VendorLens

    Welcome offer: 50% off your first 3 months

    New customers only. Applied automatically at checkout.

    06d:09h:33m:03s
    See pricing

    For iGaming suppliers

    Trust center and supplier assessments for iGaming

    Replace scattered email attachments and shared-drive links with one branded portal for your security, licensing and due-diligence documents. Then run the review in the other direction: send an iGaming-specific questionnaire to your own platform, payment, data and infrastructure suppliers and record the decision.

    • Branded supplier profile
    • Public and restricted documents
    • Request-based access
    • iGaming assessment pack (Beta)
    • No full GRC migration

    The same documents, requested again and again

    During operator procurement and integration, suppliers are asked for the same company, licensing, security, privacy, resilience and technical information over and over. The documents usually exist. They are just spread across compliance folders, email threads, Drive, Confluence and several internal owners.

    Repeated document requests

    Each operator, platform partner or payment provider asks for a slightly different pack, so the same files are assembled by hand every time.

    Outdated versions in circulation

    Once a certificate or policy is emailed, the old version stays in the recipient inbox long after you have issued a newer one.

    Sensitive evidence shared without sufficient control

    Audit reports and penetration-test material get forwarded onward, with no record of who received which file or when.

    Built for B2B suppliers selling into regulated operators

    Requirements differ by role, market and operator. Nothing here assumes every supplier needs the same licence, certification or document set.

    Platforms and aggregators

    Operator technical and security teams review your architecture, resilience and integration documentation before connecting to your platform.

    Game studios and suppliers

    Commercial and compliance teams ask which certification evidence exists for your games and which markets you can already supply.

    Payments and financial technology

    Reviews centre on data handling, resilience, incident response and the contractual paperwork behind processing player transactions.

    KYC, AML and fraud technology

    Because you may process personal data for or on behalf of an operator, privacy documentation and security evidence are examined closely. Some providers will be independent or joint controllers in their own right, depending on the arrangement.

    Infrastructure and data providers

    Hosting, data and analytics vendors are asked about locations, subprocessors, continuity arrangements and access control.

    Affiliate and marketing technology

    Marketing and data-protection reviewers look for privacy terms, data flows and the security basics behind your platform.

    What an iGaming supplier profile looks like

    An illustrative example of how a supplier can structure its portal. The company, licences and documents below are fictional.

    Example Gaming Technologies

    Example only

    Illustrative supplier profile — fictional company, no real licence or certificate.

    Company overview

    B2B games and platform supplier for regulated online casino operators. Founded 2019, remote team across Europe.

    Markets served

    Malta
    United Kingdom
    Sweden
    Ontario (Canada)

    Licensing summary

    Licensing and regulatory status summarised in plain language, with the detail released on request.

    Security and privacy

    • Data hosted in EU regions with encryption in transit and at rest
    • Annual third-party penetration testing
    • Documented incident-response and continuity processes

    Certifications

    ISO/IEC 27001
    SOC 2 Type II
    Game certification evidence

    Documents

    • Company and product overview
      Public
    • Subprocessor list
      Public
    • Data processing agreement
      Public
    • ISO/IEC 27001 certificate
      Request access
    • Penetration-test executive summary
      Request access
    • Business continuity and DR summary
      Request access

    Contact

    security@example-gaming.test · escalation contact published on the profile

    What to publish, what to gate and what to keep internal

    These are common patterns, not recommendations. Every organisation must decide what can be published or shared based on its own legal, security and regulatory advice.

    Public profile information

    • Company and product overview
    • Jurisdictions or markets served
    • High-level licensing information
    • Security and privacy summary
    • Certifications held
    • Subprocessor information
    • Support and escalation contacts

    Restricted documents

    • ISO/IEC 27001 certificate
    • SOC 2 report, where applicable
    • Penetration-test executive summary
    • Data processing agreement
    • Business continuity and disaster recovery material
    • Incident-response policy
    • Technical architecture summary
    • Insurance evidence
    • Game or system certification evidence
    • Approved operational or compliance policies

    Keep private

    • Credentials and secrets
    • Source code
    • Full vulnerability details
    • Live customer or player data
    • Unredacted personal information
    • Internal investigation material
    • Draft or unapproved policies

    How it works

    1. 1

      Build your branded supplier profile

      Company overview, markets, licensing summary, security and privacy statements, certifications and contacts in one page.

