, mandatory MFA, and immutable infrastructure-as-code deployments with signed build provenance.

GDPR and LGPD by default, residency where it is required

Player data protection is built into the wallet and identity layer.

GDPR

Full Article 30 records of processing, a named Data Protection Officer, and data subject request handling within the statutory 30-day window across all EU-facing products.

LGPD

Brazil's Lei Geral de Proteção de Dados governs all player data collected through Brazilian-facing brands, with a local data protection point of contact and consent-first collection.

Data residency

EU player data can be pinned to EU-region infrastructure; equivalent residency options exist for US and Brazil deployments where regulators require it.

DPA & sub-processors

A standard Data Processing Agreement with SCCs is issued to every operator; a maintained sub-processor register is available on request and updated with 30 days' notice before change.

Player protection enforced at the wallet layer

Limits, checks, and interventions travel with the player across every product. A limit set in casino applies in sportsbook and at the AI dealer table in the same session.

Deposit, loss & session limits

Player-set and operator-default limits enforced at the wallet layer across every product, changeable downward instantly and upward only after a mandatory cooling-off period.

Reality checks

Configurable in-session prompts showing elapsed time, net position, and deposits, surfaced identically across casino, sportsbook, and AI dealer tables.

Self-exclusion registers

Native integration with GAMSTOP (UK), ROFUS (Denmark), Spelpaus (Sweden), and equivalent national registers, checked at registration and on a recurring schedule thereafter.

AI risk-of-harm scoring

neoBrain scores play patterns for markers of harm (chasing losses, session escalation, deposit-limit circumvention attempts) and triggers tiered interventions before a human reviews the account.

Staff training

Operator support and VIP teams complete certified responsible-gambling training before go-live, refreshed annually, with completion records retained for regulator audit.

Affordability checks

Configurable source-of-funds triggers at deposit-velocity and net-loss thresholds set per licence, escalating to manual review before further deposits are accepted.

Every AI-driven decision is logged, signed, and replayable

AI runs the dealer tables, the pricing, and the risk scoring. It does not run the randomness or the audit trail. Those stay certified, deterministic, and independently verifiable.

Model cards

Every production model (pricing, risk scoring, AI dealer, lobby ranking) ships with a model card: training data provenance, intended use, known limitations, and last validation date.

Certified RNG

All randomness (game outcomes, AI dealer shuffle, and deal sequencing) runs on a GLI-19-certified RNG, independent of the conversational and rendering layers of AI Dealer Studio.

Signed, replayable round logs

Every round produces a signed log (seed, outcome, RTP variant, render hash, and, for AI tables, dealer transcript) that is independently replayable without access to our infrastructure.

Regulator audit stream

A dedicated, read-only audit feed streams round-level and account-level events to regulators in near real time, in the schema each authority requires.

Explainability

Risk and bonus-eligibility decisions expose a feature-level rationale on request: which signals drove a limit change, a KYC escalation, or a promotional exclusion.

Bias testing

Risk-scoring and affordability models are tested quarterly for disparate impact across demographic proxies, with findings and remediation logged for regulator review.

GLI-19

certified RNG, AI tables included

7 yrs

signed round-log retention

Real-time

regulator audit stream

Quarterly

bias & fairness testing cadence

Screening and monitoring built into onboarding

Identity, screening & monitoring controls

Risk scoringEvery player scored at onboarding and continuously thereafter on identity, geography, payment method, and behavioural signal
Sanctions & PEP screeningReal-time screening against OFAC, UN, EU, and UK sanctions lists plus PEP databases, re-screened on a recurring schedule
Transaction monitoringRule- and model-based monitoring for structuring, rapid movement of funds, and payment-method layering across the wallet
SAR workflowSuspicious activity flags route to a case-management workflow with escalation timers matched to each licence's statutory filing window
Enhanced due diligenceElevated document and source-of-funds requirements auto-triggered by risk score, deposit velocity, or jurisdiction

Multi-region by default, with committed recovery targets

Production traffic runs active-active across two regions per continent served; failover is tested on a schedule.

< 15 min

Recovery Time Objective (RTO)

< 60 sec

Recovery Point Objective (RPO)

24/7

security operations coverage

Active-active

multi-region infrastructure

Incident classification, communication timelines and post-incident reports follow a documented runbook shared with operators at contract signature. Every P1 gets a written root-cause report within five business days.

Full documentation (audit reports, DPA, sub-processor register, and certification evidence packs) is available under NDA. [email protected]

Where blockchain sits relative to your gaming licence

Verifiability (provably fair rounds, anchored round logs, and a tamper-evident operator audit trail) involves no digital asset: no player holds a token and no operator custodies one, so it runs under your existing gaming authorisation. Custody, conversion, tokens, and real-world assets form a separate track, off by default and enabled only where your authorisation covers that service.

MarketAssuranceCustody & exchangeTokens & RWAGating instrument
MaltaMGALive todayWith the relevant authorisationWith the relevant authorisationMiCA Title II / V
SpainDGOJLive todayWith the relevant authorisationNot offeredMiCA + DGOJ payment rules
RomaniaONJNLive todayWith the relevant authorisationNot offeredMiCA
OntarioAGCOLive todayNot offeredNot offeredAGCO registrar standards
New JerseyDGELive todayNot offeredNot offeredNJ DGE payment methods
MichiganMGCBLive todayNot offeredNot offeredMGCB internal controls
CuraçaoGCBLive todayLive todayLive todayGCB LOK framework
Live todayWith the relevant authorisationNot offered

Availability is confirmed per brand against your own licence before any module is enabled, and a market absent from this table is one we have not cleared. Full detail on each module is on the Web3 pillar.

See what is certified for your target markets

A compliance lead walks through your licensing scope, the evidence pack we can hand your regulator, and the realistic timeline for anything still in certification.

WhatsApp