AppSec That Survives a Licensing Audit
One codebase, several regulators, and each of them asks where the data sits. Whitespots keeps the findings database inside your own perimeter — so the hosting question has the same answer in every jurisdiction you hold a licence in.
Findings stay in your perimeter
The vulnerability database, raw scanner output and every triage decision live on infrastructure you control, in the jurisdiction your licence names.
Audit evidence on demand
Each finding carries its scanner, timestamp, severity, triage decision and the person who made it — exported as the pack an independent assessor asks for.
One platform, several licences
Per-brand and per-jurisdiction scopes, roles and reporting in one instance, instead of a separate tool for every regulator.
Ready before the anniversary
Continuous scanning between audits, so the weeks before your renewal date are a report export rather than a remediation sprint.
What Multi-Licence Operators Run Into
The security problem in iGaming is rarely the scanning. It is proving, to several regulators with different wording, that the scanning happened and that the results went somewhere defensible.
The hosting question ends the SaaS conversation
A cloud-only scanner puts your source code and your unfixed vulnerabilities on someone else's infrastructure. Some jurisdictions constrain where gaming systems and their data may sit; all of them expect you to be able to answer the question precisely.
Audit calendars that overlap
Each licence has its own anniversary, its own assessor and its own report format. Chasing four evidence packs a year out of four different tools is how findings go stale between them.
Third-party code inside your scope
Game aggregators, payment providers, KYC vendors and affiliate scripts all execute on your platform. An assessor treats them as yours, whether or not your scanner reaches them.
Evidence scattered across tools
SAST in one place, dependency scanning in another, pentest PDFs in a shared drive. Reconstructing the history of a single finding for an auditor takes days that the filing deadline does not allow.
What Each Regulator Actually Says
A clause map, not a marketing claim: what the published text requires, and how the platform helps you meet it.
annual security audit
Conformance with ISO/IEC 27001:2022 Annex A controls named in the RTS, assessed by an independent annual security audit. A major non-conformity must be reported to the Commission with the full audit report.
How Whitespots helps
Covers the development controls the RTS names: secure development, security requirements and security testing. Every finding keeps its full history, so the auditor reads records instead of re-testing.
gaming system location
The gaming system must be located in Sweden. It may sit abroad if a foreign regulator supervising it has an agreement with Spelinspektionen, or if Spelinspektionen can inspect it satisfactorily by remote access. Conformity is assessed by an accredited body.
How Whitespots helps
The platform runs on your servers next to the gaming system, so the findings stay in the same place. There is no second location to declare.
assessment scheme v2.1
The control database (CDB) held in the Netherlands, an annual penetration test, and management of technical vulnerabilities as part of operational security.
How Whitespots helps
Continuous scanning is the ongoing vulnerability management KS.08.11 asks for. The findings database runs on your servers, so it can sit in the Netherlands next to the CDB.
remote gambling servers
A mirror server and a safety server on Romanian territory, available to ONJN and receiving every transaction in real time. The rest of the technical equipment must be in Romania too, unless the operator is authorised in another EU member state and runs it there.
How Whitespots helps
The platform runs on your own servers, so it can sit in Romania next to the mirror server. There is no vendor cloud to explain to the regulator.
hosting and information-security principles
Principles-based guidance: hosting in Malta and/or an EEA member state and/or an approved third country. ISO 27001 is the standard the MGA aligns to, not a certification it obliges every licensee to hold.
How Whitespots helps
The platform runs wherever you host, so the choice of approved jurisdiction stays yours. The evidence for ISO-aligned controls is the same with or without certification.
public register of permitted operators
Operator, gambling type, permitted domains and permit dates are published in a register anyone can filter — your German-facing surface is a matter of public record.
How Whitespots helps
Add the domains from the register as assets of each brand, so what you scan matches what the public record lists as yours.
certification programme
A penetration test before the licence is issued and again within 12 months of the last one, and a vulnerability scan at least every 3 months, each documented in a standard report for the regulator.
How Whitespots helps
Scanning runs continuously between the scheduled tests, so each report starts from findings that are already triaged and assigned. If you hold other licences, the same instance covers Denmark.
Clause references reflect published regulator text as of August 2026 and are a map of obligations, not legal advice. Confirm current wording with your compliance counsel before relying on it in an audit. Note also that on-premise software is an enumerated ICT service type under DORA — self-hosting changes where your data sits, not whether the arrangement is registered.
