Skip to content
Architecture and security

A modular core that fails closed.

GameBridge is one hardened core with domain packages and one AI worker, not a mesh of services. It refuses to start without its secrets, verifies every payment callback before money moves, and shuts down cleanly so a deploy never leaves a half-finished transaction behind.

GoReactPostgreSQLRedisCloudflareAWS
Architecturemodular core + AI worker
Edge
Cloudflare WAF, DDoS, CDN, geo
nginx per brand domain
Clients
React player app
Operator console
Capacitor iOS / Android
Core
Go API gateway · modular domains
WebSocket realtime · outbox
GameBridge Studios + AI media worker
Data
PostgreSQL · double-entry ledger
Redis · cache, locks, presence
S3 media + CDN
Integrations
Alea · Iconic21 · Altenar
Card acquiring · Bank rails · Crypto
KYC · Fraud scoring · MaxMind
Fail closed. Missing secrets stop boot.
Leader election for every periodic worker.
/ready probes Postgres and Redis.
Bounded shutdown drains HTTP first.
At a glance
22+
vendors wired in behind hardened callbacks
90+
operator screens behind one permission model
2FA
TOTP with backup codes on every admin account
Fail-closed
boot, webhooks and every money path
20M+
simulated rounds per GameBridge Studios certificate
How it is built

Few moving parts, each one hardened.

The stack is deliberately short: one API process owns the domain, one worker owns AI generation, PostgreSQL owns the truth. Everything that can fail closed does.

Runtime

  • A Go API with domain packages, plus a separate AI worker for GameBridge Studios generation and the AI media loop
  • React and TypeScript on the front end; Capacitor shells for iOS and Android
  • PostgreSQL as the system of record, Redis alongside it, S3 and CDN for assets
  • Cloudflare WAF, DDoS protection, CDN and geo at the edge; managed AWS services underneath
  • Realtime channels for players, brands and admins, with guaranteed delivery for asynchronous work

Fails closed

  • Missing secrets stop the process from booting; unsigned payment callbacks are rejected
  • Health and readiness checks confirm the database and cache before traffic arrives
  • Singleton jobs run exactly once across the fleet through leader election
  • Bounded shutdown drains in-flight work instead of hanging a deploy
  • Panic recovery in every background job, so one bad task cannot take the process down
  • Idempotency keys and deterministic lock ordering on every money path

Application security

  • RBAC with page keys per screen and action keys for every money-moving operation, enforced in the sidebar, the route guard and the server
  • Admin 2FA with TOTP, backup codes and lockout; an Activity Log for every admin action
  • Encryption in transit and at rest; CORS hardening, sanitized CMS output and rejected SVG uploads
  • Secret scanning as a release gate, so a committed secret blocks the release
  • Payment webhooks verified by signature, amount and brand; KYC callbacks hardened; sportsbook callbacks behind an IP allow-list

Operations

  • Structured logs and CloudWatch; in-admin Engine Diagnostics with jobs, run history, heartbeats and a dead-letter queue
  • Deploy runbook with pre-open money audits before a brand takes traffic again
  • 38 operator guides in the built-in Documentation Center, with Ctrl+K search and a What's New feed
  • JSON import and export across bonuses, campaigns, packages, banners, segments and games; CSV and XLSX for reports
RNG and certification

Fairness you can verify, paperwork a lab can read.

Originals use commit-reveal HMAC-SHA256 seed pairs with a nonce for instant, stateful and slot games, and pre-committed hash chains for crash and roulette. Rotating the player seed reveals the server seed for the in-browser verifier. Around that sits an RNG dossier and submission handbook prepared for GLI-11, GLI-19, BMM and iTech Labs.

  • GameBridge Studios mints a certification package per math version: PAR sheet with RTP standard error and confidence interval, hit frequency, volatility and max-win reachability
  • 20M+ round Monte Carlo validation with hard publish gates before a game goes live
  • Definition JSON and a machine certificate bound to the definition hash and engine version, so any lab can reproduce the result
  • RNG test streams for Dieharder and NIST STS on request
Provably fair · commit-revealverifiable by player, operator, lab
  1. 1 · Commit

    Server seed generated from the OS CSPRNG; only its SHA-256 hash is shown before play.

    sha256: 9f3a…c41e
  2. 2 · Client seed

    Player sets or rotates a client seed at any time; nonce increments per bet.

    seed: nova-maya-7 · nonce 412
  3. 3 · Derive

    HMAC-SHA256(server, client:nonce) → CTR stream → rejection-sampled integers, no modulo bias.

    HMAC → 0.7421 → 74.21
  4. 4 · Reveal

    On rotation the server seed is revealed; anyone recomputes every historical outcome.

    reveal: 5d1c…e903 ✓
Instant and stateful games: seed pairs + nonce.
Crash and roulette: pre-committed hash chains.
Labs: rng-stream-dump for Dieharder / NIST STS.

Commit-reveal seeds and hash chains, verifiable in the browser. No certificate is claimed until a lab issues one.

How a release ships

Gate, migrate, audit, open.

  1. Step 1
    Gate

    Automated tests and secret scanning gate every release. A failing check is a failed release, not a warning.

  2. Step 2
    Migrate

    Database changes ship in a planned window, following the deploy runbook, once for the whole network.

  3. Step 3
    Audit

    Pre-open money audits run before traffic opens. Every check must come back clean; anything it finds is corrected first.

  4. Step 4
    Open

    The process refuses to start without its secrets, readiness checks confirm the database and cache, and the brand's domain takes traffic again.

Who relies on it

Technology, security and operations, one runbook.

A stack a small team can actually operate.

  • Modular Go core plus one AI worker, not microservices
  • Managed PostgreSQL, Redis, object storage and CDN
  • One codebase for every brand: a release ships once for the whole network
  • Realtime channels with guaranteed delivery for asynchronous work
Evaluator questions

What technical due diligence asks.

Is it microservices?
No. It is a modular core: one Go API gateway with domain packages, plus one AI worker for GameBridge Studios and the media loop. Fewer processes, fewer network boundaries, one schema.
Where does it run?
Containers on AWS with managed PostgreSQL and Redis, behind Cloudflare for WAF, DDoS protection, CDN and geo. Each brand runs on its own domain; brands share the codebase and database with complete player isolation.
How do releases reach us?
A release ships once for the whole network in a planned window: automated gates, database changes, pre-open money audits, then traffic. The What's New feed in the console records what each release changed for operators.
How is the RNG certified?
It is certification-ready, not certified. The RNG dossier and submission handbook are prepared for GLI-11, GLI-19, BMM and iTech Labs, and GameBridge Studios produces a certification package per math version. A lab issues the certificate; we do not claim it before then.
How do we verify the security claims?
Test them on a demo brand: retry a webhook, cancel a withdrawal late, interrupt a purchase, try an admin action without the permission. Every movement should leave a ledger row, nothing should double-pay, and every action should appear in the Activity Log.
Ready when you are

Launch a brand that runs like software and settles like a bank.

Walk through the launch wizard to get a scoped blueprint in ten minutes, or book a demo and we will show you the platform running end to end on your business model.

No sales pressure, no vaporware. Everything you see on this site is in the product today.

Press ⌘K or Ctrl+K