Identity & staff access
Granular RBAC, staff permissions, 2FA, IP restrictions and permission scopes keep operator access controlled.
- Role-based access control
- Staff 2FA
- IP allowlisting
- Permission scopes
NETXGEN is more than a gaming front end. This technical surface explains how security, customization, isolation, provider abstraction, wallet controls, risk tooling and operational visibility fit together behind the operator experience.
EXPLORE ↓Instead of hiding the platform behind generic “enterprise-grade” claims, this site maps the technical capabilities operators actually depend on. Use the pillars below or search the complete capability surface.
Searchable public capability map derived from the platform feature inventory.
Main, technical and status domains.
Independent desktop and mobile experience layers.
Identity, session, API, audit and tenant controls.
Protection across people, sessions, APIs and evidence. Security is implemented as an operating layer rather than a decorative checkbox.
Granular RBAC, staff permissions, 2FA, IP restrictions and permission scopes keep operator access controlled.
Session visibility, revocation, device recognition and account-takeover monitoring add controls around authenticated activity.
HMAC, signed requests, webhook signatures, request validation and rate limiting protect machine-to-machine flows.
Security, player, staff, API, KYC, finance and provider events can be traced through audit and evidence workflows.
NETXGEN separates operator logic from presentation so brands can change the experience without rebuilding the platform.
Desktop is treated as its own experience with layouts, navigation, hero areas, content blocks and game/provider collections.
Mobile is not a reduced desktop. It has its own composition, navigation priorities, campaigns, CTAs and one-hand interaction model.
Logos, favicon, colors, typography, themes, cards, buttons, backgrounds and navigation can be managed as a coherent brand layer.
Draft, preview, schedule and publish workflows support controlled content operations instead of direct hard-coded edits.
The platform is built around tenant separation, independent runtimes and explicit configuration ownership.
Runtime, database, storage, cache and session boundaries are designed to keep customer environments separated.
Public websites and operator backoffice surfaces can run on separate hosts with independent exposure and controls.
Activation, configuration sync, manifests and heartbeat concepts keep deployed runtimes aligned with the intended configuration.
Primary domains, aliases, standby domains, health checks and failover concepts reduce dependency on a single public route.