What Whitespots Gives an iGaming Security Team
The same platform the rest of the site describes, seen from the side that matters when a regulator is reading over your shoulder.
Your code and findings stay on your side of the boundary
-
No third party in the regulator's picture No subcontractors and no hidden processing chain.
-
Zero outbound data No code, findings, logs or usage data leave your servers.
-
Leave whenever you want Exit is a database export, not a vendor negotiation.
Every scanner an assessor asks for, in one clean queue
-
One flaw is one finding SAST, SCA, secrets, IaC, container and DAST results deduplicated.
-
Triage a false positive once Suppressed findings stay suppressed.
-
Add the scanner your assessor insists on Custom scanners without waiting on a vendor roadmap.
The annual audit pack builds itself from normal work
-
Every decision traceable Per-finding trail: scanner, first seen, severity, decision, owner.
-
Evidence per brand and licence Scoping per brand, per jurisdiction and per licence.
-
Reports ready for the independent audit Exported straight from the platform.
Fixes land before release, not after a forwarded PDF
-
Developers see the issue on the exact line Findings in the IDE, with remediation guidance.
-
Caught in the pull request Checks run as code is written, not in a pre-release scramble.
-
No pipeline rewrite Onboarding through a VCS webhook.
Where It Lands
The four things an iGaming security lead is usually asked to produce.
- Scenario
A regulator asks where vulnerability data is stored
With Whitespots platformOne answer, in writing: inside your perimeter, in the jurisdiction you name.
- Scenario
An independent assessor asks for a year of evidence
With Whitespots platformA per-finding record with dates, decisions and owners, exported rather than reconstructed.
- Scenario
A new brand or licence goes live
With Whitespots platformA new scope in the existing instance — not a new tool, a new contract and a new DPA.
- Scenario
A game aggregator ships an integration
With Whitespots platformThird-party and dependency risk tracked in the same queue as your own code.
Operators Already Running This
Licensed operators in this segment are among the platform's longest-running deployments. Names are withheld here at their request.
B2B platform provider · multiple EU licences
Moved from a SaaS scanner to a self-hosted deployment after a licensing review flagged where vulnerability data was being processed.
Operator · UKGC and MGA licences
Uses per-brand scopes so one instance produces separate evidence packs for two assessors on different anniversaries.
Casino platform · EU-facing
Runs quality gates on pull requests, so aggregator integrations are reviewed before they reach production.
What iGaming Teams Ask First
Does a self-hosted deployment mean we host the vulnerability data ourselves?
Yes — that is the point. The findings database, the scanner output and the remediation history sit on infrastructure you control. Whitespots does not receive your source code or your unfixed findings, which is what makes the data-location, data-return and subcontracting questions answerable in one move.
Which regulators require on-premise hosting?
It varies, and the detail matters. Sweden constrains the location of the gaming system unless remote regulator access is arranged; Romania requires servers or inspectable mirrors on Romanian territory; the Netherlands addresses database components. Others — including the UKGC's RTS — do not name a hosting location at all. Self-hosting is useful because it satisfies the strict cases without forcing a separate answer for the lenient ones.
Does self-hosting remove our DORA obligations?
No. On-premise software is an enumerated ICT service type in the register-of-information taxonomy, so the arrangement still gets recorded. What changes is the risk profile behind the entry: no third-party processing of your vulnerability data, and no subcontracting chain to map.
We already run scanners. Does this replace them?
No. Connect any scanner you already run, and its results go through the same deduplication and validation as everything else. If different teams run scanners separately, this is also how you bring them together in one place. Built-in scanners cover the gaps.
Our audit is in a few weeks. How long does onboarding take?
Connecting repositories takes a VCS webhook, with no agents and no pipeline changes. Built-in validation and deduplication rules triage standard cases automatically, so only your specific ones need a person. What takes longer is the evidence of fixing, because that depends on how quickly your teams ship fixes. If the audit is close, start with the assets named in the licence and add the rest later.
Can one instance serve several brands and licences?
Yes. Scopes, roles and reporting are per-brand and per-jurisdiction in a single instance, which is what keeps several licences from turning into one tool per regulator.
Bring the Findings Database Inside Your Perimeter
Start with a free external scan of the surface a regulator can already see, or talk to us about a self-hosted deployment scoped to your licences.