VendorLens

    For iGaming software suppliers

    An iGaming vendor security assessment template and evidence checklist

    Studios, platforms, aggregators, payments and infrastructure suppliers are asked for similar security evidence by every operator they sell into. This template organises that evidence once, so it can be assembled once and reused across reviews.

    No signup required. Both files are free to reuse internally.

    Why the same evidence keeps getting requested

    Operator security teams evaluate suppliers before integration and again at renewal. The underlying questions repeat across operators — encryption, access control, resilience, incident response, subprocessors — even though the exact questionnaire format differs. Assembling the evidence once, in a structured template, makes it faster to answer the next request instead of starting from a blank page each time.

    What the template covers

    Four sections mirror how operator reviewers typically group questions. Use the ones relevant to your business and skip the rest.

    Company and licensing evidence

    • Legal entity name, registration and registered address
    • Jurisdictions and markets where the platform or game is already supplied
    • Plain-language licensing summary, with detail released on request
    • Ownership or corporate-structure summary where an operator asks for it

    Information security evidence

    • ISO/IEC 27001 certificate and scope statement, where held
    • SOC 2 report or equivalent independent attestation, where held
    • Penetration-test executive summary and remediation status
    • Encryption approach for data in transit and at rest
    • Access-control model, including administrative access and offboarding
    • Vulnerability-management and patching cadence

    Resilience and incident evidence

    • Business-continuity and disaster-recovery summary
    • Incident-response policy and escalation contacts
    • Hosting regions and subprocessor list
    • Change-management and release process summary

    Privacy and contractual evidence

    • Data processing agreement template
    • Privacy policy and lawful-basis summary for player data handled
    • Standard contractual clauses or equivalent transfer mechanism, where relevant
    • Insurance evidence, where requested

    From a filled-in spreadsheet to a reusable supplier profile

    Once the checklist is complete, most suppliers still end up re-sending the same evidence by email for every new operator. A VendorLens trust center lets you publish the summary information openly and gate restricted documents such as audit reports or architecture detail behind an access request that your team reviews and approves manually.

    That is a distribution and access-control layer, not a replacement for completing the assessment itself, and not a certification of anything in it.

    What VendorLens does not do

    VendorLens helps present, request and control access to evidence that suppliers and operators already maintain. It does not issue licences, certify games, perform security audits, score risk on your behalf, provide legal advice, or replace regulatory submissions or your internal due-diligence process. Document access requests are reviewed and approved manually by the publishing organisation, there is no per-section visitor analytics, and each account publishes one trust page.

    Questions about the template