Licensed, certified and auditable by design
Every module, including the AI ones, is built to be inspected: certified RNG, signed replayable round logs, and a live audit stream regulators can query directly.
2
gaming licences held
6
regulated markets live or in certification
8
active certifications & standards
15min
P1 regulator/operator response SLA
Where we hold gaming licences and supplier registrations
Our critical gaming supply licence sits in Malta; every other market listed here is either a supplier registration or an active certification submission run in parallel.
| Authority | Jurisdiction | Licence / registration type | Status |
|---|---|---|---|
| Malta Gaming Authority (MGA) | Malta / EU | B2B critical gaming supply licence | Active |
| Curaçao Gaming Control Board | Curaçao | B2B gaming services authorisation | Active |
| Ontario AGCO / iGO | Ontario, Canada | Registered gaming-related supplier | In certification |
| New Jersey DGE | New Jersey, US | Vendor registration, casino service industry | In certification |
Eight active certifications across the platform
Live, in certification, and on the roadmap
A market moves from roadmap to in-certification once a commercial commitment is in place, and to live once the local regulator signs off, typically 8–14 weeks depending on the authority.
Europe
- MaltaLive
- SpainIn certification
- RomaniaIn certification
- IrelandRoadmap
- SwedenRoadmap
- DenmarkRoadmap
North America
- OntarioIn certification
- New JerseyIn certification
- MichiganRoadmap
LatAm
- BrazilIn certification
- PeruRoadmap
- ColombiaRoadmap
Rest of world
- CuraçaoLive
- Isle of ManRoadmap
Defence in depth, audited on a recurring cycle
Independent verification on every layer (infrastructure, application, cryptography, and process) on a recurring cycle.
ISO/IEC 27001
Certified information security management system covering platform infrastructure, application code, HR security, and vendor management, audited annually by an accredited body.
PCI DSS Level 1
Highest merchant tier for card data handling, required for any provider processing more than 6 million card transactions per year. Assessed annually by a Qualified Security Assessor.
Penetration testing & bug bounty
Independent penetration testing quarterly plus a continuous private bug-bounty programme with tiered payouts; every finding tracked to remediation with regulator-visible evidence.
Encryption & key management
AES-256 at rest, TLS 1.3 in transit, and a hardware security module (HSM) backed key hierarchy with quarterly rotation and split custodial access for the most sensitive material.
SOC 2 Type II
Independently audited across security, availability, and confidentiality trust principles over a 12-month observation window, with the report available under NDA to operators.
Infrastructure hardening
Segmented production networks, least-privilege IAM, mandatory MFA, and immutable infrastructure-as-code deployments with signed build provenance.
GDPR and LGPD by default, residency where it is required
Player data protection is built into the wallet and identity layer.
GDPR
Full Article 30 records of processing, a named Data Protection Officer, and data subject request handling within the statutory 30-day window across all EU-facing products.
LGPD
Brazil's Lei Geral de Proteção de Dados governs all player data collected through Brazilian-facing brands, with a local data protection point of contact and consent-first collection.
Data residency
EU player data can be pinned to EU-region infrastructure; equivalent residency options exist for US and Brazil deployments where regulators require it.
DPA & sub-processors
A standard Data Processing Agreement with SCCs is issued to every operator; a maintained sub-processor register is available on request and updated with 30 days' notice before change.
Player protection enforced at the wallet layer
Limits, checks, and interventions travel with the player across every product. A limit set in casino applies in sportsbook and at the AI dealer table in the same session.
Deposit, loss & session limits
Player-set and operator-default limits enforced at the wallet layer across every product, changeable downward instantly and upward only after a mandatory cooling-off period.
Reality checks
Configurable in-session prompts showing elapsed time, net position, and deposits, surfaced identically across casino, sportsbook, and AI dealer tables.
Self-exclusion registers
Native integration with GAMSTOP (UK), ROFUS (Denmark), Spelpaus (Sweden), and equivalent national registers, checked at registration and on a recurring schedule thereafter.
