Welcome offer: 50% off your first 3 months
New customers only. Applied automatically at checkout.
For iGaming suppliers
Replace scattered email attachments and shared-drive links with one branded portal for your security, licensing and due-diligence documents. Then run the review in the other direction: send an iGaming-specific questionnaire to your own platform, payment, data and infrastructure suppliers and record the decision.
During operator procurement and integration, suppliers are asked for the same company, licensing, security, privacy, resilience and technical information over and over. The documents usually exist. They are just spread across compliance folders, email threads, Drive, Confluence and several internal owners.
Each operator, platform partner or payment provider asks for a slightly different pack, so the same files are assembled by hand every time.
Once a certificate or policy is emailed, the old version stays in the recipient inbox long after you have issued a newer one.
Audit reports and penetration-test material get forwarded onward, with no record of who received which file or when.
Requirements differ by role, market and operator. Nothing here assumes every supplier needs the same licence, certification or document set.
Operator technical and security teams review your architecture, resilience and integration documentation before connecting to your platform.
Commercial and compliance teams ask which certification evidence exists for your games and which markets you can already supply.
Reviews centre on data handling, resilience, incident response and the contractual paperwork behind processing player transactions.
Because you may process personal data for or on behalf of an operator, privacy documentation and security evidence are examined closely. Some providers will be independent or joint controllers in their own right, depending on the arrangement.
Hosting, data and analytics vendors are asked about locations, subprocessors, continuity arrangements and access control.
Marketing and data-protection reviewers look for privacy terms, data flows and the security basics behind your platform.
An illustrative example of how a supplier can structure its portal. The company, licences and documents below are fictional.
Illustrative supplier profile — fictional company, no real licence or certificate.
B2B games and platform supplier for regulated online casino operators. Founded 2019, remote team across Europe.
Licensing and regulatory status summarised in plain language, with the detail released on request.
security@example-gaming.test · escalation contact published on the profile
These are common patterns, not recommendations. Every organisation must decide what can be published or shared based on its own legal, security and regulatory advice.
Company overview, markets, licensing summary, security and privacy statements, certifications and contacts in one page.
Each file is either openly available or restricted behind an access request. You choose the level per document.
The same URL works for every review, so there is no repeat assembly of email attachments.
Requests arrive with the requester details. Approve, and the download is time-limited and watermarked, with the release recorded in your audit log.
Suppliers in this sector are also customers: platform providers, payment and payout partners, KYC/AML and fraud vendors, data feeds, affiliate tech and hosting all sit inside your regulated delivery chain. Vendor Assessments (Beta) covers that side with the same lightweight approach.
Whether they touch player data, handle payments, sit in a critical path, hold system access and how the contract runs. VendorLens scores inherent risk from those answers server-side and shows the factors behind the rating.
Lightweight Core covers governance, access, data handling, resilience and incident response in around ten to twelve questions. Add-ons are recommended automatically: Personal Data, Critical Service, Payments and the iGaming pack.
The supplier responds without an account, with autosave and section navigation, and attaches certificates, reports or policies where a question asks for evidence. Files are inspected and stored privately.
Ask follow-up questions on specific answers, then approve, approve with conditions or reject — with a rationale, residual-risk rating and next review date kept on the record.
The iGaming add-on covers the areas operators and partners raise most often in this sector: licence and jurisdiction scope, game or platform certification evidence where relevant, player-data handling and segregation, payments and payout flows, RNG or fairness testing evidence where applicable, change management for live environments, and incident notification routes.
These are point-in-time, questionnaire-based assessments. VendorLens does not certify a supplier, test their games or systems, monitor them continuously or issue risk ratings, and it does not replace your own regulatory or contractual due-diligence obligations.
Both approaches move files. The difference is the context, the control and the record around them.
| Capability | Shared folder or email | VendorLens trust center |
|---|---|---|
| Branded company context | A file list with no company or product framing | Branded profile, and your own domain on paid plans |
| Document descriptions | Filenames only | A title and description per document |
| Public/restricted separation | One link shares everything in the folder | Per-document visibility, open or restricted |
| Structured access requests | Ad-hoc emails to whoever answers first | Request form with NDA acceptance before release |
| One approved external destination | Copies spread across inboxes and drives | One page you update once for every reviewer |
| Professional customer experience | Depends on who assembled the last pack | The same structured review experience every time |
VendorLens helps present and distribute evidence your teams already maintain, and collects structured questionnaire answers and evidence from your own suppliers. It does not issue licences, certify games, test systems, perform security audits, monitor anyone continuously, provide legal advice or replace regulatory submissions, operator due diligence or your internal compliance function.
We are inviting a limited number of iGaming suppliers to test VendorLens with their real operator and partner-review workflows. We will help structure the portal and migrate up to ten approved documents in exchange for candid product feedback.
Publish the company, market and certification detail openly, keep audit and penetration-test material behind a request, and update everything in one place.