The entry offer

Platform Technical Audit

A fixed-scope read of a live operation: what runs in production, where it breaks next, what to fix first. Two to three weeks, read-only.

Who it is for

  • You inherited a platform and nobody can say what runs in production.
  • Month-end reporting takes days and the numbers still get challenged.
  • You are entering a licensed market and need to know what the estate supports.
  • A regulator query showed one gap — you want to know how many more.

Not live yet? Turnkey Platform Delivery is the right line.

Scope

What we look at

Architecture

Wallet model, aggregation versus direct integrations, single points of failure.

Data and reporting

Where each ONJN or MGA report comes from, and how RTP and GGR reconcile.

Compliance surface

Deposit and session limits across brands, self-exclusion propagation, KYC/AML.

Payments

PSP routing, settlement reconciliation, chargebacks, and the payout queue.

Security

Account takeover, bonus abuse, DDoS, admin access — posture, not a pen test.

Delivery process

Release cadence, rollback, and how long a provider integration really takes.

What you receive

Six deliverables

Everything is written down. The artifacts are yours, usable with any vendor.

Findings Report

Every finding with its evidence, severity, and the systems it touches.

Architecture & Data-Flow Map

The estate as it runs, not as the vendor documentation claims.

Risk Register

Technical, compliance and operational risks, ranked and ownable.

Compliance Gap Summary

Per market, duty by duty, where the implementation falls short.

Remediation Roadmap

The fixes in order, estimated in engineering-weeks.

Executive Briefing

A short board document, delivered live.

What we need from you

  • A countersigned NDA before anything else.
  • Read-only access to repositories, infrastructure, and the back office.
  • Recent regulator submissions and a month of PSP settlement files.
  • Around six hours of interviews across engineering, finance, and compliance.

What we never need

Production write access, player PII exports, or a copy of your codebase outside your infrastructure.

Not in scope

What the audit is not

  • Fixes. Remediation is scoped separately.
  • A penetration test. That is the Cybersecurity line.
  • Certification. We assess GLI/BMM readiness, not run it.
  • Vendor selection. Running the RFP is separate work.
  • Legal advice. The gap summary is technical, not a legal opinion.

Book the audit

Tell us what you run and which markets. You get questions back, not a pitch deck.