Controls you can show, not describe.
Your risk is a control that exists in a policy but not in the system. When the regulator asks how a limit is enforced, you need to point at the screen, the permission and the log entry. GameBridge enforces limits, permissions and approvals server-side on every path, stops safely when something breaks and writes every admin action to an Activity Log.
Six controls that hold under audit.
Safe by default
Payment, aggregator and sportsbook callbacks verify signature, amount and brand. Missing secrets stop the process from booting. Players see less, never more, when something breaks.
role-based permissions enforced three times
Page keys per screen and action keys such as walletAdjust, withdrawalManage and bonusActivate, enforced in the sidebar, the route guard and the server. Admin 2FA with an authenticator app, backup codes and lockout.
An Activity Log on everything
Every admin action recorded with who, what, when and from where. Wallet adjustments need a reason. GDPR purge needs a typed confirmation. VIP comps above the threshold need a second approver, enforced in the data.
Responsible gaming per brand
Deposit, loss, wager, single-bet and session limits, reality checks, cooling off and self-exclusion from one day to permanent, with defaults per brand and a consent matrix per channel and vertical.
Geo you can prove
Country and state allow and deny lists, MaxMind GeoIP as a second opinion, a device GPS re-check and a restricted-region page. AMOE gated by the business model.
KYC and risk in one case
ID and selfie verification with liveness and callback hardening, in-house fraud scoring at registration and login with device fingerprinting, a 0 to 100 risk score from configurable rules, Duplicate Accounts across device, identity and location signals, and Cases with SLA and escalation.
Auto-actions ship report-only. You turn them on.
Risk scoring runs nightly and on events, but the platform does not block a player because a rule fired. Auto-actions are report-only until you enable them, so the first weeks show you what would have happened. Cases, not scripts, make the call.
- Risk score 0 to 100 from configurable rules and levels, whitelist versus manual override
- Cases: open, investigate, resolve, with assignment, escalation, SLA and notes
- Duplicate Accounts across email, phone, device, address, name, IP and location
- Bonus-time fraud checks are velocity-only; we do not claim multi-account bonus fraud detection
What you hand the regulator and the auditor.
For the regulator
- Certification-ready RNG dossier and submission handbook for Originals, prepared for GLI-11 and GLI-19, BMM and iTech Labs
- Per-brand responsible-gaming defaults and a Responsible Gaming tab on every player profile
- Sweepstakes rules pages, the AMOE queue for US sweepstakes brands
- Geo lists per brand with a restricted-region page and GPS re-check
- Consent matrix, one-click unsubscribe, SMS STOP and suppression lists with audited lift
For the auditor
- One double-entry ledger with integrity constraints; every movement is a balanced posting
- Activity Log for every admin action, action permissions on every money-moving operation, four-eyes on VIP comps enforced in the data
- Real-money-only reports with test accounts excluded, built by background jobs with CSV and XLSX export
- Money paths and admin systems hardened and audited before any brand takes traffic
- Structured logs, health and readiness probes and in-admin Engine Diagnostics
What compliance teams ask first.
Are the games certified?
Does the platform block fraud automatically?
How are limits enforced?
Which regions are supported?
Where compliance teams go next.
Risk, KYC and compliance
Risk scoring, duplicate accounts, fraud scoring and ID verification, geo controls and responsible gaming.
Scoprite di piùMarkets
Region by region: the business models that work there and what we integrate on request.
Scoprite di piùArchitecture and security
How the platform is built and secured: a modular core on hardened infrastructure, safe by default.
Scoprite di più