Compliance

You hold the licence. We provide the technology.

What the platform gives you is the evidence layer that makes your compliance work provable: a signed audit trail, reporting you can shape to your regulator, a choice of where data lives, and player-protection controls you configure yourself.

Product

What your compliance team gets

Every item below is a capability of the platform you run, configurable by you.

Immutable audit trail

Every configuration change, privileged admin action and balance movement is recorded and signed. You, or your auditor, can export the trail at any time.

Configurable reporting

Reporting periods, thresholds, fields and formats are configurable per market, so the export matches what your regulator asks for instead of a fixed template.

Data residency you choose

Where player data lives is your decision, per jurisdiction. Dedicated infrastructure per operator, with the exact location disclosed to your DPO.

Player-protection tooling

Deposit, loss and session limits, cooling-off, self-exclusion and age gates — configurable per market and enforced across the whole platform, not per product.

KYC and AML controls

Configurable KYC tiers, verification requirements and AML reporting thresholds per market, with the full review trail retained. You set the policy; the platform enforces and records it.

Subprocessor transparency

The full subprocessor list with DPA references is available on request and updated within 30 days of any change.

Data protection

Hosting

Dedicated bare-metal, fully non-US and clear of CLOUD Act exposure. Exact location disclosed to your DPO and your regulator.

Encryption

TLS 1.3 in transit. AES-256 at rest. Per-operator key separation, KMS-managed.

Privacy

Data-subject requests, retention rules and erasure are built into the admin and configurable per jurisdiction. Per-operator data residency on request. DPO at dpo@ubeton.com.

CLOUD Act / FISA 702

Walled off from our chain. Every layer is non-US-incorporated.

Separation of duties

Role-based access, SSO and mandatory MFA for staff. Privileged actions are logged immutably and are visible to your own reviewers.

Auditability

You and your regulator can run the audit-trail export at any time. Every config change is signed.

Evidence

What we hand over

Technical documentation

Where your regulator or your test house needs evidence about the technology, we hand over the technical documentation, the architecture and the audit exports they ask for.

Your own auditors

The signed audit trail, the configuration history and the subprocessor list are exportable by you at any time, so your reviewers work from the platform's own records rather than from a summary we wrote.

Need the documentation pack?

DPIA, subprocessor list, hosting-chain evidence and the architecture diagram — one PDF for your DPO.

Book a demo