AI risk-of-harm scoring
neoBrain scores play patterns for markers of harm (chasing losses, session escalation, deposit-limit circumvention attempts) and triggers tiered interventions before a human reviews the account.
Staff training
Operator support and VIP teams complete certified responsible-gambling training before go-live, refreshed annually, with completion records retained for regulator audit.
Affordability checks
Configurable source-of-funds triggers at deposit-velocity and net-loss thresholds set per licence, escalating to manual review before further deposits are accepted.
Every AI-driven decision is logged, signed, and replayable
AI runs the dealer tables, the pricing, and the risk scoring. It does not run the randomness or the audit trail. Those stay certified, deterministic, and independently verifiable.
Model cards
Every production model (pricing, risk scoring, AI dealer, lobby ranking) ships with a model card: training data provenance, intended use, known limitations, and last validation date.
Certified RNG
All randomness (game outcomes, AI dealer shuffle, and deal sequencing) runs on a GLI-19-certified RNG, independent of the conversational and rendering layers of AI Dealer Studio.
Signed, replayable round logs
Every round produces a signed log (seed, outcome, RTP variant, render hash, and, for AI tables, dealer transcript) that is independently replayable without access to our infrastructure.
Regulator audit stream
A dedicated, read-only audit feed streams round-level and account-level events to regulators in near real time, in the schema each authority requires.
Explainability
Risk and bonus-eligibility decisions expose a feature-level rationale on request: which signals drove a limit change, a KYC escalation, or a promotional exclusion.
Bias testing
Risk-scoring and affordability models are tested quarterly for disparate impact across demographic proxies, with findings and remediation logged for regulator review.
GLI-19
certified RNG, AI tables included
7 yrs
signed round-log retention
Real-time
regulator audit stream
Quarterly
bias & fairness testing cadence
Screening and monitoring built into onboarding
Identity, screening & monitoring controls
Multi-region by default, with committed recovery targets
Production traffic runs active-active across two regions per continent served; failover is tested on a schedule.
< 15 min
Recovery Time Objective (RTO)
< 60 sec
Recovery Point Objective (RPO)
24/7
security operations coverage
Active-active
multi-region infrastructure
Incident classification, communication timelines and post-incident reports follow a documented runbook shared with operators at contract signature. Every P1 gets a written root-cause report within five business days.
Full documentation (audit reports, DPA, sub-processor register, and certification evidence packs) is available under NDA. [email protected]
Where blockchain sits relative to your gaming licence
Verifiability (provably fair rounds, anchored round logs, and a tamper-evident operator audit trail) involves no digital asset: no player holds a token and no operator custodies one, so it runs under your existing gaming authorisation. Custody, conversion, tokens, and real-world assets form a separate track, off by default and enabled only where your authorisation covers that service.
| Market | Assurance | Custody & exchange | Tokens & RWA | Gating instrument |
|---|---|---|---|---|
| MaltaMGA | Live today | With the relevant authorisation | With the relevant authorisation | MiCA Title II / V |
| SpainDGOJ | Live today | With the relevant authorisation | Not offered | MiCA + DGOJ payment rules |
| RomaniaONJN | Live today | With the relevant authorisation | Not offered | MiCA |
| OntarioAGCO | Live today | Not offered | Not offered | AGCO registrar standards |
| New JerseyDGE | Live today | Not offered | Not offered | NJ DGE payment methods |
| MichiganMGCB | Live today | Not offered | Not offered | MGCB internal controls |
| CuraçaoGCB | Live today | Live today | Live today | GCB LOK framework |
Availability is confirmed per brand against your own licence before any module is enabled, and a market absent from this table is one we have not cleared. Full detail on each module is on the Web3 pillar.
See what is certified for your target markets
A compliance lead walks through your licensing scope, the evidence pack we can hand your regulator, and the realistic timeline for anything still in certification.