Built for regulated operators
Security, compliance and operational practices that help iGaming brands earn player and regulator trust.
Encryption in transit and at rest
All API traffic is TLS 1.3. Sensitive payloads and credentials are encrypted at rest using AES-256. Webhook signatures use HMAC-SHA256 so operators can verify every callback.
DDoS-protected edge network
Traffic is routed through a global CDN/WAF with automatic DDoS mitigation, bot management and rate limiting. Origin infrastructure is not exposed directly to the public internet.
Role-based access control
Staff actions require MFA. Admin privileges are granted through a separate user_roles table and audited. API keys are scoped by environment and can be rotated instantly.
Compliance-ready architecture
Built-in responsible gaming limits, self-exclusion hooks, KYC event webhooks and jurisdictional rule filtering. Operators remain responsible for their own licensing and local legal compliance.
Standards we operate against
Our providers are individually licensed. Our platform operates against the following security and infrastructure standards.
PCI-DSS Aligned
Cardholder data flows via tokenized PSPs only
GDPR Ready
DPA on request · EU data residency options
Licensed Providers
MGA · UKGC · Curaçao · Isle of Man studios
SOC 2 Practices
Access reviews, audit logs, change control
Cloudflare Enterprise
Global WAF, DDoS L3-L7, bot management
99.99% Uptime SLA
Multi-region active-active infrastructure
Responsible Gaming
Self-exclusion, deposit limits, reality checks
24/7 SOC Monitoring
Continuous threat detection & response
Formal audit reports and DPA templates available under NDA — security@casino-api.com.
Shared responsibility
We provide a secure, observable and compliant-ready API platform. Each operator is responsible for its own licensing, player terms, local tax obligations, fraud monitoring and responsible gaming policy. Our team can advise on architecture and controls, but legal and regulatory ownership stays with the operator.
Security contact
Report vulnerabilities or security questions to security@casino-api.com. We respond within 24 hours and coordinate responsible disclosure.
Incident response
24/7 on-call engineering. Critical incidents are communicated via Telegram and email within 15 minutes. Visit the status page for live health data.