    2. 2

      Upload approved documents and assign visibility

      Each file is either openly available or restricted behind an access request. You choose the level per document.

    3. 3

      Send one reusable link to the operator or partner

      The same URL works for every review, so there is no repeat assembly of email attachments.

    4. 4

      Review and manage requests for restricted material

      Requests arrive with the requester details. Approve, and the download is time-limited and watermarked, with the release recorded in your audit log.

    Assessing your own iGaming suppliers

    Suppliers in this sector are also customers: platform providers, payment and payout partners, KYC/AML and fraud vendors, data feeds, affiliate tech and hosting all sit inside your regulated delivery chain. Vendor Assessments (Beta) covers that side with the same lightweight approach.

    Step 1

    Add the supplier and answer six exposure questions

    Whether they touch player data, handle payments, sit in a critical path, hold system access and how the contract runs. VendorLens scores inherent risk from those answers server-side and shows the factors behind the rating.

    Step 2

    Send the recommended questionnaire

    Lightweight Core covers governance, access, data handling, resilience and incident response in around ten to twelve questions. Add-ons are recommended automatically: Personal Data, Critical Service, Payments and the iGaming pack.

    Step 3

    Collect answers and evidence through one expiring link

    The supplier responds without an account, with autosave and section navigation, and attaches certificates, reports or policies where a question asks for evidence. Files are inspected and stored privately.

    Step 4

    Review, request clarification and record the decision

    Ask follow-up questions on specific answers, then approve, approve with conditions or reject — with a rationale, residual-risk rating and next review date kept on the record.

    The iGaming add-on covers the areas operators and partners raise most often in this sector: licence and jurisdiction scope, game or platform certification evidence where relevant, player-data handling and segregation, payments and payout flows, RNG or fairness testing evidence where applicable, change management for live environments, and incident notification routes.

    These are point-in-time, questionnaire-based assessments. VendorLens does not certify a supplier, test their games or systems, monitor them continuously or issue risk ratings, and it does not replace your own regulatory or contractual due-diligence obligations.

    Shared folder or email thread versus a trust center

    Both approaches move files. The difference is the context, the control and the record around them.

    CapabilityShared folder or emailVendorLens trust center
    Branded company contextA file list with no company or product framingBranded profile, and your own domain on paid plans
    Document descriptionsFilenames onlyA title and description per document
    Public/restricted separationOne link shares everything in the folderPer-document visibility, open or restricted
    Structured access requestsAd-hoc emails to whoever answers firstRequest form with NDA acceptance before release
    One approved external destinationCopies spread across inboxes and drivesOne page you update once for every reviewer
    Professional customer experienceDepends on who assembled the last packThe same structured review experience every time

    What VendorLens does not do

    VendorLens helps present and distribute evidence your teams already maintain, and collects structured questionnaire answers and evidence from your own suppliers. It does not issue licences, certify games, test systems, perform security audits, monitor anyone continuously, provide legal advice or replace regulatory submissions, operator due diligence or your internal compliance function.

    Let us build your first supplier trust center

    We are inviting a limited number of iGaming suppliers to test VendorLens with their real operator and partner-review workflows. We will help structure the portal and migrate up to ten approved documents in exchange for candid product feedback.

    • VendorLens Pro free for 14 days
    • Card required for verification; no charge until the 14-day trial ends.
    • Done-for-you initial setup
    • Up to ten approved documents
    • Branding and access configuration
    • One onboarding and feedback session
    • No obligation to provide a positive testimonial

    Questions from iGaming suppliers

    Give operators one place to review your business

    Publish the company, market and certification detail openly, keep audit and penetration-test material behind a request, and update everything in one place.