What the platform gives you is the evidence layer that makes your compliance work provable: a signed audit trail, reporting you can shape to your regulator, a choice of where data lives, and player-protection controls you configure yourself.
Every item below is a capability of the platform you run, configurable by you.
Every configuration change, privileged admin action and balance movement is recorded and signed. You, or your auditor, can export the trail at any time.
Reporting periods, thresholds, fields and formats are configurable per market, so the export matches what your regulator asks for instead of a fixed template.
Where player data lives is your decision, per jurisdiction. Dedicated infrastructure per operator, with the exact location disclosed to your DPO.
Deposit, loss and session limits, cooling-off, self-exclusion and age gates — configurable per market and enforced across the whole platform, not per product.
Configurable KYC tiers, verification requirements and AML reporting thresholds per market, with the full review trail retained. You set the policy; the platform enforces and records it.
The full subprocessor list with DPA references is available on request and updated within 30 days of any change.
Dedicated bare-metal, fully non-US and clear of CLOUD Act exposure. Exact location disclosed to your DPO and your regulator.
TLS 1.3 in transit. AES-256 at rest. Per-operator key separation, KMS-managed.
Data-subject requests, retention rules and erasure are built into the admin and configurable per jurisdiction. Per-operator data residency on request. DPO at dpo@ubeton.com.
Walled off from our chain. Every layer is non-US-incorporated.
Role-based access, SSO and mandatory MFA for staff. Privileged actions are logged immutably and are visible to your own reviewers.
You and your regulator can run the audit-trail export at any time. Every config change is signed.
Where your regulator or your test house needs evidence about the technology, we hand over the technical documentation, the architecture and the audit exports they ask for.
The signed audit trail, the configuration history and the subprocessor list are exportable by you at any time, so your reviewers work from the platform's own records rather than from a summary we wrote.
DPIA, subprocessor list, hosting-chain evidence and the architecture diagram — one PDF for your DPO.