Identity & staff access
Granular RBAC, staff permissions, 2FA, IP restrictions and permission scopes keep operator access controlled.
- Role-based access control
- Staff 2FA
- IP allowlisting
- Permission scopes
Protection across people, sessions, APIs and evidence. Security is implemented as an operating layer rather than a decorative checkbox.
DETAIL ↓Protection across people, sessions, APIs and evidence. Security is implemented as an operating layer rather than a decorative checkbox. The sections below describe the capability surface in customer-facing technical language while intentionally avoiding internal credentials, topology and commercially sensitive controls.
Granular RBAC, staff permissions, 2FA, IP restrictions and permission scopes keep operator access controlled.
Session visibility, revocation, device recognition and account-takeover monitoring add controls around authenticated activity.
HMAC, signed requests, webhook signatures, request validation and rate limiting protect machine-to-machine flows.
Security, player, staff, API, KYC, finance and provider events can be traced through audit and evidence workflows.