Protect data at every boundary
Keep secrets out of client code, verify notification signatures server-side, treat repeat notifications idempotently, apply least-privilege access, sign requests with a private key, and retain only the records required for operations and legal obligations. Running on local wallets and bank transfers keeps cardholder data out of the operator estate entirely.
Risk controls need player context
Payment authentication, device signals, account age, payment-method ownership, transaction velocity, deposit history, dispute history, and withdrawal behaviour can inform a decision. Controls should increase friction only where evidence supports it and should never replace the operator's KYC, AML, or responsible-gaming programme.
- Approval and rejection outcomes per route
- Velocity and duplicate-payment checks
- Webhook integrity and event replay controls
- Dispute evidence and transaction audit trail
Operate for change
Security review continues after launch. New markets, methods, products, owners, domains, and payment purposes may require renewed assessment. Incident contacts and escalation paths should be known before they are needed.