Industry iGaming & online gambling

AppSec That Survives a Licensing Audit

One codebase, several regulators, and each of them asks where the data sits. Whitespots keeps the findings database inside your own perimeter — so the hosting question has the same answer in every jurisdiction you hold a licence in.

Findings stay in your perimeter

The vulnerability database, raw scanner output and every triage decision live on infrastructure you control, in the jurisdiction your licence names.

Audit evidence on demand

Each finding carries its scanner, timestamp, severity, triage decision and the person who made it — exported as the pack an independent assessor asks for.

One platform, several licences

Per-brand and per-jurisdiction scopes, roles and reporting in one instance, instead of a separate tool for every regulator.

Ready before the anniversary

Continuous scanning between audits, so the weeks before your renewal date are a report export rather than a remediation sprint.

Key challenges

What Multi-Licence Operators Run Into

The security problem in iGaming is rarely the scanning. It is proving, to several regulators with different wording, that the scanning happened and that the results went somewhere defensible.

The hosting question ends the SaaS conversation

A cloud-only scanner puts your source code and your unfixed vulnerabilities on someone else's infrastructure. Some jurisdictions constrain where gaming systems and their data may sit; all of them expect you to be able to answer the question precisely.

Audit calendars that overlap

Each licence has its own anniversary, its own assessor and its own report format. Chasing four evidence packs a year out of four different tools is how findings go stale between them.

Third-party code inside your scope

Game aggregators, payment providers, KYC vendors and affiliate scripts all execute on your platform. An assessor treats them as yours, whether or not your scanner reaches them.

Evidence scattered across tools

SAST in one place, dependency scanning in another, pentest PDFs in a shared drive. Reconstructing the history of a single finding for an auditor takes days that the filing deadline does not allow.

Clause map

What Each Regulator Actually Says

A clause map, not a marketing claim: what the published text requires, and how the platform helps you meet it.

UKGC United Kingdom

annual security audit

Conformance with ISO/IEC 27001:2022 Annex A controls named in the RTS, assessed by an independent annual security audit. A major non-conformity must be reported to the Commission with the full audit report.

How Whitespots helps

Covers the development controls the RTS names: secure development, security requirements and security testing. Every finding keeps its full history, so the auditor reads records instead of re-testing.

Spelinspektionen Sweden

gaming system location

The gaming system must be located in Sweden. It may sit abroad if a foreign regulator supervising it has an agreement with Spelinspektionen, or if Spelinspektionen can inspect it satisfactorily by remote access. Conformity is assessed by an accredited body.

How Whitespots helps

The platform runs on your servers next to the gaming system, so the findings stay in the same place. There is no second location to declare.

KSA Netherlands

assessment scheme v2.1

The control database (CDB) held in the Netherlands, an annual penetration test, and management of technical vulnerabilities as part of operational security.

How Whitespots helps

Continuous scanning is the ongoing vulnerability management KS.08.11 asks for. The findings database runs on your servers, so it can sit in the Netherlands next to the CDB.

ONJN Romania

remote gambling servers

A mirror server and a safety server on Romanian territory, available to ONJN and receiving every transaction in real time. The rest of the technical equipment must be in Romania too, unless the operator is authorised in another EU member state and runs it there.

How Whitespots helps

The platform runs on your own servers, so it can sit in Romania next to the mirror server. There is no vendor cloud to explain to the regulator.

MGA Malta

hosting and information-security principles

Principles-based guidance: hosting in Malta and/or an EEA member state and/or an approved third country. ISO 27001 is the standard the MGA aligns to, not a certification it obliges every licensee to hold.

How Whitespots helps

The platform runs wherever you host, so the choice of approved jurisdiction stays yours. The evidence for ISO-aligned controls is the same with or without certification.

GGL Germany

public register of permitted operators

Operator, gambling type, permitted domains and permit dates are published in a register anyone can filter — your German-facing surface is a matter of public record.

How Whitespots helps

Add the domains from the register as assets of each brand, so what you scan matches what the public record lists as yours.

Spillemyndigheden Denmark

certification programme

A penetration test before the licence is issued and again within 12 months of the last one, and a vulnerability scan at least every 3 months, each documented in a standard report for the regulator.

How Whitespots helps

Scanning runs continuously between the scheduled tests, so each report starts from findings that are already triaged and assigned. If you hold other licences, the same instance covers Denmark.

Clause references reflect published regulator text as of August 2026 and are a map of obligations, not legal advice. Confirm current wording with your compliance counsel before relying on it in an audit. Note also that on-premise software is an enumerated ICT service type under DORA — self-hosting changes where your data sits, not whether the arrangement is registered.

