Trust & Security

Built for regulated operators

Security, compliance and operational practices that help iGaming brands earn player and regulator trust.

Encryption in transit and at rest

All API traffic is TLS 1.3. Sensitive payloads and credentials are encrypted at rest using AES-256. Webhook signatures use HMAC-SHA256 so operators can verify every callback.

DDoS-protected edge network

Traffic is routed through a global CDN/WAF with automatic DDoS mitigation, bot management and rate limiting. Origin infrastructure is not exposed directly to the public internet.

Role-based access control

Staff actions require MFA. Admin privileges are granted through a separate user_roles table and audited. API keys are scoped by environment and can be rotated instantly.

Compliance-ready architecture

Built-in responsible gaming limits, self-exclusion hooks, KYC event webhooks and jurisdictional rule filtering. Operators remain responsible for their own licensing and local legal compliance.

Certifications & Compliance

Standards we operate against

Our providers are individually licensed. Our platform operates against the following security and infrastructure standards.

PCI-DSS Aligned

Cardholder data flows via tokenized PSPs only

GDPR Ready

DPA on request · EU data residency options

Licensed Providers

MGA · UKGC · Curaçao · Isle of Man studios

SOC 2 Practices

Access reviews, audit logs, change control

Cloudflare Enterprise

Global WAF, DDoS L3-L7, bot management

99.99% Uptime SLA

Multi-region active-active infrastructure

Responsible Gaming

Self-exclusion, deposit limits, reality checks

24/7 SOC Monitoring

Continuous threat detection & response

Formal audit reports and DPA templates available under NDA — security@casino-api.com.

Shared responsibility

We provide a secure, observable and compliant-ready API platform. Each operator is responsible for its own licensing, player terms, local tax obligations, fraud monitoring and responsible gaming policy. Our team can advise on architecture and controls, but legal and regulatory ownership stays with the operator.

Security contact

Report vulnerabilities or security questions to security@casino-api.com. We respond within 24 hours and coordinate responsible disclosure.

Incident response

24/7 on-call engineering. Critical incidents are communicated via Telegram and email within 15 minutes. Visit the status page for live health data.