Security & Trust

Security by Design. Across Every Integration.

PlayerHub connects guest identity, casino systems, hospitality, payments and marketing through a security model built on isolation, encryption, controlled integration boundaries and auditability, never a generic shared SaaS data pool.

Core Controls

The controls behind the platform.

01

Encryption

PlayerHub encrypts data in transit and at rest. Protected integration paths separate public guest surfaces from casino, hospitality and payment systems.

02

Dedicated client isolation

Each client environment is isolated in a dedicated AWS account rather than commingled inside a shared customer account.

03

Penetration testing

Penetration testing and remediation are part of PlayerHub's security validation process for production-facing applications and services.

04

Payment boundaries

PlayerHub is the guest-experience and integration layer, not the card processor. Regulated payment handling stays with PCI-certified payment and wallet partners.

05

Scoped access

Operator, service and guest access is scoped to the role, environment and action required. Integrations do not expose casino systems directly to the public internet.

06

Audit trails

Promotion-rule changes and consequential automated actions are logged with the actor, action and time so teams can reconstruct what happened.

Architecture Boundary

The guest experience stays separated from systems of record.

PlayerHub connects to casino, payment and hospitality systems through controlled integration paths. Core systems remain protected behind the integration boundary instead of becoming public-facing application backends.

Dedicated client AWS isolation
Encrypted network and storage paths
Hybrid deployment for operator-governed data
Environment and role separation
Mobile App
Player Portal
Operator Portal
PlayerHub Secure CoreIdentity • policy • orchestration • audit
CMS / PMS
Payments
Access
Data Governance

Your player data stays under your governance.

For operator-controlled deployments, analytics and player records live inside infrastructure governed by the operator, under the operator's retention and access rules—not in a cross-client data pool.

Read the data-sovereignty model

Client isolation

Dedicated AWS account boundary for each client environment.

Retention

Operator governance determines how player-identifying records are retained inside operator-controlled deployments.

Data location

Hybrid deployment keeps sensitive data and analytics inside the agreed governance boundary.

Vendor access

Access is limited to the operational scope required to deliver and support the platform.

Read scope
The assistant reaches only data authorized for the authenticated guest and current session.
Write scope
Actions are constrained to explicit tools and policies rather than open-ended system access.
Confirmation
Money movement and reservation changes require guest confirmation before a write occurs.
Audit
Action requests and resulting writes are logged to the audit trail.
AI Guardrails

Useful AI without unconstrained authority.

The concierge reaches only approved tools and guest-scoped data. Consequential writes require explicit confirmation and are recorded for review.

Built-in safety for every AI interaction
Evaluation Ready

Bring the security questionnaire.

For an active evaluation, PlayerHub can walk your IT, security and compliance teams through deployment boundaries, data flows, payment scope, integration controls and testing practices.

Schedule a Technical Review