UBetOn is a technology provider: you hold the licence in your market, we provide the platform underneath it. Security and data sovereignty aren't a feature here — they're the product. Here's how we run it, what we prove independently, and how to report a problem.
Each operator runs on dedicated, single-tenant infrastructure, with every company in the hosting chain non-US. Exact location disclosed to your DPO and regulator.
TLS 1.3 in transit, AES-256 at rest, HSM-managed keys. Player data stays in the jurisdiction you choose.
RBAC, SSO, mandatory MFA for staff, and immutable audit logs of every privileged action across the platform.
Your ML models train only on your players. No model weights, features or signals are pooled across operators.
Edge runs on sovereign, non-US services; observability is self-hosted, staying clear of Cloudflare and other US-controlled SaaS.
Daily signed attestations of where data lives and what touched it — auditable evidence, not a marketing promise.
Monthly red-team exercises against the ML pipeline. Latest cycle: 47 attacks attempted, 44 blocked, 3 patched within the window.
Third-party pen-tests of the platform and infrastructure annually and on major releases.
If you discover a vulnerability, report it to security@ubeton.com. We acknowledge within 48 hours, keep you updated through the fix, and offer safe harbour for good-faith research — no legal action against researchers acting in good faith.
We share our assurance pack — DPIA, hosting-chain evidence and pen-test summary — with operators under NDA.