Platform

What Whitespots Gives an iGaming Security Team

The same platform the rest of the site describes, seen from the side that matters when a regulator is reading over your shoulder.

Self-hosted 01

Your code and findings stay on your side of the boundary

  • No third party in the regulator's picture No subcontractors and no hidden processing chain.

  • Zero outbound data No code, findings, logs or usage data leave your servers.

  • Leave whenever you want Exit is a database export, not a vendor negotiation.

See deployment options →
Scanner-agnostic 02

Every scanner an assessor asks for, in one clean queue

  • One flaw is one finding SAST, SCA, secrets, IaC, container and DAST results deduplicated.

  • Triage a false positive once Suppressed findings stay suppressed.

  • Add the scanner your assessor insists on Custom scanners without waiting on a vendor roadmap.

Explore the platform →
Audit evidence 03

The annual audit pack builds itself from normal work

  • Every decision traceable Per-finding trail: scanner, first seen, severity, decision, owner.

  • Evidence per brand and licence Scoping per brand, per jurisdiction and per licence.

  • Reports ready for the independent audit Exported straight from the platform.

How it works →
Developer workflow 04

Fixes land before release, not after a forwarded PDF

  • Developers see the issue on the exact line Findings in the IDE, with remediation guidance.

  • Caught in the pull request Checks run as code is written, not in a pre-release scramble.

  • No pipeline rewrite Onboarding through a VCS webhook.

See the IDE integration →
Outcomes

Where It Lands

The four things an iGaming security lead is usually asked to produce.

  • Scenario

    A regulator asks where vulnerability data is stored

    With Whitespots platform

    One answer, in writing: inside your perimeter, in the jurisdiction you name.

  • Scenario

    An independent assessor asks for a year of evidence

    With Whitespots platform

    A per-finding record with dates, decisions and owners, exported rather than reconstructed.

  • Scenario

    A new brand or licence goes live

    With Whitespots platform

    A new scope in the existing instance — not a new tool, a new contract and a new DPA.

  • Scenario

    A game aggregator ships an integration

    With Whitespots platform

    Third-party and dependency risk tracked in the same queue as your own code.

Proof

Operators Already Running This

Licensed operators in this segment are among the platform's longest-running deployments. Names are withheld here at their request.

B2B platform provider · multiple EU licences

Moved from a SaaS scanner to a self-hosted deployment after a licensing review flagged where vulnerability data was being processed.

Operator · UKGC and MGA licences

Uses per-brand scopes so one instance produces separate evidence packs for two assessors on different anniversaries.

Casino platform · EU-facing

Runs quality gates on pull requests, so aggregator integrations are reviewed before they reach production.

FAQ

What iGaming Teams Ask First

Does a self-hosted deployment mean we host the vulnerability data ourselves?

Yes — that is the point. The findings database, the scanner output and the remediation history sit on infrastructure you control. Whitespots does not receive your source code or your unfixed findings, which is what makes the data-location, data-return and subcontracting questions answerable in one move.

Which regulators require on-premise hosting?

It varies, and the detail matters. Sweden constrains the location of the gaming system unless remote regulator access is arranged; Romania requires servers or inspectable mirrors on Romanian territory; the Netherlands addresses database components. Others — including the UKGC's RTS — do not name a hosting location at all. Self-hosting is useful because it satisfies the strict cases without forcing a separate answer for the lenient ones.

Does self-hosting remove our DORA obligations?

No. On-premise software is an enumerated ICT service type in the register-of-information taxonomy, so the arrangement still gets recorded. What changes is the risk profile behind the entry: no third-party processing of your vulnerability data, and no subcontracting chain to map.

We already run scanners. Does this replace them?

No. Connect any scanner you already run, and its results go through the same deduplication and validation as everything else. If different teams run scanners separately, this is also how you bring them together in one place. Built-in scanners cover the gaps.

Our audit is in a few weeks. How long does onboarding take?

Connecting repositories takes a VCS webhook, with no agents and no pipeline changes. Built-in validation and deduplication rules triage standard cases automatically, so only your specific ones need a person. What takes longer is the evidence of fixing, because that depends on how quickly your teams ship fixes. If the audit is close, start with the assets named in the licence and add the rest later.

Can one instance serve several brands and licences?

Yes. Scopes, roles and reporting are per-brand and per-jurisdiction in a single instance, which is what keeps several licences from turning into one tool per regulator.

Bring the Findings Database Inside Your Perimeter

Start with a free external scan of the surface a regulator can already see, or talk to us about a self-hosted deployment scoped to your licences.